A security bot breach exposed over 1 million Discord users’ data after attackers hit Double Counter’s system. The leak included emails, IDs, and IP addresses before the issue was fixed.
The attack happened on October 4 when hackers broke into a legacy server using an old analytics tool. They stole cloud credentials and copied about 12GB of records in six hours. The stolen data included around 1 million email addresses, 28 million Discord IDs, and 27 million IP addresses with location info.
A stolen bot token was then used to spread malicious links and unwanted invites in about 50 large Discord servers. The breach also led to $7,316 in fraudulent charges using a stolen Stripe key. Later, about 275,000 email addresses and usernames were leaked online.
Double Counter said no Discord passwords or stored card numbers were exposed. Cold storage data for about 58 million users stayed safe. Still, customer records with names, countries, and postal codes were affected.
The company acted fast by disabling stolen credentials, rotating secrets, and moving databases to private networks. Service was restored the same day. Server admins were told to delete suspicious bot messages posted during the attack.
Also Read: Discord commits to stronger cooperation with PH govt
For users, some of your personal data may now be exposed online, so it’s best to stay alert. Double Counter says it has added monitoring and stricter access controls to stop this from happening again.
Source: 1
