The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Double Counter's own incident report (Oct 5), quoted by Insider Gaming, Cybernews, Dexerto and CyberSecurityNews, confirms the Oct 4 breach: ~28M Discord IDs/usernames and ~27M IP/location records partly copied and treated as exposed, ~25M user-agent hashes and ~1M emails copied. Discord told Dexerto it was not a breach of Discord. Have I Been Pwned lists 274,922 addresses from the public dump.

Sourcing
4independent sources

via Insider Gaming

Insider Gaming · track record
57Stories
100%Verified
2730d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Gaming/Double Counter Breach Exposes Data Tied to Up to 28 Million Discord Accounts
VERIFIEDBy Xavier Rivera· ·3 min read

Double Counter Breach Exposes Data Tied to Up to 28 Million Discord Accounts

Discord server-protection bot Double Counter says an October 4 attack exposed IDs and usernames tied to up to 28 million Discord accounts, plus IP and coarse location data for about 27 million and roughly 1 million email addresses. Discord says its own platform was not breached.

Source:Insider Gaming
Post
Double Counter Breach Exposes Data Tied to Up to 28 Million Discord Accounts
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Double Counter, a third-party Discord bot that server owners use to block alt accounts, raids and VPN users, says an October 4 breach exposed data tied to up to 28 million Discord accounts. Discord says its own platform was not breached.

What was exposed, according to Double Counter. In an incident report published October 5, the bot's operator, Tellter, said the attacker copied about 12 GB from one of its databases between 15:09 and 15:34 UTC. Discord IDs and usernames for about 28 million accounts, and IP addresses with coarse geolocation for about 27 million, were partly copied. Because the company cannot tell exactly which of those records left, it treats all of them as exposed, which is why 28 million is an upper bound rather than a confirmed count.
Because the company cannot tell exactly which of those records left, it treats all of them as exposed, which is why 28 million is an upper bound rather than a confirmed count.
User-agent hashes for about 25 million accounts and roughly 1 million email addresses were copied in full. According to the report, the email addresses belong to people who gave one to Double Counter or its Doogle service, such as dashboard users, customers and advertisers. The categories overlap, so the figures should not be added together.

Double Counter says about 15 million VPN detection logs were not copied, a separate cold-storage database was not affected, and it never held Discord passwords. Have I Been Pwned added the breach on October 7 after a dataset with about 275,000 unique email addresses and Discord usernames was posted publicly.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
How the attack happened. The attacker got in through a retired server from Double Counter's old hosting setup that was still running a vulnerable analytics tool, then used credentials stored on it to reach the company's cloud. They were active in its cloud for 5 hours and 51 minutes (12:03 to 17:54 UTC). During that time they took the bot's Discord token and used it to post links to their own server in about 50 large Discord servers.
The categories overlap, so the figures should not be added together.
They also used a stolen payment key to run $7,316 in fraudulent charges on a separate payment account. Double Counter says only three cards were charged, one of its own and two customers', and that the customers were refunded. It says no stored card numbers were exposed and that it revoked every payment-provider key at 17:14. Service was restored at 19:19 UTC with new credentials.

Discord's response. In a statement to Dexerto, Discord said: “While this was not a breach of Discord, we've disabled new installs of the app while we work with Double Counter to understand the full scope of the incident.” Double Counter says it has reported the breach to France's data protection authority, the CNIL, and is pursuing the attackers in France and the United States.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
What users should do. Double Counter says members do not need to change anything on their Discord accounts but should not join servers promoted in unexpected Double Counter messages. Server owners should delete Double Counter messages sent on October 4 between 12:00 and 16:30 UTC that invite people to another server, and check their audit logs for bot actions in that window. Anyone who gave Double Counter or Doogle an email address should watch for phishing.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securitydiscordbreach
More fromInsider Gaming
  • Xbox Forms XP Division to Grow Franchises Into Film and Events

    Tech · 6h
  • PS5 Crunchyroll Anime Hub Launches Spring 2027

    Tech · 10h
  • Netflix Releases Conjuring Interactive Horror Game October 13

    Gaming · 1d
More inGaming
  • GTA VI Adds Podcasts and Six Radio Stations

    Gaming · 3h
  • Netflix Releases Conjuring Interactive Horror Game October 13

    Gaming · 1d
  • Xbox Denies Report It Has Exclusive GTA VI Streaming Rights

    Gaming · 1d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Gaming →
  • Tech· 

    Red Hat OpenShift 4 hit by CVE-2026-93017 with 7.7 CVSS score

    Red Hat OpenShift Container Platform 4 is affected by CVE-2026-93017, a high-severity flaw that lets attackers read every secret in every namespace. The 7.7 CVSS score reflects broad access granted through an unrestricted ClusterRole on the insights-operator-gather service account.

  • Tech· 

    IBM Patches 40 DataPower Gateway Flaws, Seven Rated Critical

    IBM has fixed 40 vulnerabilities in DataPower Gateway, seven of them rated critical at CVSS 9.3 to 9.8, including remote code execution bugs and an LDAP flaw that accepts empty passwords for admin access. IBM says to upgrade to 10.5.0.23, 10.6.0.11 or 11.0.0.3.

  • Tech· 

    Cisco Releases Hardening Fix for Critical NX-OS Vulnerability

    Cisco has released NX-OS hardening updates covering CVE-2026-76455, a group of improper access control issues (CWE-284) scored 9.8 critical. Cisco found the issues in an internal review and says they are not known to be exploited.

  • Tech· 

    Cisco releases hardening fixes for critical CVE-2026-76482 in Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem)

    Cisco has released hardening updates for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), to fix CVE-2026-76482, a critical vulnerability with a CVSS score of 10. The flaw stems from improper input verification and was identified during an internal security review.

  • Tech· 

    Critical CVE-2026-76465 Allows Root RCE on Cisco Nexus Switches

    A critical vulnerability tracked as CVE-2026-76465 affects the MPLS OAM feature in Cisco NX-OS on Nexus 3000 and 9000 Series Switches. The flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges or trigger denial-of-service conditions.