The Discord security bot Double Counter experienced a targeted infrastructure breach that compromised personal information linked to millions of accounts.
According to an incident report by operator Tellter SAS, an attacker accessed cloud credentials, hijacked the bot, copied about 12 GB of database contents, and misused a separate payment account.
The attacker remained active in the cloud environment for 5 hours and 51 minutes, from 12:03 to 17:54 UTC. Double Counter restored service at 19:19 after replacing the exposed credentials. An audit of 14 cloud projects found no remaining traces of the attacker.
The intrusion began through a retired OVH server that was disconnected from Double Counter’s operational network but still hosted an internet-accessible Metabase analytics instance.
The report attributes the initial access to a Metabase vulnerability that allowed the attacker to forge an administrator session and access the underlying host. No specific Common Vulnerabilities and Exposures (CVE) identifier was provided.
The compromised server contained valuable credentials, including a service account key with cloud administrator privileges and an administrator’s saved command-line session. By using these legitimate identities, the attacker blended their activities into normal operations.
Once inside the cloud, the attacker added an SSH key and exported a database to a newly created storage bucket. However, they did not download the initial export.
At 12:26 UTC, the attacker accessed a running bot container’s shell and extracted its Discord token. They then granted their account administrator privileges on Double Counter’s support server, reversed a staff-issued ban, and distributed invitations to their own Discord server through about 50 large communities.
According to Double Counter, Containment efforts initially failed because the attacker retained access to the infrastructure. When defenders rotated the bot token, the attacker obtained the new token within two minutes.
They then changed the database administrator password, disrupting legitimate services, and continued to copy database contents until responders terminated the session at 15:34. After revoking the service account key, the attacker switched to the stolen administrator session.
The affected dataset included Discord IDs and usernames associated with approximately 28 million accounts, as well as IP address records with coarse geolocation data related to about 27 million accounts.
Both categories were partially copied and are being treated as exposed. Additionally, the operator confirmed that approximately 25 million user-agent hashes and one million deduplicated email addresses were copied.
However, the operator confirmed that 15 million VPN detection logs were not copied, and separate cold storage containing data for approximately 58 million users and a behavioral database remained unaffected. Notably, Discord never collected passwords, and stored payment card details were not exposed.
A stolen Stripe key belonging to a separate product, Atis, enabled fraudulent charges totaling $7,316 against a company card. Two customers also incurred charges of $3 and $15, which have since been refunded.
In response to the breach, responders revoked credentials, shut down the legacy server, restricted database connectivity, removed public cache exposures, and implemented secret-access logging.
Administrators are advised to inspect audit logs and delete suspicious bot invitations posted between 12:00 and 16:30 UTC on October 4. Users should also be on the lookout for phishing attempts targeting exposed email addresses. Tellter notified France’s CNIL on October 5 and is pursuing legal action.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…