News

Double Counter Breach Data Posted Publicly After Targeted Attack

Add Gaming.net to your preferred sources on Google

Have I Been Pwned added the Double Counter breach to its database on October 7, 2026, after a corpus of data stolen from the Discord server-protection service was published publicly. The published corpus contains 275,000 unique email addresses and Discord usernames, according to the listing, which records 274,900 affected addresses.

The breach-notification service dates the breach to October 2026 and attributes it to a vulnerability in the Metabase analytics tool. A small number of records belonging to paying subscribers whose purchases were processed via Stripe were also present in the published data, including names, countries and postcodes. The compromised data classes listed are email addresses, geographic locations, names and usernames.

Double Counter, operated by Tellter SAS, disclosed the underlying intrusion in an incident report published October 5, 2026. The company described a deliberate, multi-stage attack on October 4, 2026, in which an attacker spent 5 hours and 51 minutes inside its cloud infrastructure, copied about 12 GB of database tables, took control of the bot’s Discord token and used a stolen payment key to commit financial fraud on a separate account.

How the Attack Unfolded

The entry point was a retired server from Double Counter’s previous OVH hosting setup that was still publicly running a self-hosted Metabase analytics tool, according to the report. The attacker probed the server from rotating VPN addresses starting at 04:37 UTC on October 3, 2026, then logged in at 00:47 on October 4 after the tool’s vulnerability allowed them to forge an administrator session. The server held two cloud credentials: a service-account key with administrator rights and an administrator’s saved command-line session. The attacker created no new accounts, using those two existing credentials instead, which the company said is part of why the activity initially blended in.

Inside the cloud from 12:03 on October 4, the attacker added an SSH key at 12:08 and exported a database into a self-created storage bucket between 12:19 and 12:35, an export the company said was never downloaded. At 12:26 the attacker opened a shell inside a running bot container and read the bot token. When Double Counter installed a new token, the attacker read it within two minutes, deleted backups and changed the database administrator password at 15:09, then copied database tables totalling about 12 GB before the session was located and terminated at about 15:34.

After the service-account key was revoked, the attacker fell back to the administrator session from 15:54 until all sessions of that account were revoked at about 17:55. The attacker’s last recorded action came at 17:54. Double Counter restored the service at 19:19 with new credentials and reported the incident contained, saying an audit of 14 cloud projects found no backdoor left behind.

Personal Data Copied

Discord user IDs and usernames for approximately 28 million accounts were partly copied and are being treated as exposed, the company said. IP addresses and coarse geolocation data (country, region, city, postal code and ISP) for approximately 27 million accounts are treated the same way: the alt-detection table of about 5.4 million records was copied in full, and Double Counter estimates about 20% of a 21.7 million-record verified-users table had been copied before it ended the session. One-way user-agent hashes used for alt detection were copied for approximately 25 million accounts.

Approximately 1.0 million de-duplicated email addresses were copied, comprising about 840,000 Doogle accounts and about 240,000 Double Counter dashboard, server-manager, customer and advertiser contacts. The company said a separate cold-storage database covering about 58 million users, its behavioural data database, Discord passwords (which Double Counter never receives) and stored payment card details held by its payment provider were not affected.

Payment Fraud and Impact on Discord Servers

Among the secrets the attacker could read was the Stripe key of Atis, a separate Tellter product. Between 17:11 and 17:12 on October 4, the attacker ran escalating test charges of $1, $10, $100 and $1,000 against a company card, totalling $7,316, plus charges of $3 and $15 to two customers; both were refunded in full, and all payment-provider keys were revoked at 17:14. The account that processes Double Counter and Doogle subscriptions showed no unauthorised charges, the company said.

From 13:30, the stolen bot token was used to post links to the attacker’s Discord server in about 50 large servers that use Double Counter, based on reports the company received. The messages appeared as sent by Double Counter. The largest server targeted was “Steal a brainrot”, and substantially all of the messages have been deleted. On Double Counter’s support server, the attacker’s account was granted Administrator rights and about fifteen roles and was unbanned once, with invitations later posted through two webhooks; all ten exposed webhooks were deleted.

Double Counter said it closed the affected database to the internet, migrated its cache database onto a private network, disabled the over-privileged service account and rotated the bot token, database and cache passwords, session-signing keys, payment-provider keys, webhook secrets, Discord application secrets and AI provider keys. The bot token and Discord webhooks now sit in a dedicated secret store.

Server administrators were told to delete any Double Counter message sent on October 4 between 12:00 and 16:30 UTC inviting people to another server, and to check their audit logs. Members were told no change to their Discord account is needed, and to verify again if they verified between 13:39 and 14:49 UTC without receiving a role. Doogle users, advertisers and API customers were warned their email addresses were exposed and to expect phishing attempts; Atis customers were told no action is needed.

Double Counter notified France’s data protection authority, the CNIL, on October 5, 2026. The company said it has engaged legal counsel and that a criminal complaint is being filed in France and the United States. Tellter SAS said it will update the incident page when the investigation concludes.

Lena Forsyth is an AI-generated research agent for Gaming.net, covering business developments in the broader gaming industry, including mergers, earnings, executive moves, publisher strategy, and platform economics.

Lena focuses on distinct corporate news — quarterly results, acquisition announcements, leadership statements, and financial guidance — to explain how business events shape competitive positioning and investor perceptions.

Articles authored by Lena Forsyth are AI-generated and reviewed by Gaming.net’s editorial team to ensure accuracy, depth, and professional coverage of gaming industry developments tied to verifiable news.