Double Counter, a bot that screens new members joining Discord servers, was breached on October 4, 2026. About 275,000 email addresses and Discord usernames taken from the service have since been published online.

Discord itself was not breached. The distinction is easy to miss, because every stolen record is Discord data, but the systems that were broken into belong to a third-party developer.
The bot is run by Tellter SAS, a French company. In its own incident report, published October 5, Tellter says an attacker spent five hours and 51 minutes inside its cloud infrastructure.
Tellter markets Double Counter as protecting more than 600,000 communities and 3.7 million monthly users. That reach is why the figures in the report run so high.
What Double Counter says the attacker copied
The report puts the haul at roughly 12 gigabytes, pulled from its databases between 15:09 and 15:34 UTC on October 4.
Tellter lists about 28 million Discord user IDs and usernames as exposed. It also lists around 27 million records of IP addresses and coarse location, covering country, region, city, postal code and internet provider.
Another 25 million one-way hashes of browser user agents were copied. So were roughly 1 million email addresses, after duplicates were removed.
About 840,000 of those belong to accounts on Doogle, a sister lookup tool for moderators. The other 240,000 are dashboard users, server managers, customers and advertiser contacts.
Tellter says a separate cold-storage database covering about 58 million users was untouched. Its behavioural data store sat elsewhere and was not accessed.

Where the 275,000 figure comes from
That number is not Tellter’s. It comes from Have I Been Pwned, which added the breach on October 7 and counts 274,922 unique email addresses.
The corpus it counted is the slice of stolen data that was later posted publicly. Tellter’s own figure for what was copied is close to four times higher.
Have I Been Pwned lists four data classes in that published set: email addresses, usernames, names and geographic locations. It notes that some records belonged to paying subscribers whose purchases ran through Stripe, and those carried names, countries and postcodes.
Tellter’s report is dated October 5 and has not been revised since. It predates the public posting and does not address the 275,000 count at all.
No Discord passwords or account tokens were involved
Tellter states plainly that Discord passwords were not in the affected database, because Double Counter never receives them. Stored card numbers were not exposed either, since its payment provider holds those.
Neither the operator’s data table nor the Have I Been Pwned listing includes Discord OAuth or access tokens. That matters more than any other line in the report.
Tokens of that kind can grant access to an account outright. Nothing in either source indicates that any were taken.
One token was stolen, and it was the bot’s own. The attacker read it out of a running container at 12:26 UTC, then used it to post invitations to their own server across about 50 large Discord communities.
Those messages appeared to come from Double Counter. Tellter reset the token three times during the incident and says substantially all of those posts have now been deleted.
What administrators and members are being told to do
Tellter asks server administrators to delete any Double Counter message sent on October 4 between 12:00 and 16:30 UTC that invites people elsewhere. It also asks them to check the audit log for actions by the bot in that window.
For ordinary members, the operator’s advice is that nothing on a Discord account needs changing. Anyone whose address was in the exposed set should expect phishing, and Tellter notes that it never asks for passwords, tokens or payment by email or direct message.
Revoking the bot is therefore not urgent. Anyone who wants to do it anyway can follow Discord’s own guidance, which points to User Settings and then Authorized Apps, where an app is removed with the Deauthorize button.
On mobile that sits behind the avatar in the bottom-right corner, then the cogwheel at the top-right. There is a fuller walkthrough of apps connected to a Discord account if the menu proves hard to find.
Discord’s own response was a short statement on October 7 from its support account. It said Discord’s systems were not breached and that it is preventing new server installs of the app while it investigates.
Discord has not said whether existing installs are affected, or when new installs will resume. The incident lands while Discord is already routing user data through outside parties elsewhere, including the vendor that handles its age-check ID scans.
Tellter named no CVE and no version of the analytics tool the attacker exploited, and it has not identified the attacker. It notified France’s data protection regulator on October 5 and says the report will be updated once the investigation closes.



Discussion (0)
Be the first to comment.