Double Counter breach exposes 275,000 email addresses and Discord usernames
Discord server-protection service Double Counter suffered a breach linked to a vulnerability in its Metabase analytics tool, according to Have I Been Pwned. Its published dataset contained about 275,000 email addresses and Discord usernames; a small number of subscriber records also included names, countries and postcodes. Mozilla Monitor says passwords were not exposed, but the leaked identity pairs may make targeted phishing easier.
Bottom line — Have I Been Pwned lists 274,922 affected accounts; check your addresses and watch for messages posing as Discord or server moderators.
Go deeper 7
-
Have I Been Pwned says the breach occurred in October 2026 and the corpus was added to its database on 7 October.
-
Have I Been Pwned reports that some exposed subscriber records related to Stripe purchases and included names, countries and postcodes.
-
Mozilla Monitor says passwords were not exposed in the breach.
-
TwistedVoxel reports a much broader incident: data linked to about 28 million Discord accounts, including IDs and usernames, with IP and location information for about 27 million. This conflicts with the roughly 275,000 email-address figure reported by Have I Been Pwned.
-
TwistedVoxel says Double Counter reported that the attacker accessed its cloud infrastructure for 5 hours and 51 minutes and copied about 12 GB of data.
-
TwistedVoxel says Double Counter reported that Discord passwords and stored payment-card information were not accessed.
-
PrivacyOn advises checking old and alias email addresses against a breach-notification service and changing any password reused elsewhere.