Discord Security Breach: 1 Million Email Addresses Exposed in Double Counter Bot Attack

MIXTV 1
By
21 Views
2 Min Read
Discord protection bot Double Counter hit by breach exposing around 1 million email addresses
- Advertisement -

Security Breach Hits Double Counter: Millions of Discord Users Impacted

The security of the Discord ecosystem was recently compromised following a sophisticated cyberattack on Double Counter, a popular moderation tool designed to prevent server raids and the proliferation of alt accounts. The incident has resulted in the exposure of sensitive user data, raising significant privacy concerns for millions of community members.

Discord security breach illustration
Image credit: Discord

Anatomy of the Cyberattack

According to the official incident report, the breach was not a random occurrence but a calculated, multi-stage operation that took place on October 4. Threat actors identified and exploited a security flaw within an analytics tool hosted on a legacy server. By leveraging this vulnerability, the attackers successfully obtained cloud credentials, granting them unauthorized access to the system for a duration of nearly six hours.

Scope of the Data Exposure

The scale of the information compromised is substantial. Double Counter has confirmed that the following data points were accessed:

  • Account Identifiers: Discord IDs and usernames for approximately 28 million accounts were partially exfiltrated.
  • Network Data: IP addresses and coarse geolocation data associated with roughly 27 million users are now considered compromised.
  • Contact Information: Approximately 1 million email addresses were exposed.
  • Premium User Data: For those with paid subscriptions, the breach included personal details such as full names, country of residence, and postal codes.

Data breach monitoring service Have I Been Pwned has verified that a subset of this data-specifically 274,900 email addresses and associated usernames-has already been leaked into the public domain.

Malicious Exploitation and Financial Impact

Beyond the theft of user information, the attackers weaponized the service to facilitate further harm. By stealing a bot token, the perpetrators gained the ability to broadcast malicious links across approximately 50 high-traffic Discord servers. Furthermore, the attackers managed to compromise a separate payment account, resulting in $7,316 in unauthorized, fraudulent charges.

This incident serves as a stark reminder of the risks associated with third-party integrations. As cyber threats evolve, even tools intended to bolster security can become vectors for large-scale data loss if legacy infrastructure is not properly audited and secured. Users are encouraged to remain vigilant against phishing attempts that may utilize the leaked email addresses and usernames.

» More Info >>>

Disclaimer: This article is partially generated by artificial intelligence, so there may be some errors. Please check the information before using it in real life.

- Advertisement -
MIXTV PUSH
LATEST NEWS
Share This Article
Leave a Comment

Comments (0)

Your email address will not be published. Required fields are marked *