Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Discord Users’ Data Exposed in Double Counter Breach

Discord Users’ Data Exposed in Double Counter Breach

Posted on October 7, 2026 By CWS

Discord Security Bot Breach

On October 4, 2026, Double Counter, a prominent security bot for Discord, experienced a significant data breach. Approximately 12 GB of user data was compromised when an attacker infiltrated its cloud infrastructure, leading to unauthorized postings across nearly 50 major Discord servers.

The breach was swiftly addressed, with Double Counter restoring services by 19:19, according to their incident report. An audit of 14 cloud projects revealed no backdoors, confirming the breach was isolated to Double Counter’s systems and not Discord’s.

How the Breach Occurred

The intrusion was traced back to an outdated OVH server from Double Counter’s previous hosting arrangement. Despite being disconnected from active services, it hosted a publicly accessible Metabase analytics tool. A vulnerability allowed the attacker to create an administrator session and gain access to sensitive credentials stored on the server.

These credentials included a cloud service-account key with full administrative rights and an administrator’s command-line session logs. By leveraging existing identities instead of creating new ones, the attacker initially avoided detection.

Details of the Cyber Attack

The attack commenced at 12:03, with the attacker adding an SSH key, exporting a database into a storage bucket, and opening a shell within a bot container, exposing the Discord token. Although the initial database export wasn’t downloaded, the stolen token enabled the attacker to manipulate server permissions.

Efforts to invalidate the token at 13:39 were insufficient, as the attacker quickly accessed the new token. Subsequent actions included changing the database admin password and duplicating records between 15:09 and 15:34. The attack concluded when all compromised sessions were revoked at 17:55.

Impact and Response

The breach affected approximately 28 million Discord IDs and usernames and 27 million IP addresses, along with user-agent hashes and email addresses. Investigators consider the entire IP table compromised due to uncertainty about specific rows.

Despite the breach’s scale, Discord passwords and stored payment information were not accessed. A separate incident involving a stolen Stripe key resulted in $7,316 in unauthorized charges, but affected customers were refunded.

To secure their systems, Double Counter decommissioned the vulnerable server, revoked cloud access, rotated credentials, and implemented stronger security measures, including secret storage and continuous monitoring.

These actions reflect a commitment to bolster security and prevent future incidents.

Cyber Security News Tags:cloud security, cyber attack, Cybersecurity, data breach, Discord, Double Counter, IT security, Metabase flaw, security bot, user data

Post navigation

Previous Post: Attackers Exploit ccTLDs to Acquire Google Certificates
Next Post: SonicWall Fixes Critical SSRF Vulnerability in SMA1000

Related Posts

ValleyRAT Malware Uses Fake LINE Installer to Steal Data ValleyRAT Malware Uses Fake LINE Installer to Steal Data Cyber Security News
Global Outage Disrupts Claude AI Services Global Outage Disrupts Claude AI Services Cyber Security News
SSHStalker Botnet Exploits Weak Passwords to Target Linux Servers SSHStalker Botnet Exploits Weak Passwords to Target Linux Servers Cyber Security News
Critical Flaw in Canon MailSuite Risks RCE Attacks Critical Flaw in Canon MailSuite Risks RCE Attacks Cyber Security News
Critical Vulnerability in Claude Extension Exposes Google Data Critical Vulnerability in Claude Extension Exposes Google Data Cyber Security News
Speaker Proposal Deadline Approaches for OpenSSL Conference 2025 in Prague Speaker Proposal Deadline Approaches for OpenSSL Conference 2025 in Prague Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Key Challenges Facing US SOCs: Solutions to Improve Efficiency
  • SonicWall Fixes Critical SSRF Vulnerability in SMA1000
  • Discord Users’ Data Exposed in Double Counter Breach
  • Attackers Exploit ccTLDs to Acquire Google Certificates
  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Key Challenges Facing US SOCs: Solutions to Improve Efficiency
  • SonicWall Fixes Critical SSRF Vulnerability in SMA1000
  • Discord Users’ Data Exposed in Double Counter Breach
  • Attackers Exploit ccTLDs to Acquire Google Certificates
  • CrowdStrike, AWS, NVIDIA Enhance Cybersecurity Accelerator

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark