In October 2026, Discord server protection service Double Counter suffered a data breach after attackers exploited a vulnerability in its Metabase analytics tool. A dataset containing 275,000 unique email addresses and Discord usernames was published publicly, along with names, countries, and postcodes for some paying subscribers. Affected individuals should change passwords, enable two-factor authentication, and watch closely for phishing attempts.
| Company | Double Counter |
|---|---|
| Industry | Other Commercial |
| Data Types Exposed | Email Addresses, Discord Usernames, Names, Countries, Postcodes |
| People Affected | 275,000 individuals |
| Attack Method | Third-Party Vendor Breach |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Double Counter Data Breach?
Double Counter, a service that helps protect Discord servers, has confirmed a data breach. The incident came to light in October 2026, when the company disclosed that attackers had broken into a portion of its systems. As a result, sensitive user data ended up in the hands of unauthorized parties.
According to Double Counter’s own disclosure, the breach stemmed from a vulnerability in Metabase, a third-party analytics tool the company used to review data. Attackers exploited this flaw to reach a subset of Double Counter’s stored information. Shortly afterward, a dataset tied to the breach appeared publicly, confirming that the exposure was real and not just theoretical.
Because the breach was first identified through the discovery of a published dataset, much of what is known comes directly from Double Counter’s own notice. The company has not released a detailed forensic timeline beyond confirming the breach occurred in October 2026. It remains unclear exactly how long the attackers had access before the issue was found. Double Counter has also not stated whether an outside cybersecurity firm was brought in to investigate.
Who was affected?
The breach affected users of Double Counter’s Discord protection service. This includes anyone who signed up using an email address, as well as users whose Discord usernames were tied to their accounts. In addition, a smaller group of paying subscribers who completed purchases through Stripe also had their information exposed.
The published dataset reportedly contained 275,000 unique email addresses and Discord usernames. This figure represents the confirmed scope based on what was found in the leaked corpus. However, Double Counter has not disclosed the exact number of paying subscribers whose additional details, such as names, countries, and postcodes, were included. Because Discord communities often include younger users, it is possible that some affected individuals are minors, although the source material does not specify ages.
What Information Was Potentially Exposed?
The exposed data falls into two general categories. Most affected individuals had only basic account information exposed. A smaller subset, tied to paid subscriptions, had additional personal details compromised.
- Email addresses
- Discord usernames
- Names (subscribers only)
- Countries (subscribers only)
- Postcodes (subscribers only)
Even though this breach did not involve Social Security numbers or financial account details, the exposed data still carries real risk. For example, attackers often combine email addresses and usernames to craft convincing phishing messages. Because many people reuse the same username or email across multiple platforms, this breach could help attackers link a person’s Discord identity to other accounts.
For the subscribers whose names, countries, and postcodes were exposed, the risk is somewhat higher. This combination of details can help scammers build more personalized and believable phishing attempts. In addition, this information could be used alongside other leaked data to attempt identity verification fraud on services that rely on basic personal details for account recovery.
What is the company doing?
Double Counter has acknowledged the breach through a public disclosure notice. In this notice, the company confirmed that attackers accessed a subset of its data through the Metabase vulnerability. Double Counter has not detailed specific remediation steps, such as patching timelines or system changes, beyond confirming the breach occurred.
It is not yet clear whether Double Counter is offering credit monitoring or identity protection services to affected users. The company also has not stated whether it directly notified individual users by email. Because the dataset was already published publicly, affected users may need to take independent steps to protect themselves rather than wait for further company communication.
What Should Affected Individuals Do?
Watch for Phishing and Scam Attempts
Because email addresses and usernames were exposed, affected individuals should be extra cautious with unexpected messages. Scammers often use leaked email lists to send convincing phishing emails that appear to come from trusted services. If you receive a message referencing Double Counter or Discord that asks for login details, treat it with suspicion.
As a result of this breach, it’s wise to verify any unexpected communication directly through official channels. Never click links in unsolicited emails. Instead, type the website address directly into your browser. This simple habit can prevent many common phishing attacks.
Update Passwords and Enable Two-Factor Authentication
If you used the same password for your Discord account and other services, change it immediately. This matters because attackers often test leaked usernames and emails against other popular platforms. Using a unique password for each account significantly reduces this risk.
In addition, enabling two-factor authentication adds an important extra layer of protection. Even if your password is compromised, two-factor authentication can stop an attacker from logging in. Most platforms, including Discord, offer this feature for free.
Monitor Your Accounts and Credit Reports
Even though this breach did not expose financial account numbers, affected subscribers should still monitor their credit reports. This is especially true for those whose names and addresses were included in the leaked data. Regularly checking your credit report can help you catch suspicious activity early.
You can request free credit reports from major credit bureaus each year. Because fraud can sometimes take months to appear, it helps to check periodically rather than just once. If you notice unfamiliar accounts or inquiries, report them immediately.
Consider Consulting a Data Breach Attorney
If you were affected by this breach, it may be worth speaking with a data breach attorney. Many attorneys offer free consultations to help you understand your rights. This is especially useful if you experience identity theft or fraud linked to this incident.
Because data breach laws vary by state, an attorney can help clarify whether you qualify for compensation. They can also help you understand filing deadlines that may apply to your situation. Acting sooner rather than later can help preserve your legal options.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
