Double Counter Breach Exposes Data for Up to 28 Million Users
Hackers spent nearly six hours inside Double Counter's infrastructure before the vulnerability was closed, the security service says.
Double Counter, a third-party security service used by Discord servers, has reported a deliberate multi-stage attack in which hackers spent nearly six hours inside its infrastructure before the vulnerability was closed. By Double Counter's own estimates, around 1 million user email addresses have been affected.
The attackers also partly copied databases containing Discord IDs, usernames, IP addresses and location information for up to 28 million users, according to the company's account of the incident.
Security breach tracker Have I Been Pwned reported that 275,000 of the stolen emails and usernames have since been posted publicly.
Prior incidents and context
Almost a year to the day before this breach, attackers compromised one of Discord's customer service partners, with some 70,000 photos of users' government-issued IDs reportedly among the data haul. Double Counter has previously been accused of selling user data for revenue. The breach also comes amid a faltering rollout of an age verification system which, at least in the UK, has funnelled data into a company backed by Peter Thiel.
Quick answers
How many users are affected by the Double Counter breach?
Double Counter estimates around 1 million user email addresses have been affected, and databases covering up to 28 million users were partly copied.
What data was stolen in the Double Counter breach?
Hackers partly copied databases of Discord IDs, usernames, IP addresses and location info, plus an estimated 1 million user email addresses.
Has any of the stolen data been posted publicly?
Have I Been Pwned reported that 275,000 of the stolen emails and usernames have since been posted publicly.