ComputersAI

Double Counter Breach Exposes 1 Million Emails, 28 Million Discord IDs

Double Counter says a hack on the 4th leaked credentials and data, prompting a report to France's CNIL on the 5th.

Double Counter, a service that provides protection bots for Discord servers, disclosed that a hacking attack on the 4th exposed roughly 1 million email addresses among a much larger set of user data, according to zdnet.co.kr.

The attackers exploited a security flaw in an analytics program that was exposed externally on an old server. They obtained cloud access credentials and remained in the system for about six hours, exfiltrating data before being cut off.

Partially copied data includes about 28 million Discord IDs and usernames, and about 27 million IP addresses with approximate location information. Have I Been Pwned says about 274,900 email addresses and Discord usernames have already been published publicly. For paid subscribers, names, countries of residence and postal codes were also among the leaked items.

The hackers posted malicious links in about 50 large Discord servers, causing financial damage of about 7,316 dollars. Double Counter said it disabled the stolen credentials, rotated encryption keys and moved its database to a private network, restoring service the same day. It reported the incident to France's CNIL data protection authority on the 5th.

Double Counter has told server administrators to delete suspicious links from messages sent under its name on the 4th.

Quick answers

What data was exposed in the Double Counter breach?

Roughly 1 million email addresses, about 28 million Discord IDs and usernames, and about 27 million IP addresses with approximate location information. For paid subscribers, names, countries of residence and postal codes were also included.

How long were the attackers inside Double Counter's systems?

About six hours, after exploiting a security flaw in an analytics program exposed externally on an old server.

What has Double Counter done since the breach?

It disabled the stolen credentials, rotated encryption keys and moved its database to a private network, restoring service the same day. It reported the incident to France's CNIL on the 5th.

Source