Hackers Steal Millions of Discord User Records

October 08, 2026 • subimpact team • 0 comments

Hackers Steal Millions of Discord User Records

Double Counter is a third-party security verification service designed to protect communities on the gaming chat app Discord. By managing access and verifying member identities across infrastructure networks, Double Counter prevents fraudulent activity and automated abuse. Although Discord itself was not directly breached, Double Counter suffered an intrusion exposing user data, including Discord email addresses, user IDs, and IP addresses.

Key Facts

Attribute Value
Affected Service Double Counter (Third-party security service)
Associated Platform Discord
Incident Report Date October 2026
Compromised Email Addresses Suspected 1 million
Compromised Records User IDs and IP addresses (potentially millions)
Duration of Unauthorized Access Nearly 6 hours

A third-party security service for Discord, Double Counter, suffered an unauthorized intrusion exposing an estimated 1 million email addresses alongside Discord user IDs and IP addresses.

How Did the Double Counter Breach Occur?

The Double Counter breach occurred when malicious actors executed a multi-stage attack against the security provider's infrastructure. Attackers spent nearly six hours exploring system internals before the vulnerability was discovered and closed. Discord was not breached directly, but users who relied on Double Counter verification had their account identifiers compromised during the operation.

According to an incident disclosure published by Double Counter in October 2026, unauthorized operators breached internal defenses and remained undetected for hours. Double Counter characterized the event as a targeted intrusion on its infrastructure.

"deliberate, multi-stage attack" Double Counter security disclosure, October 2026

Hackers accessed Double Counter's infrastructure for nearly six hours during a multi-stage attack before engineers identified and closed the vulnerability.

Who Is Affected by This Incident?

Discord users who interacted with the third-party security bot Double Counter are the primary subjects affected by this data compromise. A suspected 1 million user email addresses were stolen, while the total volume of compromised Discord user IDs and IP addresses potentially exceeds that figure across participating communities.

Because the intrusion targeted Double Counter rather than Discord servers directly, exposure is limited to members who engaged with Double Counter verification workflows. While the exact scope of affected servers remains unspecified in initial reports, the compromised records expose identifiable communication coordinates.

The Double Counter data compromise exposed an estimated 1 million Discord user email addresses as well as additional user IDs and network IP addresses.

Common Questions

Was Discord directly compromised in this security incident?

No, Discord was not targeted directly by the attackers. The security vulnerability existed exclusively within the third-party security service Double Counter, which interfaces with Discord to provide verification features for communities and their users.

How long did attackers maintain access to Double Counter systems?

Threat actors spent nearly six hours inside Double Counter's network infrastructure before administrators detected the intrusion and closed the active security vulnerability, according to the provider's official incident investigation timeline.

How many user records were stolen during the attack?

Attackers stole a suspected 1 million email addresses, alongside a potentially larger, unconfirmed volume of Discord user IDs and IP addresses that had been processed through Double Counter's verification systems.

Sources and Methodology

This article synthesizes official reporting published by Rock Paper Shotgun alongside technical incident disclosures released by security provider Double Counter regarding its October 2026 security incident.

  • Rock Paper Shotgun: "Hackers Steal Millions of Discord User Records" (Source URL: https://www.rockpapershotgun.com/hackers-steal-millions-of-discord-ids-and-email-address-in-deliberate-multi-stage-attack-on-security-service-double-counter)
  • Double Counter: Official Incident Report (October 2026)

No statistical conversions or language translations were required. This article was last updated on October 8, 2026.

Twitter Facebook
Link copied to clipboard!