ADDEDb250rel/studios-leadership3 min read
Discord anti-raid bot Double Counter breach exposes ~1 million emails
Discord protection service Double Counter has suffered a data breach exposing approximately 1 million email addresses, alongside Discord IDs and IP addresses affecting millions more users of the anti-raid bot.
Patch notes
Approximately 1 million email addresses exposed in Double Counter breach
Discord IDs and IP addresses also affected for 'millions more' users per available reporting
Double Counter is a third-party bot that protects Discord servers from raids and alt-account abuse
Operator has not disclosed breach vector, intrusion date, or leak-forum status
Exposed data categories: email addresses, Discord IDs, and IP addresses
Discord protection service Double Counter has suffered a data breach that exposed approximately 1 million email addresses, alongside Discord IDs and IP addresses for millions more users.
Double Counter operates as a third-party bot that protects Discord servers from raids and alt-account abuse. The service sits inside a wider market of moderation tooling that has become standard operational infrastructure for studios running community channels, esports events, and large fan-run servers.
Many of these tools process server join events, message content, and user metadata at volumes that no human moderator team could cover in real time.
The exposed dataset breaks down into three categories: roughly 1 million email addresses, plus Discord user IDs and IP addresses that available reporting describes only as touching "millions more" users. The operator has not disclosed a precise total for the ID and IP exposure.
What does the breach change for studios and community managers?
For studios and community teams that route player traffic, support channels, or moderator rosters through Discord, the incident reshapes a familiar risk calculation. Three operational priorities follow directly from the data types exposed:
- Email address leakage enables targeted phishing against server staff and high-trust volunteers whose handles are publicly visible, with the email column providing a clean delivery channel for credential-harvest attempts impersonating Discord or the bot operator.
- IP address exposure raises doxxing and swatting risk for individual moderators, with the added complication that moderator rosters are often semi-public and that IP data often reveals approximate geography.
- Discord ID exposure lets attackers correlate leaked records against existing server rosters, which refines follow-on attacks by aligning leaked emails with known in-server identities.
Teams running Double Counter deployments should treat moderator and high-trust-member addresses as compromised pending an official count from the operator. Studios with security operations centers should expect a short window of elevated phishing attempts against Discord-adjacent staff, and should brief moderators to treat unsolicited DMs and emails as hostile until the operator clarifies scope.
What the operator has not yet disclosed
Available reporting does not include the breach vector, the date of intrusion, or confirmation of whether the dataset has surfaced on a marketplace or leak forum. Without those details, server operators cannot cleanly prioritize remediation.
A vector limited to a misconfigured external database suggests a one-time exposure and a one-time notification obligation; a vector involving persistent access to logs would suggest ongoing risk and force an immediate rotation of moderator credentials, shared tokens, and any linked webhooks.
Server operators that route role assignments or welcome messages through Double Counter should also check whether the bot stores role-assignment history in the same system that the breach touched, since Discord IDs plus server IDs plus role metadata would let an attacker reconstruct moderator hierarchies.
What to watch next
The next signal worth tracking is whether Double Counter publishes a per-account notification, and whether the operator clarifies whether moderation logs — which routinely include message content from monitored channels — formed part of the dataset. That second answer will determine whether the breach stays a credential-phishing risk or escalates into a content-leak incident with direct disclosure obligations under GDPR, CCPA, or equivalent regimes.
Studios using the bot should also watch for an official statement from Double Counter clarifying retention windows for the leaked data types, which will set the floor for any downstream moderation-policy review.
via doublecounter.gg (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Game Dev Wire.
148 articles