About 12 GB of database tables left Double Counter’s systems between 15:09 and 15:34 UTC on Oct. 4, 2026, and the bot’s operator, the French company Tellter SAS, counts roughly 28 million Discord accounts’ IDs and usernames among the data it treats as exposed. The count is deliberately broad: part of one table was copied, and Tellter could not tell which rows, so it counted all of them.
Double Counter is an alt-account detection and verification bot that sits in more than 600,000 Discord communities, which is why a single compromised server reached so many people who never signed up for anything else the company sells.
Copied rows and exposed rows in Tellter’s report
The operator’s incident report, INC-2026-10-04, sorts the data into tiers. Discord user IDs and usernames for about 28 million accounts are marked “partly copied (treated as exposed).” IP addresses with coarse location for about 27 million accounts get the same label. About 25 million one-way user-agent hashes and about 1.0 million de-duplicated email addresses are listed as copied outright.
The reasoning behind the wording sits in two tables of IP records. The alt-detection table, about 5.4 million rows, was copied in full. The verified-users table, about 21.7 million rows, was cut off partway, with an estimated 20% leaving. Since the affected rows cannot be identified, Tellter treats the entire table as exposed, and the user-ID figure follows the same logic.
Tellter lists what stayed out of reach: roughly 15 million VPN-detection records were not copied, a cold-storage database covering about 58 million users sits outside the affected infrastructure, and a separate behavioural-data store was confirmed unaccessed. Discord passwords never reach the bot, and card details are held by the payment provider.
Metabase on a retired OVH server
The way in was an old machine. According to the report, a retired OVH server was still running a publicly reachable, self-hosted Metabase analytics tool, and a vulnerability in that tool let the intruder forge an administrator session. Two credentials left on the server, a cloud service-account key and an administrator’s saved session, opened the production cloud environment from there. Digital Citizen’s summary notes that Tellter names neither a CVE nor a Metabase version.
Per the report and the account on The CyberSec Guru, cloud access began at 12:03 UTC. The intruder added an SSH key, exported a database, and lifted the Discord bot token from a running container. With the token, the intruder posted invitations to a server of their own in about 50 large communities and gained admin rights on Double Counter’s support server. Resetting the token did not help at first: access to the infrastructure let the intruder fetch the replacement within minutes. The last recorded action came at 17:54 UTC, and service returned at 19:19 with new credentials.
A full 5.0 GB export was created at 12:35 UTC and never downloaded, according to the CyberSec Guru account of the report.
The 275,000 emails and the $7,316 card charge
An outside count exists for the emails. the HIBP breach database added the entry on Oct. 7 with 274.9 thousand affected addresses, the set that was later published publicly. Its entry lists email addresses, geographic locations, names and usernames, and notes that a small number of paying subscribers’ records carried names, countries and postcodes. Tellter’s own copied total of about 1.0 million emails, about 840,000 of them tied to its sister lookup tool Doogle, is close to four times the published set.
Money also moved. The intruder used a payment-provider key belonging to Atis, a separate Tellter product, to run test charges of $1, $10, $100 and $1,000 on a company card, totalling $7,316, plus two small customer charges of $3 and $15 that were refunded. The Double Counter and Doogle payment account showed no unauthorized charges, the report states.
Discord said its own systems were not breached, and Dexerto reports that the platform disabled new installs of the bot while it works with the developer on the incident. Tellter notified France’s data protection authority, the CNIL, on Oct. 5 and says it is pursuing those responsible.
For server administrators, Tellter’s instruction is specific: delete any Double Counter invite messages posted between 12:00 and 16:30 UTC on Oct. 4, and check the audit log for bot actions in that window. Members who verified between 13:39 and 14:49 UTC and never received their role are told to verify again. The report promises an update when the investigation closes.
One boundary matters for anyone checking their own exposure: Tellter says Double Counter never receives Discord passwords, so the exposed material is identity and network detail, namely IDs, usernames, approximate location and, for about 1.0 million people, an email address, rather than login credentials. The company adds that it will never ask for a password, token or payment by email or private message, which makes any message claiming to come from Double Counter and asking for one a phishing attempt by definition.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview