{"id":380160,"date":"2026-10-07T10:16:00","date_gmt":"2026-10-07T17:16:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=380160"},"modified":"2026-10-07T10:16:15","modified_gmt":"2026-10-07T17:16:15","slug":"discord-bot-double-counter-breached-275000-email-addresses-exposed","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/discord-bot-double-counter-breached-275000-email-addresses-exposed\/","title":{"rendered":"Discord bot Double Counter breached: 275,000 email addresses exposed"},"content":{"rendered":"<p class=\"wp-block-paragraph\"><a href=\"https:\/\/discord.en.softonic.com\/\" rel=\"noopener\">Discord<\/a> moderation bot <a href=\"https:\/\/double-counter.en.softonic.com\/\" rel=\"noopener\">Double Counter<\/a> has been breached, exposing user data and <strong>about 275,000 unique email addresses<\/strong> tied to the third-party security bot. Double Counter says the bot is used on more than 600,000 servers. Discord says its own platform wasn&#8217;t directly compromised, but the leak still exposed around 275,000 unique email addresses, which were later posted alongside usernames. Attackers also got access to Discord usernames, user IDs, IP addresses, and, in some cases, names, location details, country, and postcode data.<\/p>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Discord\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/9848e854-ffae-11e6-a59d-00163ed833e7\/1112163749\/discord-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Discord<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/discord.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/discord.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Double Counter also says <strong>datasets linked to as many as 28 million users<\/strong> may have been copied in part.<\/p>\n\n<p class=\"wp-block-paragraph\">Reports say the attackers got in through a <strong><a href=\"https:\/\/metabase.en.softonic.com\/\" rel=\"noopener\">Metabase<\/a> vulnerability<\/strong> and stayed inside Double Counter&#8217;s systems for nearly six hours, which makes this look like a targeted attack. Double Counter says it keeps IP addresses linked to Discord user IDs for up to 24 months so it can spot alt accounts, ban evasion, spam, and raids. The leaked data was reportedly posted on Doogle and made searchable for a fee.<\/p>\n\n<p class=\"wp-block-paragraph\">If you&#8217;re in Discord communities that depend on moderation bots, <strong>pay attention to this one<\/strong>. It adds to the privacy concerns already hanging over Discord after <a href=\"https:\/\/en.softonic.com\/articles\/discord-confirms-that-its-users-data-has-been-compromised\" rel=\"noopener\">earlier partner breaches<\/a>, including exposed ID images, and it makes stricter privacy measures like age checks even harder to trust. You can use Discord on the web, <a href=\"https:\/\/ios-data-recovery.en.softonic.com\/\" rel=\"noopener\">iOS<\/a>, Android, Windows, and Mac, but this breach involves the Double Counter bot, not Discord&#8217;s own servers.<\/p>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"NordVPN\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/6edeb839-ad87-4a36-8a90-f8c37d491340\/3661486701\/nordvpn-icon.webp\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">NordVPN<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/nordvpn.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/nordvpn.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Discord moderation bot Double Counter has been breached, exposing user data and about 275,000 unique email addresses tied to the third-party security bot. Double Counter says the bot is used on more than 600,000 servers. Discord says its own platform wasn&#8217;t directly compromised, but the leak still exposed around 275,000 unique email addresses, which were &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/discord-bot-double-counter-breached-275000-email-addresses-exposed\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Discord bot Double Counter breached: 275,000 email addresses exposed&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9351,"featured_media":380159,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[6823],"class_list":["post-380160","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","content-category-games"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/380160","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9351"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=380160"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/380160\/revisions"}],"predecessor-version":[{"id":380161,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/380160\/revisions\/380161"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/380159"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=380160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=380160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=380160"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=380160"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=380160"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=380160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}