Skip to content
logo The magazine for digital lifestyle and entertainment
Data protection News Security All topics
Current Incident

Hackers Steal Data From Up to 28 Million Discord Users

Discord Logo on a Smartphone
Discord Users Targeted: Security Service Reports Major Hacking Attack Photo: SOPA Images/LightRocket via Gett

October 8, 2026, 3:37 pm | Read time: 2 minutes

An attack on the security service “Double Counter” could have consequences for millions of Discord users. The perpetrators gained access to internal systems and copied large amounts of data. The security service is used by hundreds of thousands of servers to detect fake accounts and bot attacks.

Hackers Exploit Security Flaw

Discord itself was not the focus of the attack, but rather the security service Double Counter. According to the company, a hacker gained access to parts of the cloud infrastructure on October 4. The entry point was apparently a security flaw in an analytics tool on an older server. The incident report states that the attacker remained in the systems for nearly six hours and copied around 12 gigabytes of data from a database during that time.

More on the topic

Millions of Records Could Be Affected

The potential impact of the incident is particularly alarming. Double Counter believes that up to 28 million Discord accounts could be affected, including Discord IDs and usernames. Additionally, the attackers may have accessed information on around 27 million IP addresses and general location data.

According to the company, the hackers also copied the email addresses of about one million accounts. Since it is no longer possible to determine which datasets were fully transferred, Double Counter is treating all potentially affected information as compromised as a precaution.

Also of interest: Security Measures After Data Theft in Berlin

The hackers also gained access to Double Counter’s Discord bot. Using a stolen bot token, invitation links to a foreign Discord server were published in about 50 larger communities. Additionally, fraudulent withdrawals totaling $7,316 were made through a separate payment account.

No Passwords Compromised

There is at least some good news for users: According to Double Counter, the attackers were unable to access Discord passwords or credit card data. The reason is that the service does not store passwords, while external payment service providers manage payment information. Following the incident, the company replaced all compromised access data and tightened security measures. Double Counter resumed operations on the day of the attack.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.