Security News Discord indirectly hacked

Security News
1 Reply 50 Views

TuxTalk

Level 21
Verified
Top Poster
Well-known

Summary​

On 4 October 2026, Double Counter was the target of a deliberate, multi-stage attack. The attacker broke into a server from our previous hosting setup through a vulnerability in an analytics tool it was still running, then used credentials found on that server to reach our cloud infrastructure and adapted to each of our containment steps. During the attack they took control of the bot’s Discord token, used it to post links to their own Discord server in about 50 large servers, copied part of one of our databases, and used a stolen payment key to commit financial fraud on a separate account.

We cut off their access, found no persistence, replaced the exposed credentials and restored the service at 19:19. We sincerely apologise to everyone affected.
  • 5 h 51 min of attacker activity in our cloud (12:03 → 17:54).
  • About 12 GB copied from one of our databases (15:09 → 15:34).
  • About 50 large servers where the bot posted the attacker’s links.
  • $7,316 in fraudulent charges on a separate payment account. Customer funds are safe.
 
Summary On 4 October 2026, Double Counter was the target of a deliberate, multi-stage attack. The attacker broke into a server from our previous hosting setup through a vulnerability in an analytics tool it was still running, then used credentials found on that server to reach our cloud infrastructu […]


Hi TuxTalk. “Discord indirectly hacked” is fair shorthand, but Discord’s own platform was not breached. Double Counter—a third-party bot trusted by many Discord servers—was compromised, and its stolen token allowed the attacker to act with whatever permissions those servers had granted the bot.

The bot spam is only the visible part. The more serious issue is the copied user data: Have I Been Pwned has already indexed a publicly released corpus containing 274,922 unique email addresses and Discord usernames, with names and location details in some subscriber records (HIBP). That creates a credible phishing and impersonation risk, although it does not mean those users’ Discord passwords were stolen.

Practical response:

  • Server administrators: review the Discord audit log for 4 October, remove unexpected invitations posted by Double Counter, and review the bot’s permissions. Bots rarely need the full Administrator permission.
  • Members who only saw the message: there is no reason to reset Discord credentials solely because of this incident. Avoid the advertised server and expect more convincing phishing using leaked usernames or email addresses.
  • Anyone who entered credentials, scanned a login QR code, authorized an application, or ran a download after following one of the links: change the Discord password from a trusted device, revoke sessions and unfamiliar authorized apps, enable MFA, and investigate the device as a possible compromise.
  • Treat password-expiry or account-warning emails cautiously; wording alone proves nothing, so open the service directly and inspect the actual sender and destination rather than using the email button.

The incident report also offers a useful lesson: the “retired” server remained publicly reachable and held an administrator-level service-account key plus a saved administrator session. Retired but still online is really just forgotten with better branding. The attacker could even read a replacement bot token within two minutes because the underlying cloud access had not yet been eliminated—an excellent example of why containment should revoke identities and active sessions before rotating downstream secrets.

Double Counter reports that its audit found no remaining backdoor and that credentials were replaced, but that is appropriately a company finding, not independent proof that persistence was impossible.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top