Discord has suspended new installations of Double Counter after the anti-raid and alt-account detection bot was compromised. The incident was not a breach of Discord’s own infrastructure, Discord said, but it could affect millions of users whose information was held by the third-party service.

Double Counter said an attacker exploited a vulnerability in an old server that still had the Metabase analytics tool running, then obtained credentials for the service’s cloud infrastructure. The attacker spent nearly six hours in that environment and copied about 12GB of data.

  • About 28 million Discord user ID and username records were in an affected table, though the dataset was copied only partially.
  • About 27 million records containing IP addresses and approximate geolocation data were also copied only partially. The location data can indicate a city or region, not an exact GPS position.
  • Around 25 million hashes used to identify alternate accounts were copied in full.
  • Roughly 1 million email addresses were copied in full.

Discord passwords and payment-card numbers were not stored in the affected database, according to Double Counter. The attacker also took control of the bot and used it to distribute invitations to an attacker-controlled Discord server across about 50 large communities. A stolen payment key was separately used for $7,316 in fraudulent charges on the company’s card.

A publicly posted dataset containing about 275,000 unique email addresses and usernames has already been logged by Have I Been Pwned. Even where passwords were not exposed, the combination of account names, email addresses and rough geographic information could make phishing messages more convincing. Discord and Double Counter are still working to establish the full scope of the incident.

SOURCEtech.yahoo.com
Previous articleAcer Iconia Tab 11 5G launches in India with dual-SIM support and Android 16