Discord server protection service Double Counter disclosed a data breach on October 4, 2026, attributed to a vulnerability in the Metabase analytics tool. Attackers accessed a subset of the service’s data, and a subsequently published corpus contained approximately 275,000 unique email addresses, along with Discord usernames. Have I Been Pwned added the breach to its records on October 7.
The exposed data also included a small number of paying subscribers’ records containing names, countries, and postcodes, associated with purchases processed through Stripe; the reported incident does not establish a breach of Stripe itself. The combination of email addresses, Discord identities, and subscriber details creates opportunities for targeted phishing and impersonation. Affected users should be alert to messages posing as Double Counter or payment support, while organizations operating Metabase should review security updates and restrict access to analytics systems.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
On October 4, 2026, responders ended the attacker's cloud access around 17:55 by revoking stolen administrator sessions, after bot-token rotation and service-account key revocation failed to fully contain the intrusion. Double Counter restored service at 19:19 and strengthened credential storage, private networking, and monitoring.
On October 4, 2026, the attacker abused an exposed Stripe key belonging to Atis, a separate Tellter product, for reported fraudulent charges totaling $7,316. Two Atis customer charges of $3 and $15 were refunded, and payment-provider keys were revoked at 17:14 UTC.
Double Counter disclosed the incident and stated that attackers had accessed a subset of its data, attributing the breach to a Metabase vulnerability.
Double Counter, a Discord server protection service, suffered a breach attributed to a vulnerability in the Metabase analytics tool. Attackers gained access to a subset of the service's data.
A subsequently published corpus contained approximately 275,000 unique email addresses and Discord usernames. It also exposed names, countries, and postcodes for a small number of paying subscribers whose purchases had been processed through Stripe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethecybersecguru.com
Open sourcehaveibeenpwned.com
Open sourcedoublecounter.gg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.