SecurityOctober 7, 20267 min read

What to Do After the Double Counter Discord Data Breach (2026)

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the Double Counter Discord Data Breach (2026)

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

If you were in a Discord server protected by Double Counter, assume your email address and Discord username are now public. The breach exposed roughly 275,000 email addresses and usernames, plus names, countries, and postcodes for a smaller set of paying subscribers. No Discord passwords or card numbers were taken. Change reused passwords, enable 2FA, and expect targeted phishing.

What Was Exposed

Confirmed: about 275,000 unique email addresses and Discord usernames; names, countries, and postcodes for a small number of subscribers whose payments ran through Stripe. Not exposed: Discord account passwords, full payment card details. How: an attacker exploited a vulnerability in an exposed Metabase analytics instance on October 4, 2026, obtained service account keys and an administrative session, copied roughly 12 GB of data, deleted backups, and changed the database password before being locked out. The leaked set has since been published publicly and indexed by breach-notification services.

What Double Counter Is, and Why Your Email Is in It

Double Counter is a third-party Discord server-protection service used by community operators to screen for alt accounts and ban evasion. Server members never sign up for it directly, which is why the breach catches people by surprise: your email address and username were held by a vendor you never chose, because a server you joined used it. Discord's own systems were not breached in this incident — the exposure sits with the vendor. (This is a separate event from the earlier third-party customer-support vendor incident that exposed a batch of identity documents submitted to Discord support.)

Reporting around the incident has cited far larger figures for the number of Discord account identifiers held in the service's database. Treat the confirmed, verifiable number as the one that affects you: roughly 275,000 email addresses in the published corpus. If your address is in it, the practical risk is the same either way.

Step 1: Confirm Whether You Are Affected

Check your email addresses — every one you have used to register a Discord account, including throwaway aliases — against a breach-notification service such as Have I Been Pwned, which lists the Double Counter corpus. Search your inbox for mail from server-verification bots, and for any notice from a server you are in. If you have been in large public gaming, crypto, trading, or NFT Discords, your odds are higher: those are exactly the communities that deploy alt-detection tooling.

Step 2: Secure the Discord Account First

  • Change your Discord password now if it is reused anywhere else. The breach did not include passwords, but your email and username are now a confirmed pair for credential-stuffing attempts.
  • Turn on two-factor authentication in User Settings → My Account, using an authenticator app rather than SMS.
  • Review authorized apps under Settings → Authorized Apps and revoke any bot or service you no longer recognize.
  • Check active sessions under Settings → Devices and log out of everything unfamiliar.
  • Hide your email from servers and tighten Privacy & Safety settings so direct messages from non-friends are filtered.

Step 3: Expect Phishing That Knows Your Username

The dangerous combination here is email address plus Discord username. That lets an attacker write a message that looks like it comes from Discord, from a server moderator, or from Nitro billing, and reference details that feel private. In the weeks after a breach like this, expect:

  • Fake Discord login pages delivered by email or DM, harvesting your password and 2FA code in real time.
  • “Free Nitro” and giveaway lures that require an OAuth authorization or a QR-code scan — scanning a QR code with the Discord app can hand over your session.
  • Moderator impersonation claiming your account is flagged for ban evasion and demanding verification.
  • Extortion email quoting your username as “proof” of access to your account or device.

The One Rule That Blocks All of It

Discord will never ask you to scan a QR code, authorize an app, or enter your password to resolve a moderation issue, verify ownership, or claim Nitro. Navigate to discord.com yourself; never through a link in a message.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 4: Break the Email Reuse Chain

A leaked email address is only valuable because of what else it unlocks. Change the password on any account that shares a password with your Discord login, starting with your email itself, then move to a password manager so each service has a unique credential. If your gaming accounts (Steam, Epic, Riot, Roblox) share the same address and password, treat those as exposed too. Where a service offers it, switch to a passkey, which cannot be phished or stuffed.

Step 5: Decide Whether to Retire the Address

If the exposed address is one you use for banking, work, or account recovery, consider moving those accounts to a fresh address and demoting the leaked one to low-value signups. Email aliasing — a different alias per service — means the next vendor breach exposes an address that leads nowhere.

Step 6: Reduce What Else Can Be Joined to Your Username

Breach data becomes dangerous when it is cross-referenced. An email address plus a username plus a people-search listing gives a stranger your legal name, home address, phone number, and relatives — everything needed to escalate from spam to doxxing or SIM-swap fraud. Data brokers publish that second half, and they publish it whether or not you have ever been breached.

PrivacyOn removes your personal information from 100+ data broker and people-search sites, monitors for relisting 24/7 and refiles automatically, and includes dark web monitoring that tells you when your email or other details surface in a new dump. One plan covers up to 5 family members from $8.33/month.

Check Your Exposure in Minutes

Run a free PrivacyOn scan to see which data brokers currently publish your name, address, and phone number — the details that turn a leaked email address into a real-world problem — then let PrivacyOn remove them and keep watch.

Frequently Asked Questions

Was Discord itself hacked in the Double Counter breach?

No. The breach happened at Double Counter, a third-party server-protection service that community operators install. Discord's own infrastructure and password database were not involved, but members of servers using the tool had their email addresses and usernames exposed.

Were Discord passwords or credit cards leaked?

No Discord passwords and no full payment card numbers appear in the published data. A small number of paying subscribers had names, countries, and postcodes exposed through Stripe-processed purchase records.

How do I know if my email was in the Double Counter leak?

Search each of your email addresses on a breach-notification service that lists the Double Counter corpus, such as Have I Been Pwned. Check aliases and old addresses too — people often registered Discord with an address they no longer use daily.

Do I need to change my Discord password?

Change it if that password is used anywhere else, and enable app-based two-factor authentication either way. Passwords were not in the leak, but a confirmed email and username pair is exactly what credential-stuffing tools need.

Should I delete my Discord account?

Deleting it does not unpublish data that is already circulating, so it rarely helps. Securing the account with 2FA and a unique password, revoking unknown authorized apps, and hiding your email from servers achieves more.

What is the long-term risk from an exposed email address?

Persistent phishing and credential stuffing, and — when the address is joined to broker records that hold your real name, home address, and phone number — doxxing, SIM-swap attempts, and account-recovery fraud. Removing those broker listings, which is what PrivacyOn automates across 100+ sites, is the part you can still control.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families