Gaming chat app Discord has experienced another user data breach, with hackers reportedly stealing approximately 1 million email addresses alongside user IDs and IP addresses. The breach did not target Discord directly, but rather its third-party security service, Double Counter. Security researchers at Double Counter reported that a "deliberate, multi-stage attack" allowed hackers to access their systems for nearly six hours before the vulnerability was secured.
Double Counter operates as a bot designed to protect Discord servers by detecting and blocking unauthorized alt accounts and preventing malicious raids. While its effectiveness is debated among users, and the service has faced accusations of selling user data in the past, it nonetheless collected and stored personal information from users on protected servers. This data is now compromised.
According to Double Counter's estimates, around 1 million user email addresses were affected. Additionally, databases containing Discord IDs, usernames, IP addresses, and location data for up to 28 million users were "partly" copied. Security breach trackers Have I Been Pwned have confirmed that 275,000 of the stolen email addresses and usernames have been publicly posted.
This incident follows a similar breach approximately one year prior, when cybercriminals compromised one of Discord's customer service partners, reportedly obtaining tens of thousands of users' government-issued IDs. These repeated security lapses, even when originating from third-party providers, reflect poorly on Discord's overall security posture. The latest breach also occurs during a troubled rollout of Discord's age verification system, which has faced scrutiny in the UK for allegedly funneling data into a company linked to Peter Thiel.