DO

Double Counter

Medium

In October 2026, Double Counter experienced a breach exposing data of 275,000 users due to a Metabase vulnerability.

274,922 recordsBreach Oct 4, 2026Updated Oct 7, 2026

Exposed data classes

Fields reported as compromised in this breach record.

Email addressesGeographic locationsNamesUsernames

Detailed Analysis

In-depth analysis of the breach and its implications.

In October 2026, the Discord server protection service Double Counter experienced a data breach resulting from a vulnerability in the Metabase analytics tool. Unauthorized access enabled attackers to obtain and publicly disclose a subset of the platform's data, affecting approximately 275,000 unique individuals. Among the exposed data were email addresses, usernames, geographic locations, and Discord usernames. Additionally, a limited number of records from paying subscribers, including names, countries, and postal codes processed via Stripe, were compromised.

Impact Analysis

Understanding the scope and consequences of this breach.

User Impact
Exposure of personal information, including email addresses and usernames, leading to privacy concerns.
Business Impact
Potential loss of user trust, regulatory scrutiny, and infringement on data security policies.
Affected Sectors
  • Online Services
  • Cybersecurity
Geographic Impact
  • Global

What You Should Do

Recommended actions to take in response to this breach.

If You Were Affected

  • •Use HIBP (Have I Been Pwned) to check if your email is included and change related passwords immediately.
  • •Enable and maintain two-factor authentication on all accounts for added security.
  • •Be vigilant for phishing attempts leveraging your email or usernames from this breach.

Preventive Measures

  • •Ensure robust security for third-party tools integrated into systems.
  • •Conduct routine vulnerability assessments and apply patches promptly.
  • •Educate employees about the impact of unsecured third-party analytics software.

Frequently Asked Questions

Common questions about this breach and what it means for you.

The breach exposed email addresses, geographic locations, names, usernames, and a limited number of financial transaction details.