Incident
Published 2026-10-05
Verified 2026-10-07

Double Counter (Discord anti-alt bot) breach: attacker used a Metabase flaw on a retired server to steal admin cloud credentials, hijacked the bot to spam about 50 large servers and copied IP-address data; HIBP adds 275,000 email addresses

Tellter SAS, which runs the Discord server protection bot Double Counter, published an incident report (version 1.9, last updated 5 October 2026) on a multi-stage attack on 4 October 2026. The way in was an old server from its previous OVH hosting that was no longer used but still ran a publicly reachable self-hosted Metabase analytics instance; a Metabase vulnerability let the attacker forge an administrator session and reach the host. The company does not name a CVE. That server held a cloud service-account key with administrator rights and an administrator's saved command-line session. With them the attacker added an SSH key, exported a database to a bucket, read the bot's Discord token from a running container, gave itself admin on the support server and posted links to its own Discord server in about 50 large servers using the bot. It read a replacement token within two minutes, deleted backups, changed the database admin password and copied about 12 GB before being cut off around 17:55; the service was restored at 19:19 with new credentials. Exposed data includes IP-address records for alt detection (about 5.4 million copied in full) and a verified-users table (about 21.7 million rows, treated as wholly exposed though about 20% left). The attacker also used a stolen Stripe key for Tellter's separate Atis product to charge three cards. Have I Been Pwned loaded the published data on 7 October: 274,922 unique email addresses with Discord usernames, plus names, countries and postcodes for a small number of paying subscribers. Discord passwords and stored card numbers were not exposed. Primary: Double Counter incident report.

Product
Double Counter Discord bot (Tellter SAS); self-hosted Metabase on a retired OVH server
Versions
n/a — incident (Metabase version and CVE not disclosed)
Exploited in Australia?
unknown
Patch to
Users: check your email on Have I Been Pwned and ignore Discord invites or DMs that arrived through Double Counter on 4 October. Operators: switch off and wipe retired servers rather than leaving them running, keep Metabase and other admin tools patched and off the internet, never leave administrator cloud keys or saved CLI sessions on application hosts, and rotate bot tokens and payment keys straight after any host compromise.

Primary: Double Counter — Security incident, October 2026 (INC-2026-10-04, version 1.9, updated 5 Oct 2026) · Vendor: Have I Been Pwned — Double Counter breach (added 7 Oct 2026)

breaches cloud identity