← Double Counter

2026 Double Counter — Metabase/OVH path; ~28M Discord users + ~1M emails treated exposed

2026 28.0M records affected Share on X

Data compromised

Company treats as exposed: ~28M Discord user IDs/usernames; ~27M IPs + coarse geolocation; ~25M user-agent hashes; ~1.0M emails. HIBP public corpus 274,922 emails+usernames. Bot token abused (~50 servers). Stripe key fraud (refunded). Cold storage ~58M not affected.

Technical writeup

Verified company incident report INC-2026-10-04 (published Oct 5, 2026) — On October 4, 2026 (12:03–17:54 UTC; restored 19:19), attackers accessed Double Counter via a retired OVH server that remained publicly reachable and ran self-hosted Metabase. A Metabase vulnerability enabled a forged administrator session; stored cloud credentials then provided access to live systems. About 12 GB was copied from one database (~15:09–15:34). Company data table: ~28M Discord user IDs/usernames and ~27M IP/geolocation records partly copied but treated as exposed; ~25M user-agent hashes and ~1.0M deduplicated emails fully copied; VPN logs and behavioural fingerprints not copied; cold-storage ~58M users not affected. Stolen Discord bot token posted attacker invites in about 50 large servers; stolen Stripe key used for $7,316 test charges on a company card and small charges on two customer cards (all refunded). Reported to French data protection authority; Discord disabled new installs. Have I Been Pwned (Oct 7) loaded a public corpus of 274,922 unique emails with Discord usernames. recordsAffected 28000000 reflects company-treated Discord account exposure.

Root cause

Retired OVH server still public running self-hosted Metabase; forged admin session → cloud credentials (company INC-2026-10-04)

References