Full Report
In October 2026, the Discord server protection service Double Counter suffered a data breach attributed to a vulnerability in the Metabase analytics tool. In its disclosure notice, Double Counter advised that attackers gained access to a subset of its data. A corpus of data was subsequently published publicly and contained 275k unique email addresses and Discord usernames. A small number of records belonging to paying subscribers whose purchases were processed via Stripe were also present and included names, countries and postcodes.
Analysis Summary
# Incident Report: Double Counter Data Breach via Metabase Vulnerability
## Executive Summary
In October 2026, the Discord server protection service Double Counter experienced a data breach resulting from a vulnerability in its Metabase analytics tool. Attackers successfully exfiltrated a dataset containing approximately 275,000 unique records, which were subsequently published online. The incident compromised user Discord identities and limited PII of paying subscribers.
## Incident Details
- **Discovery Date:** October 2026 (exact day not specified)
- **Incident Date:** October 2026
- **Affected Organization:** Double Counter
- **Sector:** Technology / Discord Security Services
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** October 2026
- **Vector:** Exploitation of a software vulnerability.
- **Details:** Attackers exploited a security flaw within the Metabase analytics tool used by Double Counter to gain unauthorized access to the backend database.
### Lateral Movement
- **Details:** Information not publicly disclosed; however, the attacker moved from the Metabase interface to the underlying data stores containing user and subscriber information.
### Data Exfiltration/Impact
- **Details:** Attackers exfiltrated a subset of data containing 274,900 unique email addresses and Discord usernames. A smaller subset of data related to Stripe payments (names, countries, and postcodes) was also stolen.
### Detection & Response
- **How it was discovered:** Likely via internal monitoring or the public release of the data corpus.
- **Response actions taken:** Double Counter issued a formal disclosure notice and notified affected users via their official blog.
## Attack Methodology
- **Initial Access:** Exploitation of a vulnerability in a third-party analytics tool (Metabase).
- **Persistence:** Not disclosed.
- **Privilege Escalation:** Not disclosed.
- **Defense Evasion:** Not disclosed.
- **Credential Access:** Access to the database likely allowed direct harvesting of Discord usernames and email addresses.
- **Discovery:** Reconnaissance of the Metabase environment.
- **Lateral Movement:** Pivot from Metabase tool to database records.
- **Collection:** Gathering of user profiles and payment-related metadata.
- **Exfiltration:** Transfer of data for public release.
- **Impact:** Data breach and public exposure of user identities.
## Impact Assessment
- **Financial:** Potential loss of subscribers; no direct theft of funds reported, though payment metadata was exposed.
- **Data Breach:** ~275,000 unique email addresses and Discord usernames; subscriber names, countries, and postcodes.
- **Operational:** Disruption for remediation and security patching of the Metabase tool.
- **Reputational:** High; as a security-focused service for Discord, a breach of user Discord identities significantly impacts trust.
## Indicators of Compromise
- **Network indicators:** N/A - Not disclosed in the report.
- **File indicators:** N/A - Not disclosed in the report.
- **Behavioral indicators:** Unusual query patterns or unauthorized export activity originating from the Metabase service account.
## Response Actions
- **Containment measures:** Identification and isolation of the vulnerable Metabase instance.
- **Eradication steps:** Vulnerability patching or version upgrades for Metabase.
- **Recovery actions:** Public disclosure issued via hxxps[://]doublecounter[.]gg/blog/security-incident-october-2026.
## Lessons Learned
- **Key takeaways:** Third-party analytics tools often represent a significant "side-door" into sensitive production databases.
- **What could have been done better:** Stricter network segmentation between analytics tools and production data, and more frequent patching of secondary software components (Metabase).
## Recommendations
- **Patch Management:** Implement a rigorous patching schedule for all third-party integrations, particularly data visualization and analytics tools.
- **Principle of Least Privilege:** Ensure the service account used by Metabase has read-only access limited strictly to the tables required for reporting, excluding PII where possible.
- **Monitoring:** Implement alerting for large data exports or unusual query volumes from analytics platforms.
- **User Security:** Encourage all affected users to rotate passwords and enable Two-Factor Authentication (2FA) on their Discord and associated email accounts.