Hackers have stolen approximately one million email addresses and a potentially far larger number of Discord user IDs and IP addresses in a sustained cyberattack on Double Counter, a third-party security service used by the chat platform. The breach was not a direct intrusion into Discord's own systems but a deliberate, multi-stage operation targeting the security provider's infrastructure.
Double Counter has described the incident as a «deliberate, multi-stage attack» in which the intruders spent nearly six hours exploring its systems before the vulnerability was identified and closed. The company confirmed the theft of user data but has not yet disclosed the full scale of the compromise, leaving open the possibility that the number of affected accounts is considerably higher than the one million email addresses initially reported.
The attack highlights a growing risk in the digital ecosystem: third-party services that integrate with major platforms often hold sensitive user information, and their security posture can determine the exposure of millions of people. Discord, which is widely used by gaming communities, has faced previous data breaches, but this incident shifts attention to the supply chain of security tools that are meant to protect users rather than expose them.
According to details released by Double Counter, the hackers moved through its infrastructure methodically over several hours. The breach was eventually contained, but not before a substantial volume of data had been extracted. The stolen information includes email addresses, Discord user IDs, and IP addresses — a combination that could be used for targeted phishing, account takeover attempts, or further malicious activity.
The incident raises questions about how third-party security services are vetted and monitored, particularly when they handle authentication or verification functions for large platforms. While Discord itself was not directly breached, the data belongs to its users, and the platform may face pressure to review its partnerships with external providers.
Double Counter has not indicated whether it has notified affected users or whether law enforcement has been engaged. The company's statement emphasised the deliberate nature of the attack, suggesting that the intruders were not opportunistic but specifically focused on its systems. The near six-hour window before the vulnerability was closed indicates a prolonged period of unauthorised access.
For Discord users, the immediate risk lies in the potential for phishing emails and messages that reference their actual user IDs or email addresses, making fraudulent communications more convincing. Security experts generally advise changing passwords, enabling two-factor authentication, and being cautious of unsolicited contact that appears to come from Discord or related services.
The breach also underscores the broader challenge facing platforms that rely on external security providers. As digital services become more interconnected, a single weak point in the chain can expose vast amounts of personal data. The incident is likely to renew calls for stricter oversight of third-party vendors and more transparent disclosure requirements when breaches occur.
Double Counter has not yet published a detailed timeline of the attack or a full accounting of the data taken. The company's confirmation of the breach, however, makes it one of the more significant supply-chain incidents affecting the Discord ecosystem in recent years. Further details are expected as the investigation continues.