Discord Anti-Raid Bot Double Counter Hit By Hack, 1 Million Emails Leaked
A hacked server-management bot can be turned into the attack, so the same tool administrators added to police their servers spent the breach window mailing invites to roughly 50 large servers using Double Counter.
Reporting from 1 source: Automaton.
Tellter reported on October 5 that its Discord bot Double Counter suffered a targeted attack. An attacker exploited a vulnerability in an analytics tool on an old server, took credentials left there, and reached the company cloud environment for about six hours, copying roughly 12 GB of data. About 1 million email addresses leaked, along with roughly 28 million Discord IDs and usernames and 27 million IP addresses and location data.
The intruder worked from a vulnerability in an analytics tool on a server Tellter had previously used, then took credentials left there to enter the cloud environment. The company says it has recovered on new credentials and restored the service, and that a check found no backdoor left behind.
No unauthorized charges have appeared on payment accounts such as Double Counter, but fraudulent charges using stolen payment service authentication keys did hit another Tellter service, and the amounts billed to customers have been refunded. Discord passwords and card details have not leaked because Double Counter does not collect them.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.