Key Takeaways:
- Double Counter disclosed a Discord Double Counter breach affecting its cloud systems on October 4.
- Attackers gained access to a bot container but did not download the database export.
- A stolen payment key led to $7,316 in fraudulent charges.
Double Counter, a security bot provider, suffered a cloud system breach on October 4. An attacker gained access to its cloud servers, exposed tokens, and used a stolen payment key to make fraudulent charges.
Cloud Breach Exposes Discord Tokens
Double Counter disclosed a security breach affecting its cloud systems. The Discord Double Counter breach occurred when an attacker gained access to the company’s cloud environment at 12:03.
The attacker added a secure shell key to the system and then opened a shell inside a bot container to run commands. This gave the attacker access to a Discord token.
The breach affected Double Counter’s systems, not Discord itself. The company contained the attack by the evening and restored normal service at 19:19 after making emergency repairs.
Fraudulent Charges Follow Cloud Breach
The attacker tried to export an internal database to a storage bucket. However, investigators found that the attacker did not download the database export file.
User passwords and stored card numbers were not affected. Cold storage containing information related to nearly 58 million users was also not affected by the Discord Double Counter breach.
However, a stolen Stripe key led to financial losses. The key was used to make $7,316 in fraudulent charges against a company card account on another platform. Two customer charges were identified and refunded.
Some other company accounts also experienced minor disruptions during the incident. Security teams tracked the unauthorized transactions and secured the affected billing systems.
Security Team Restores Service And Access
The company’s technical team moved quickly to contain the breach and protect its systems. It shut down the old server, removed existing cloud access, and changed credentials for active administrator accounts.
The team also deleted exposed webhooks and moved internal databases behind private networks to limit future access. The affected token was moved to a dedicated system for storing sensitive information.
The company’s response to the Discord Double Counter breach also included adding access logs and continued monitoring after service was restored. Investigators checked 14 separate cloud projects for signs of further problems.
The checks found no active backdoors in the company’s cloud systems. Double Counter said it will continue improving its security measures to protect its users and services.
Visit more of our news! CyberPro Magazine




