Discord authentication bot "Double Counter", which was supposed to stop people from creating alt accounts and evading bans, has been subjected to a cyberattack, resulting in approximately 12 GB of data being copied from one of its databases.
For those unfamiliar with Double Counter, it's a third-party Discord bot used by servers to verify users and detect alternate accounts. Ironically enough, the very service designed to keep people from evading bans has now leaked a shitload of user data.
Here's the reported breakdown:
・Email addresses: approximately 1 million
・Browser identification hashes: approximately 25 million
・Discord IDs/usernames: approximately 28 million
・IP addresses/location information: approximately 27 million
The IP-related data reportedly includes information such as country, region, city, postal code and ISP. Not exactly the sort of information you'd want floating around.
Individuals who previously went through Double Counter verification may have had their Discord information, IP address and other identifying data exposed. Some reports have also confirmed that a portion of the leaked email addresses and usernames has already been published online.
Please exercise extreme caution regarding suspicious emails or Discord messages pretending to be official communications. A leak like this is basically a phishing kit waiting to happen.
And once again, this is why I don't particularly like handing third-party bots a bunch of information just because a Discord server wants to know whether I have an alt account.
