Double Counter Data Breach Exposed 274,922 Users
Attackers leaked a massive dataset of emails and Discord usernames following a vulnerability exploit.
Updated on Oct. 7, 2026 in Cybersecurity

Live Poll
Do you trust online services to keep your personal payment information secure?
Double Counter recently suffered a data breach involving a vulnerability in the Metabase analytics tool. The incident resulted in the exposure of 274,922 unique email addresses and Discord usernames, which have since been published online.
Why it matters
The breach highlights the risks posed by vulnerabilities in third-party analytics software used by online services. Beyond account identifiers, the exposure of customer payment records complicates the security landscape for those affected.
The incident was facilitated through a security vulnerability found in the Metabase analytics tool. Accessed records included customer names, countries, and postcodes linked to Stripe payment data.
The players
Double Counter
Double Counter is an online platform that recently experienced a significant data security incident involving its customer database.
Metabase
Metabase is an open-source analytics tool used by organizations to visualize and share data from their databases.
Stripe
Stripe is a global technology company that provides economic infrastructure for the internet by facilitating payment processing.
The details
Attackers exploited the Metabase flaw to gain unauthorized access to the internal records of Double Counter. The stolen information, including payment data and contact credentials, was subsequently released in a public data dump.
Timeline
The data breach occurred in October 2026.
The Tech Race
This incident follows a pattern set by previous exploits targeting the Metabase analytics tool. It highlights how third-party software integrations remain a primary vector for security failures across the broader digital landscape.
Users of the platform should remain vigilant against phishing attempts that may use their leaked email addresses. If you have an account, consider monitoring your financial statements for any unauthorized activity related to your linked payment information.
The takeaway
Maintaining unique, complex passwords across different online platforms can significantly mitigate the fallout from individual site breaches. Users should enable multi-factor authentication whenever possible to add a secondary layer of protection against unauthorized access.
Further reading
Learn more about securing sensitive digital infrastructure on our Cybersecurity hub.
Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.
Live Poll
Do you trust online services to keep your personal payment information secure?







