Discord Security Bot Double Counter Exposes Data on 28 Million Accounts
The incident shows how a forgotten third-party server can let attackers access sensitive network and location records.
Overview
- Tellter said the attacker siphoned about 12GB of data in a 25-minute window on Monday, October 5, linked to roughly 28 million Discord accounts and including usernames, IP addresses and city-level locations.
- About one million full email addresses were copied and Tellter is treating all records as exposed because it cannot determine which specific entries were taken.
- The intruder entered through an old, unused server running a tool with a known vulnerability, obtained keys to live systems, captured the bot’s Discord login and grabbed the new password two minutes after staff changed it.
- Attackers found a payment key for Tellter’s Atis product and made $7,316 in unauthorized charges on a company card while two customer charges were later refunded.
- Tellter has cut access, notified France’s data regulator, is filing a criminal complaint and has warned users who gave email addresses to watch for phishing as investigators and platform responses continue.