Double Counter Data Breach Exposed 274,922 Users

The incident involved a vulnerability in the Metabase analytics tool, exposing sensitive user and payment data.

Updated on Oct. 7, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a fractured stone pillar with glowing fissures, symbolizing a breach in secure data systems.
Double Counter disclosed a data breach exposing 274,922 users, following an exploit in the company's third-party Metabase analytics software integration. AI Illustration. Upload story photo >

Live Poll

Do you trust online services to keep your personal payment information secure?

Double Counter recently suffered a data breach in which attackers accessed and published 274,922 unique email addresses and Discord usernames. The leaked dataset also included Stripe payment records containing customer names, countries, and postcodes.

Why it matters

The breach highlights the risks of exploiting vulnerabilities in third-party analytics software, such as Metabase, to pivot into a company's internal data stores. The exposure of integrated payment records underscores the security challenges of managing customer financial metadata.

The incident resulted in the public release of 274,922 unique email addresses and Discord usernames. While the total number of exposed Stripe records was not quantified, the data points accessed included customer names, countries, and postcodes.

The players

Double Counter

A digital service platform that integrates third-party analytics and payment infrastructure to manage customer accounts.

Metabase

An open-source analytics and business intelligence tool used for querying and visualizing connected database information.

Stripe

A global financial infrastructure company that provides payment processing APIs and transaction management for online businesses.

The details

Attackers exploited a specific security vulnerability within the Metabase analytics tool to gain unauthorized access to internal systems. Metabase is an open-source business intelligence platform that allows users to query and visualize data from connected databases. By targeting this tool, the attackers bypassed standard security layers to retrieve sensitive customer data and payment records from the connected payment processor, Stripe.

Timeline

  1. The data breach occurred in October 2026.

The Tech Race

This incident follows a pattern set by the 2023 Metabase vulnerability exploits that targeted business intelligence pipelines. The breach confirms that infrastructure-as-a-service integrations remain a primary target for actors seeking access to financial metadata.

Users of the Double Counter platform should monitor their emails for phishing attempts and verify any communications related to their Stripe account details. Because customer names and postcodes were exposed, individuals should remain vigilant against identity-related fraud or targeted social engineering.

The takeaway

The event highlights the critical importance of patching third-party analytics tools as a core component of surface-area management. Affected customers should watch for official security notifications from the company regarding potential remediation steps or account monitoring services.

Further reading

For broader trends in enterprise security, visit the Cybersecurity section.

Live Poll

Do you trust online services to keep your personal payment information secure?