INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
LimeLeads Breach Exposes 17 Million Accounts
| 2026-10-07 05:42 DATA BREACH
Executive Summary
AI-generated
In October 2026, the Discord server protection service Double Counter suffered a data breach attributed to a vulnerability in the Metabase analytics tool. The attackers gained access to a subset of its data and subsequently published a corpus containing approximately 274,922 unique email addresses and Discord usernames. This incident is similar to another data breach that occurred in 2019 when LimeLeads, a now-defunct B2B marketing leads database service, suffered an exposed, unsecured Elasticsearch server, exposing tens of millions of records including 17,838,396 breached accounts. The Metabase analytics tool and Double Counter's vulnerability are believed to be behind the breach, but no further information is available on who specifically carried out the attack or how it worked.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Intelligence Sources
Have I Been Pwned
2026-09-22
LimeLeads - 17,838,396 breached accounts
Have I Been Pwned
Have I Been Pwned
2026-10-07
Double Counter - 274,922 breached accounts
Have I Been Pwned