Fraudulent data-breach notices were submitted to Maine’s public breach portal and published as if they were real, falsely claiming incidents at VRChat and Discord. VRChat told BleepingComputer the filing was fake and used a nonexistent employee name, while Maine’s Attorney General office said notices can be posted without prior verification and that the VRChat entry would be removed. The incident appears to be abuse of a government disclosure system rather than a confirmed breach of the named companies.
Why it matters: This can mislead users, investors, journalists, and incident responders by making fake breaches look official. Organizations should monitor state breach portals for false filings in their name, and users should wait for confirmation from the affected company before reacting to reported breaches.
2026.06.15
94% relevant
This article updates the same underlying event by reporting Maine's response: the state has taken the public breach portal offline, confirmed the VRChat and Discord notices were hoaxes, and said it is auditing procedures before restoring public access.
Eduard Kovacs
2026.06.15
96% relevant
This article adds that the Maine Attorney General temporarily disabled the public breach portal because of the hoax VRChat and Discord submissions, and confirms the state is reviewing procedures before restoring the database.
Lawrence Abrams
2026.06.12
97% relevant
This updates the same underlying event by adding Maine's official response: the attorney general confirmed the VRChat and Discord notices were hoaxes, removed them, and temporarily disabled public access to the breach portal while reviewing its publication procedures.
Bill Toulas
2026.06.11
100% relevant
This article establishes a distinct story about abuse of Maine’s breach-reporting portal to publish unverified and false disclosures, with VRChat and Discord cited as early known examples.
← Back to all stories