Maine’s Office of the Attorney General has temporarily shut down its public-facing data breach notification portal after an unknown actor successfully submitted fraudulent breach disclosures impersonating two major online platforms, VRChat and Discord, exposing a critical gap in how state breach registries verify their filers.
The fraudulent VRChat filing, posted to the Maine portal on June 11, 2026, claimed the social VR platform suffered an external hacking incident between May 10 and May 12, 2026, exposing the data of over 2.4 million users, including 8,607 Maine residents.
The notice was drafted on fake VRChat letterhead and listed a fictitious employee as the contact person. A separate filing impersonated Discord, falsely claiming an “insider wrongdoing” incident that exposed personal data from millions of users.
Maine Takes Data Breach Reporting Portal
VRChat moved quickly to dispute the filing. The company posted on Reddit and later published an official blog statement confirming that it “did not submit this Notice of Data Incident” and that it had “no reason to believe that our systems have been compromised”. Discord did not publicly respond to media inquiries at the time of publication.
After the researcher initially flagged the filing and confirmed VRChat’s denial, Maine’s AG office acknowledged in a June 12 statement that the reports were “hoaxes submitted by an unknown entity unrelated to either company”.
Both fraudulent notices were removed from the database, and the public-facing portal was taken offline pending a review of reporting procedures.
A key detail that made the abuse possible: prior to the shutdown, submitted breach notices were automatically published to the public database with no independent verification.
The AG’s office confirmed: “We don’t have any independent knowledge of the breaches, the submitting entity fills out the information, and it goes directly onto the site.”
Maine’s breach portal is one of the most frequently cited state-level registries by cybersecurity journalists, researchers, and threat intelligence firms for tracking newly disclosed security incidents.
The ability to push fabricated breach notices targeting any company, with any fabricated scale, directly onto such a trusted public resource carries serious implications: reputational damage to innocent companies, manipulation of investor sentiment, and erosion of public trust in legitimate disclosures.
The AG’s office confirmed that legitimate breach submissions can still be filed through its online reporting service, and those requiring access to existing reports may contact the Consumer Protection Division directly.
It remains unknown whether law enforcement has been engaged to identify the perpetrator, or how many other fraudulent filings may have gone undetected before the portal went dark.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.