HackMyIP
← Back to News
2026-06-12 BleepingComputer

Maine Pulls Breach Portal Offline After Fake VRChat and Discord Disclosures

Data BreachRegulationIncident Response

The Maine Attorney General's Office has temporarily disabled public access to its state-run data breach notification portal after fraudulent breach reports impersonating VRChat and Discord were published on the site. The fake filings, which were submitted through the portal's standard reporting form and posted automatically without independent verification, included a fabricated VRChat notice claiming an incident affecting more than 2.4 million people along with a fictitious employee contact name. VRChat confirmed to BleepingComputer that the disclosure was not legitimate and that it had not submitted any report to Maine authorities, while Discord did not respond to inquiries about the second fraudulent notice.

In a statement released Friday, the Maine AG's Office acknowledged the abuse and said it had removed the false reports from the database. "The reported data breaches were hoaxes submitted by an unknown entity unrelated to either company," the office said, adding that it had "no knowledge of any recent legitimate data breach reports from either VRChat or Discord." Companies can still submit breach notifications through the service, but the public database is now offline while officials review submission and verification procedures. Until the shutdown, notices were published directly to the public-facing site as soon as they were filed, with no prior vetting by the state.

The incident highlights a structural weakness in automatically published breach disclosure systems, which are widely used by journalists, researchers, and threat intelligence teams to track newly disclosed incidents. Without authentication or cross-checking against the named organizations, attackers, competitors, or bad actors can weaponize the channel to spread misinformation, manipulate stock prices, or damage brand reputation. Organizations monitoring for exposure of their own credentials or customer data should use a dedicated email breach checker to verify whether their domains truly appear in any disclosed incident rather than relying on portal posts alone. Investigators tracing the submitting entity can also use a WHOIS lookup to correlate infrastructure used in the fraudulent filings.

It remains unclear how many additional fraudulent notices were submitted before the portal was taken offline, and the Maine AG's Office has not said when public access will be restored. The episode is likely to fuel broader debate over the safeguards required for public breach reporting systems, particularly as more states automate compliance with consumer notification laws. For the time being, anyone needing copies of historical disclosures must request them directly from the Attorney General's Office.

Source: BleepingComputer →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →