Maine AG’s Data Breach Portal Offline After Fake VRChat, Discord Filings
Key Takeaways The Maine Attorney General’s data breach reporting portal has been temporarily taken offline. The action follows the discovery of fraudulent breach notifications falsely...
Key Takeaways
- The Maine Attorney General’s data breach reporting portal has been temporarily taken offline.
- The action follows the discovery of fraudulent breach notifications falsely implicating VRChat and Discord.
- Unidentified actors exploited the system’s lack of immediate verification, submitting false claims of large-scale data exposure.
- The Maine AG’s office is reviewing its procedures to prevent future abuse while maintaining public access to legitimate data.
The Maine Attorney General’s office has suspended public access to its online data breach reporting database after identifying the submission of fabricated breach notifications. These fraudulent filings falsely alleged significant data compromises at prominent online platforms, VRChat and Discord, prompting an immediate operational review of the state’s disclosure system.
Table Of Content
On June 12, 2026, the Maine AG’s office issued an official statement confirming the VRChat and Discord breach reports were hoaxes. Investigations revealed that an unknown third party, not affiliated with either company, submitted these false reports. Following direct communication with VRChat, officials verified the complete fabrication of the claims. Both erroneous entries have since been purged from the public database.
Breach Reporting Portal Suspended
Earlier reports indicated that one of the false filings asserted a Discord “insider wrongdoing” incident exposed personal data for over 10 million users. A separate submission falsely claimed VRChat leaked data belonging to approximately 2.4 million users, attributed to a non-existent employee. Neither Discord nor VRChat submitted these reports.
Maine operates one of the nation’s most stringent breach notification statutes, mandating that companies report a breach even if only a single Maine resident is affected. This low reporting threshold has historically made Maine’s public portal a critical resource for cybersecurity researchers, journalists, and legal professionals pursuing early breach disclosures.
The AG’s office has acknowledged that submissions made via its online reporting form were automatically published to the public portal without prior independent verification. This design, while intended to foster transparency and rapid public disclosure, inadvertently created a vulnerability that the unknown actor exploited to disseminate false information on an official government website.
In response, the Maine AG’s office has taken its public-facing breach database offline. The office is currently undertaking a comprehensive review of its internal procedures to prevent similar abuses in the future, while simultaneously working to preserve transparent public access to legitimate breach data.
During this interim period, organizations obligated to file breach reports can continue to do so via the office’s existing online reporting service. Individuals requiring information from previously filed reports can contact the AG’s Consumer Protection Division directly.
This incident underscores a critical systemic vulnerability inherent in government compliance portals that rely on self-reported, auto-published data. Cybersecurity professionals and journalists are advised to treat all entries on such portals as unverified until independent confirmation is obtained directly from the affected entity.
Authentic large-scale data breaches typically generate corroborating coverage across multiple reputable media outlets, official company advisories, or legal filings. Conversely, fabricated entries rarely exhibit such widespread, simultaneous validation.
As of this publication, the identity of the individual or group responsible for these fraudulent submissions remains unknown, and no arrests have been reported.
What You Should Do
- Verify Information: Always cross-reference breach notifications from public portals with official statements directly from the affected companies.
- Look for Corroboration: Seek out multiple independent news reports, official company press releases, and legal filings before accepting a breach report as legitimate.
- Exercise Caution: Treat unverified breach reports with skepticism, especially if they lack specific details or come from unknown sources on public databases.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.