Maine breach portal abused to publish fake data breach disclosures
Fake breach notices were posted to Maine’s AG portal before companies could verify them, including a bogus VRChat filing.
Intelligence analysis by GPT-5.4 Mini

Fraudulent data breach disclosures were submitted to Maine’s official portal and published without verification, allowing false claims about VRChat and Discord to spread. The episode exposed a weak point in public breach-reporting systems and forced both companies to deny the notices.
Someone slipped fake warning letters into Maine’s breach report site, like putting fake fire alarms on a public wall. The article says people should check with the company first, because the notice page itself does not prove a real hack happened.
Analysis
What happened
Maine’s official breach disclosure portal was used to publish false reports that looked like real incident notices. One of the latest examples claimed VRChat had suffered a breach affecting more than 2.4 million users, but the company said the notice was fake and that the named employee did not exist.
The bogus filing included a polished-looking notification letter and listed data types such as usernames, email addresses, subscription status, login history, and linked platform IDs. That made the filing appear credible at first glance, even though VRChat said it had no reason to believe its systems were compromised and was working to get the post removed.
Why the portal was vulnerable
The Maine Attorney General’s office told BleepingComputer that anyone can submit a breach form and have it posted without independent verification. The office said it does not have its own knowledge of the alleged incidents and relies on the submitting party’s information.
That creates a clear opening for misinformation. A separate suspicious notice allegedly from Discord was also published, claiming 10 million users were affected. It contained weak signs of authenticity, including a Gmail contact, placeholder details, and a notification date that did not make sense. Discord had a real breach in 2025, but it was a different incident tied to its Zendesk support system.
Broader impact
The article’s main warning is straightforward: a public breach portal is not proof that a breach happened. Journalists and consumers should verify filings directly with the affected company before treating them as confirmed incidents. Without that check, a fake notice can spread faster than the truth.
Key points
- Fake breach notices were posted to Maine’s official disclosure portal before they were verified.
- VRChat said a notice in its name was fraudulent and that the named employee does not exist.
- Maine’s AG office said submissions go live without independent validation.
- A separate suspicious filing alleged a large Discord breach but contained obvious inconsistencies.
- The article says breach notices should be confirmed with the company before being treated as real.
The article shows a path for the portal to be cleaned up quickly once false filings are identified. If the state tightens review or verification, future fake notices could be caught before they spread widely.
If the portal stays easy to abuse, fake breach claims can keep causing confusion and reputational harm. Real incidents may also become harder to spot quickly if readers start doubting every filing.



