ProBackend
cybersecurity
Jun 14, 20263 min read

Maine Breach Portal Abused to Publish Fake Data Breach Disclosures

An unusual misinformation campaign saw fraudulent data breach disclosures submitted to Maine's official breach portal, including fake reports from VRChat and Discord, highlighting the lack of verification in public breach notification systems.

Summary

In an unusual misinformation campaign, fraudulent data breach disclosures were submitted to Maine's official breach portal and publicly posted before their legitimacy could be verified, prompting companies like VRChat and Discord to deny the claims.

The Maine Attorney General's Office confirmed that anyone can submit a breach notification form without verification, allowing bad actors to create fake breach reports that appear authoritative. For background on how organizations protect themselves against such vulnerabilities, see our guide on Web Application Firewalls.

The VRChat Fake Breach Report

The most prominent fake entry involved multiplayer social virtual reality platform VRChat. A notice allegedly filed by VRChat claimed that personal data of more than 2.4 million users was exposed to hackers after they gained access to the company's cloud environment.

The fake notification letter detailed what appeared to be a sophisticated breach occurring between May 10 and 12, claiming exposure of:

  • VRChat username
  • Email address associated with a VRChat account
  • VRChat+ subscription status
  • Login history, including device, hardware identifiers, and IP addresses
  • Steam or Meta user ID linked to a VRChat account

Charles Tupper, Head of Community at VRChat, confirmed the notification was fraudulent:

"VRChat did not submit this Notice of Data Incident, and the employee/email cited does not exist. We have no reason to believe that our data or systems have been compromised."

Tupper added that the company was contacting the Maine Attorney General's office to have the entry removed.

The Discord Fake Breach Report

Earlier that week, another suspicious data breach notification appeared allegedly from Discord, claiming that 10 million people were impacted by a data breach.

Maine's Attorney General Office confirmed to BleepingComputer that anyone can submit a breach notification form without verification:

"We don't have any independent knowledge of the breaches, the submitting entity fills out the information and it goes directly onto the site. We will review the one you've flagged, thank you,"

The Discord entry contained vague and unreliable information:

  • A Gmail contact as the submitter
  • A placeholder phone number
  • No notification letter from the company

System Vulnerabilities

The Maine Attorney General's breach portal lacks verification mechanisms, creating serious problems:

  1. Reputational Damage: Companies must publicly deny false breach reports
  2. Consumer Confusion: Users may receive fake breach notifications
  3. Resource Drain: Companies and government offices must investigate and remove false entries

For best practices on incident response and breach verification, see our comprehensive guide on Web Application Firewalls.

Implications for Data Breach Reporting

This incident raises questions about the reliability of public breach notification databases. Many states rely on self-reported breach notifications without verification.

Security experts recommend:

  • Implementing verification mechanisms before publishing breach reports
  • Creating standardized reporting channels with company authentication
  • Warning users about the possibility of fake breach notifications

For more information on how to protect your organization from data breaches, see our Data Breach Response Guide.

Conclusion

The Maine breach portal abuse highlights a critical gap in data breach notification systems. Without proper verification, public portals can be weaponized for misinformation, causing reputational harm and confusing consumers about their data security.

Summary

More blogs