
In a peculiar disinformation effort, fraudulent data breach notifications were submitted to Maine’s official breach portal and made publicly available before their authenticity could be confirmed, leading companies to refute the claims.
A notice purportedly filed by VRChat, a multiplayer social virtual reality platform, is the latest addition to the state Attorney General’s database of breach disclosures.
However, a company spokesperson informed BleepingComputer that the breach notification is fabricated and was submitted using the name of a nonexistent employee. VRChat is a multiplayer social virtual reality platform built on Unity, initially released for Windows and Oculus Rift in 2014, where users interact as customizable avatars in user-created virtual environments.
The fraudulent VRChat data breach entry states that personal data of over 2.4 million users was exposed to hackers after they accessed the company’s cloud environment.
The individual who submitted the false information took the effort to compose a notification letter for affected individuals, which claimed the hacking incident occurred between May 10 and 12 and affected the following data types:
VRChat username
Email address linked to a VRChat account
VRChat+ subscription status
Login history, including device, hardware identifiers, and IP addresses
Steam or Meta user ID tied to a VRChat account
At first glance, the fake letter appears credible, filled with details about unauthorized access, findings from a forensic investigation, actions taken following detection of the hack, claims that security measures have been enhanced, and recommendations for users to bolster account protection.
Charles Tupper, Head of Community at VRChat, told BleepingComputer that the data breach notification in the Maine Office of the Attorney General’s database is fraudulent:
"VRChat did not submit this Notice of Data Incident, and the employee/email cited does not exist. We have no reason to believe that our data or systems have been compromised."
Tupper added that the company is "in the process of contacting the Maine Attorney General's office to have this removed."
Graham Gaylor, CEO and co-founder of VRChat, also verified the statement that BleepingComputer received from Tupper.
The Maine Office of the Attorney General also responded to our request for comment, stating that "the notice will be coming down" and that they were "not aware of another example of intentional misrepresentation of the notice filings."
Earlier this week, the Maine Attorney General’s Office listed another suspicious data breach notification allegedly from Discord, which claimed that 10 million people were impacted by a data breach.
Maine’s Attorney General Office confirmed to BleepingComputer that anyone can submit a breach notification form and have it added to the portal without verification.
"We don’t have any independent knowledge of the breaches, the submitting entity fills out the information and it goes directly onto the site. We will review the one you’ve flagged, thank you," Maine Attorney General’s Office told BleepingComputer when asked about the validity of the Discord data breach submission.
Unlike most formal data breach notifications, the Discord entry did not include a notification letter from the company informing consumers about the breach, detailing what occurred and how those affected can protect themselves.
Beyond the company address, the Discord entry contained vague and unreliable information, starting with the name of the person submitting the notice, a Gmail contact, and a placeholder phone number.
Moreover, the details about the breach occurring on July 9, 2024, and being discovered on August 8, 2025, along with an inconsistent consumer notification date of January 1, 2000, are clear signs of a false submission.
Although a data breach did impact Discord in 2025, it occurred on September 20 and resulted from a compromise of the company’s Zendesk support desk system.
At that time, the hackers told BleepingComputer that they had stolen data from 5.5 million users out of 8.4 million tickets.
Despite being listed on an official portal, the validity of data disclosures should not be taken for granted, as inadequate vetting makes it easy for scammers to spread misinformation, potentially causing reputational harm and panic before companies even realize that a false filing has been posted.
These fake filings highlight the need for journalists and consumers to independently verify breach notifications with affected companies before treating entries on public notification portals as legitimate incidents.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
Maine disables data breach notification portal after fake disclosures
NVIDIA confirms GeForce NOW data breach affecting Armenian users
Ex-school district employee jailed for hacks on former employer
Japanese energy firm loses drive with data of 10.9 million clients
Pharma giant Novo Nordisk discloses breach of clinical trials data