In June 2026, Maine's official data-breach notification portal became the centerpiece of an unusual misinformation campaign that fooled journalists, security outlets, and breach trackers—including an early BreachHistory catalog entry—before the named companies could respond. The most elaborate fake notice targeted VRChat, claiming 2,436,782 users were affected by a cloud intrusion. VRChat staff and CEO Graham Gaylor told BleepingComputer the company never submitted the filing, the cited employee does not exist, and they have no reason to believe their systems were compromised. This article explains how Maine's portal was abused, how the VRChat hoax spread, and what readers should verify before treating any state filing as proof of a hack.
Related: our original VRChat 2.4M breach coverage (published when the Maine filing first circulated) now carries a June 12 update banner linking here.
What happened: Maine's breach portal posted fake notices
BleepingComputer reported in June 2026 that fraudulent disclosures were submitted to Maine's public database, published on the state site, and circulated in security news before anyone confirmed they came from the named companies.
The Maine Office of the Attorney General told reporters that anyone can submit a breach notification form and have it added to the public database without independent verification: "We don't have any independent knowledge of the breaches, the submitting entity fills out the information and it goes directly onto the site." Officials said they were not aware of another prior case of intentional misrepresentation and that false notices would be taken down after review.
The fake VRChat data breach (2.4 million users)
The VRChat hoax claimed 2,436,782 users were affected after hackers accessed the platform's cloud environment between May 10 and 12, 2026. The submission included a polished consumer notification letter listing usernames, emails, VRChat+ status, Steam/Meta IDs, and login metadata—details that made the filing look like a legitimate regulator post at first glance (DocumentCloud copy).
Charles Tupper, Head of Community at VRChat, told BleepingComputer:
"VRChat did not submit this Notice of Data Incident, and the employee/email cited does not exist. We have no reason to believe that our data or systems have been compromised."
VRChat said it was contacting the Maine Attorney General's office to have the entry removed. CEO and co-founder Graham Gaylor confirmed the same statement. Malwarebytes later updated its coverage to reflect VRChat's denial on Reddit and official channels.
The fraudulent Maine URL that triggered initial headlines:
Maine AG listing — VRChat (hoax)
How the hoax reached BreachHistory and social media
State AG portals are widely treated as authoritative by journalists, threat-intelligence feeds, and breach catalogs. When submissions publish instantly, a single hoax can generate false headlines—including premature "VRChat hacked" threads—and force companies to spend resources publicly denying incidents they never had.
BreachHistory initially indexed the filing under vrchat-cloud2026 and published long-form VRChat breach coverage at the same URL shared on social media. After VRChat's denial and BleepingComputer's investigation, we removed the catalog row and kept the original article online with an update banner pointing readers to this explainer.
A suspicious Discord filing (10 million users)
Earlier the same week, Maine's portal listed another questionable notice allegedly from Discord, claiming 10 million people were impacted. Red flags cited by BleepingComputer included:
- No formal consumer notification letter attached (unlike typical corporate filings)
- A Gmail contact address and placeholder phone number for the submitter
- Vague breach details inconsistent with Discord's real September 2025 Zendesk support-desk incident (a separate, documented event)
Maine AG staff told reporters they would review flagged submissions but do not pre-validate them. Discord's authentic 2025 breach involved support-ticket exposure—not the fictional 10M-row entry on the Maine site.
Why unverified Maine filings are risky for breach tracking
When portals lack submission vetting, a hoax can:
- Trigger phishing campaigns pretending to help "breach victims"
- Undermine trust in public breach databases used for compliance research
- Spread through SEO and social shares before company denial catches up
BleepingComputer's conclusion applies to every reader: verify breach notifications with the affected company before treating a regulator listing as proof of compromise—especially on portals without submission vetting.
How BreachHistory verifies incidents
Our verified-breaches-only policy requires company or agency confirmation, corroborated regulator filings, or substantive trade press citing named victim acknowledgment. A Maine agviewer row alone is insufficient when the vendor denies the filing.
After VRChat's denial we:
- Removed the
vrchat-cloud2026breach record from the catalog - Kept the original VRChat breach article at its published URL with an update banner
- Published this Maine portal explainer as a separate article
How to verify a data breach before you panic
- Check the company's official site — status page, press release, or security incident FAQ.
- Look for a consumer notification letter with verifiable legal/contact details—not only a state form filled by a Gmail address.
- Cross-check trade press — BleepingComputer, SecurityWeek, Reuters should cite a named company spokesperson, not only the AG URL.
- Watch for HIBP — independent indexes load datasets only after analysis; absence plus company denial is a strong negative signal.
- Beware post-hoax phishing — even fake breach news produces real scam emails citing the fabricated details.
VRChat users: was there a real 2026 breach?
No verified VRChat data breach occurred in June 2026. The 2.4M-user figure came from a fraudulent Maine filing, not from VRChat or a corroborated forensic investigation. Enabling 2FA remains good hygiene, but users should not treat the hoax letter's May 10–12 timeline as factual.
FAQ
Was the VRChat Maine AG notice real?
No. VRChat denied submitting it; Maine AG said the notice would be removed; BleepingComputer documented the filing as fraudulent.
Can anyone post to Maine's breach portal?
Yes—submissions go live without Maine independently verifying them, per the Attorney General's office statement to BleepingComputer.
Was Discord breached for 10 million users in June 2026?
Not per any company confirmation. The Maine Discord entry showed multiple authenticity red flags; Discord's verified 2025 incident was a separate Zendesk-related event.
Sources: BleepingComputer — Maine breach portal abused, Malwarebytes — VRChat denial update, DocumentCloud — fake VRChat letter