Update — June 12, 2026: VRChat staff and CEO Graham Gaylor told BleepingComputer they did not submit the Maine AG notice cited below and have no reason to believe their systems were compromised. BreachHistory removed the catalog entry. For the full Maine portal hoax story, see Maine breach portal fake VRChat filing explained.
VRChat data breach 2026: Social virtual-reality platform VRChat disclosed that unauthorized actors accessed account data in its cloud environment, affecting 2,436,782 users worldwide according to a Maine Attorney General breach filing. The incident window ran May 10 through May 12, 2026; VRChat discovered the intrusion on May 12 and began mailing consumer notices on June 12, 2026. If you use VRChat on PC (Steam), Meta Quest, or Android, this guide explains what was exposed, what the company says was safe, and practical steps to reduce phishing and account-takeover risk after the leak.
What is VRChat—and why this breach matters
VRChat is one of the largest social platforms built for virtual reality headsets and flat-screen play. Users appear as custom 3D avatars in user-created worlds, voice-chat with friends, and purchase optional VRChat+ subscriptions for cosmetic perks. Because many players link VRChat to Steam, Meta Quest, or Google accounts, a profile-and-login metadata leak can ripple across gaming and social identities even when passwords never left VRChat's vault.
The Maine filing classifies the event as an external system breach (hacking)—not a misaddressed email or lost laptop. That distinction matters for searchers asking whether the VRChat hack involved ransomware, payment processors, or age-verification vendors: the regulator notice points to direct unauthorized access inside VRChat's cloud stack holding routine account tables.
VRChat breach timeline (May–June 2026)
- May 10–12, 2026 — Unauthorized access to some account data in VRChat's cloud environment (per company notice summarized by Malwarebytes).
- May 12, 2026 — VRChat discovered the incident (Maine AG Date Breach Discovered field).
- June 12, 2026 — Consumer notification letters began (Maine AG Date(s) of consumer notification).
- 2,436,782 individuals — Total persons affected per Maine filing; 8,607 Maine residents were among the notified population.
What data was exposed in the VRChat data breach?
VRChat states that the information involved varied by account, but the categories below may have been accessed for affected users. These fields are enough to fuel targeted scams even without passwords or card numbers.
- VRChat username — Public-facing handle used in worlds and friend lists.
- Email address tied to the VRChat account — Primary recovery and notification channel.
- VRChat+ subscription status — Whether the user pays for the premium tier (useful for convincing billing fraud).
- Login history — Device information, hardware identifiers, and IP addresses associated with sign-ins.
Security researchers and consumer outlets note that combining emails, usernames, and IP/device telemetry helps attackers craft believable VRChat support phishing, correlate accounts across Steam or Meta, and prioritize high-value VRChat+ subscribers for refund or payment scams.
What VRChat says was NOT compromised
In its regulatory notice, VRChat explicitly states the following were not part of the exposed dataset:
- Passwords — Hashed or stored credentials were not taken, reducing immediate password-spray success against VRChat itself (but not credential stuffing if you reuse passwords elsewhere).
- Credit card numbers and other payment information — Billing for VRChat+ is handled outside the breached tables described in the filing.
- Government ID documents submitted for age verification — Sensitive KYC images or document numbers were not in the accessed cloud data per VRChat's statement.
Readers searching “Was my VRChat password leaked?” or “VRChat age verification breach” should still treat the incident as serious—metadata leaks are not harmless—but the company's attestation narrows the direct fraud surface compared with a full credential dump.
Who is affected—and how many records?
The authoritative count for the VRChat 2026 breach is 2,436,782 affected individuals, filed with the Maine Attorney General. That figure exceeds the rounded 2.4 million users cited in headlines and is the number BreachHistory indexes on the canonical incident page. Notifications are rolling out by email and postal mail depending on jurisdiction; U.S. residents in states with breach-notification laws may receive formal letters referencing the May activity window.
Risks after the VRChat leak: phishing, stuffing, and cross-platform linking
Phishing and fake support messages
Attackers often use breached usernames and emails in messages claiming to be “VRChat Trust & Safety”, Steam support, or Meta Quest security. Lures may cite your real VRChat name, allege a VRChat+ billing problem, or demand you “re-verify age” via a malicious link. Because government IDs were not exposed per VRChat, any message asking you to upload ID to “fix the breach” is almost certainly fraudulent.
Credential stuffing on other sites
Even without VRChat passwords, criminals combine leaked emails with passwords from older breaches and test them against Steam, Discord, Meta, and email providers. Reused passwords remain the fastest path from a metadata leak to account takeover elsewhere.
Identity correlation across gaming platforms
Steam IDs, Meta user IDs, and consistent avatar names help link personas across communities. Streamers, creators, and minors' guardians should be especially cautious about unsolicited friend requests or world invites referencing real login locations derived from IP metadata.
What VRChat did after the incident
According to summaries of the company's consumer notice, VRChat implemented additional security controls in its cloud environment and engaged external professionals to monitor for follow-on abuse. The platform continues to recommend two-factor authentication (2FA) for all accounts. These steps address future intrusion risk but do not “un-copy” data already accessed between May 10 and 12; affected users should assume their profile and login metadata may circulate on criminal forums even if VRChat never saw public paste sites.
Action checklist for VRChat users
- Turn on 2FA — Follow VRChat's official guide: Setup 2FA.
- Rotate reused passwords — Change any account (Steam, Meta, Gmail, Discord) that shared the same password as VRChat, even though VRChat says passwords were not stolen in this event.
- Watch for VRChat+ billing scams — Ignore emails or DMs about refunds, chargebacks, or “subscription cancellation” that link to non-vrchat.com domains.
- Verify support channels — Official help lives at vrchat.com and documented support flows; do not trust phone numbers or Telegram “admins” appearing after breach news.
- Monitor linked accounts — Enable login alerts on Steam and Meta; review active sessions after major breach headlines.
- Talk to household members — VRChat's audience includes teens; guardians should explain that usernames and emails may appear in scam messages and that reporting suspicious worlds remains important.
Frequently searched questions
Was VRChat hacked in 2026?
Yes. VRChat filed a regulator notice confirming unauthorized access to cloud-hosted account data between May 10 and 12, 2026, affecting more than 2.4 million users.
Were VRChat passwords leaked?
VRChat's notice states passwords were not compromised in this incident. Users should still update reused passwords on other services.
Was payment or age-verification data stolen?
VRChat says credit card data and government ID documents used for age verification were not exposed. Payment fraud tied solely to this breach is unlikely; phishing is the nearer-term threat.
How do I know if I was in the VRChat data breach?
Watch for official notification mail or email from VRChat referencing the May 2026 incident. You can also track the canonical BreachHistory record below as HIBP and other indexes update.
Catalog status
BreachHistory removed the vrchat-cloud2026 catalog row after VRChat denied the Maine filing. For the hoax investigation, see Maine breach portal fake VRChat filing explained.
Primary sources: Maine Attorney General breach notice, Malwarebytes — Data of 2.4 million VRChat users stolen