2026 VRChat — cloud breach exposed 2.4M users (May 10–12; profile and login metadata)
Data compromised
Usernames, emails, VRChat+ subscription status, login history with device info, hardware identifiers, and IP addresses; passwords, payment cards, and age-verification government IDs not compromised per notice
Technical writeup
VRChat, Inc. filed a Maine Attorney General breach notice reporting that 2,436,782 individuals were affected after unauthorized access to account data in the company's cloud environment between May 10 and May 12, 2026, discovered May 12, with consumer notifications beginning June 12, 2026. The filing classified the incident as an external system breach (hacking). VRChat's notice states exposed fields varied by account but could include VRChat usernames, associated email addresses, VRChat+ subscription status, and login history including device information, hardware identifiers, and IP addresses; the company said passwords, credit card or other payment information, and government ID documents used for age verification were not compromised. Malwarebytes summarized the disclosure and noted VRChat implemented additional security controls and engaged monitoring professionals.
Root cause
External system breach (hacking); unauthorized access to VRChat cloud environment