A state capitol building dome lit up at dusk, the kind of government building that hosts the state attorney general offices running public breach notification portals
Photo: Markus Spiske / Unsplash License

TL;DR: On June 11, 2026, a fraudulent data breach disclosure in VRChat's name was filed through the Maine Attorney General's online breach notification portal and posted as a public record on the state AG website. The filing claimed 2.4 million VRChat users had their usernames, emails, subscription status, login history, and linked Steam or Meta user IDs exposed between May 10 and May 12, 2026. Charles Tupper, Head of Community at VRChat, told BleepingComputer the filing is fake, the employee cited in the submission does not exist, and the company has no evidence of any compromise. The Maine Attorney General's office told BleepingComputer the notice would be taken down and that "anyone can submit a breach notification form and have it added to the portal without verification." The same office confirmed it was "not aware of another example of intentional misrepresentation" of notice filings, which means at least one prior example, filed earlier in the week in Discord's name claiming 10 million users impacted, is the second. Maine is one of forty-plus states that publish breach notices through similar portals. Every one of those portals is now part of the attack surface for stock manipulation, reputation damage, and short-and-distort schemes. The fix is small and obvious. The political will to apply it is not.[1][2][3]

What Happened on June 11

The fake notice was filed through the Maine AG's online breach notification form, the public portal any filer can use to disclose a breach to the state. The form requires an organization name, a contact name, a contact email and phone, a date of the breach, a date of discovery, a count of affected residents, and a description of what was exposed. There is no pre-publication check by Maine before the notice appears in the public database. The submitter fills in the form. The notice goes live.[2]

The VRChat filing, which appeared in the Maine AG's public breach notice database on the evening of June 11, was unusually polished. It included a full draft notification letter addressed to affected users, complete with the standard sections any real consumer breach notice would have: a description of the unauthorized access, a reference to a forensic investigation, a list of security improvements, and advice on what users should do to protect themselves. The data fields matched the categories a real disclosure would have included: VRChat username, email address, VRChat+ subscription status, login history with device, hardware identifiers, and IP addresses, and any linked Steam or Meta user IDs.[1]

VRChat says none of it is real. Charles Tupper, Head of Community at VRChat, told BleepingComputer in a direct statement on June 11: "VRChat did not submit this Notice of Data Incident, and the employee/email cited does not exist. We have no reason to believe that our data or systems have been compromised." Graham Gaylor, the CEO and co-founder of VRChat, also confirmed the denial. Tupper added that the company is "in the process of contacting the Maine Attorney General's office to have this removed."[1]

The Maine AG's office responded to BleepingComputer's request for comment with two statements that are load-bearing for this whole story. First, on the specific VRChat notice: "the notice will be coming down." Second, on whether the office had ever seen this kind of abuse before: "not aware of another example of intentional misrepresentation of the notice filings." And on the underlying process question, asked by BleepingComputer about a separate suspicious Discord filing earlier in the week: "We don't have any independent knowledge of the breaches, the submitting entity fills out the information and it goes directly onto the site. We will review the one you've flagged, thank you."[1]

That last quote is the whole story. The Maine AG's office runs a public breach notification database that publishes whatever an anonymous filer puts in a web form. The state itself does not verify the notice. The state does not notify the company. The state does not give the company a chance to confirm or deny the breach before the public record goes live. Once the form is submitted, the notice is a public record, and reporters, regulators, short-sellers, and competitors can pull it, screenshot it, and write the headline on top of it.

The Portal Is the Attack Surface

The state AG breach notification portal in Maine, like similar portals in at least forty other states, is built to make compliance easy. The intent is good. Real companies that suffer a real breach are required to file a notice in every state where affected residents live, and the portal makes that filing process one web form instead of forty separate legal letters. The state gets the disclosure, residents get the notice, and the public gets a searchable database of breach history. That architecture works fine when the filer is a real company that has actually suffered a real breach.[1][3]

The architecture breaks the moment someone with bad intent learns that the form is unverified. The Maine AG's office confirmed the gap explicitly. A bad filer can put any company name in the form, fabricate an employee contact, claim any number of affected users, list any data categories, and the notice goes onto a state government website. From the perspective of a reporter or a regulator scanning the database, the notice looks identical to a real filing. From the perspective of a company that just had a fake notice posted in its name, the only recourse is to issue a public denial, contact the AG's office, and hope the fake notice gets taken down before the press cycle hardens around it.[1]

The other forty-plus state portals are running on the same basic model. The mechanics vary: some states require a notarized affidavit, some states require a counsel signature, some states publish notices only after a state-level review. But the majority of state AG breach portals accept an unverified web form submission, and the submission is published as a public record with the full weight of a state government URL behind it. A short-seller who wants to move a stock on a fabricated breach notice has a target list of forty-plus government websites to choose from.[1][3]

Security Magazine's coverage on June 11 ran with the headline "2.4M Impacted by VRChat Breach." The article cited "a notice filed by the organization" and quoted the fake disclosure's data categories and the fake incident timeline as if the filing were legitimate. Security Magazine, a publication that covers cybersecurity professionally, did not independently verify the filing with VRChat before publishing.[4] That is exactly the problem. The structural incentive in the press is to write the headline on the state AG's notice, not to wait for the company's confirmation. By the time VRChat's denial landed, the headline was already out, the screenshots were already in Slack channels, and the data was already in the public record of an official state government website.

The Discord Precedent: The Second One This Week

The VRChat filing was not the first fake breach disclosure posted on a state AG portal this week. Earlier in the week of June 8 through June 12, a separate suspicious notice was filed through the same Maine AG portal alleging that Discord had suffered a breach affecting 10 million people. The Discord filing was sloppier than the VRChat one. It cited a Gmail address as the contact, a placeholder phone number, and a timeline that placed the breach on July 9, 2024 with a discovery date of August 8, 2025 and a consumer notification date of January 1, 2000, an internal inconsistency that would have been a flag for any reviewer.[1]

The Discord filing also did not include the kind of consumer notification letter the VRChat filing had. The state AG form does not require a notification letter, only the form fields. That detail matters. The Discord entry was a thin submission that any state portal reviewer could have caught on the face of it. The VRChat entry was a polished submission that read like a real corporate breach notice. The polish is what makes the attack surface work. A sloppy fake notice gets questioned. A polished fake notice gets reported.[1]

The Discord filing was also factually wrong in a way that the VRChat one is not, which made the response easier in Discord's case. A real Discord breach did happen, on September 20, 2025, when a third-party Zendesk support desk compromise exposed data on 5.5 million users from 8.4 million tickets. The fake filing in Maine claimed July 9, 2024 and 10 million users, both of which are easy to disprove on a timeline check. The VRChat filing, by contrast, references a real product (VRChat), a plausible incident window (May 10 to May 12, 2026), and data categories VRChat actually collects. There is no internal inconsistency to catch. The only way to know it is fake is to ask VRChat.[1]

The pattern is clear. The state AG portal is being used as a low-cost, high-credibility vector for publishing fabricated breach notices. The notices get cited in press coverage. The fake filing carries the weight of a state government URL. The victim company has to publicly deny the breach, which itself is news, and the cycle of "fake breach" plus "company denial" still leaves the public confused about whether the breach actually happened. The fact pattern fits a textbook short-and-distort scheme: fabricate negative news, drive the stock down, cover the short, and let the headlines sort themselves out over the next news cycle.

What the Fix Would Look Like

The technical fix is small, well-understood, and already used in other notice regimes. Three changes to the state AG portal process would close most of the gap.

1. Twenty-four hour pre-publication hold with direct company notification. When a breach notice form is submitted, the state AG's office should be required to notify the named company by direct contact (verified legal contact, not the email address the form itself supplies) and hold the notice from publication for at least 24 hours. The company gets a window to confirm or deny the breach. The state gets a chance to flag obviously fake filings before they become a public record. The 24-hour hold does not prevent publication of a real breach: real companies usually file the state notice after they have already started notifying affected residents, so a 24-hour hold on top of the company's own notice cycle is a rounding error. The hold only matters for fabricated filings, and the entire point of the hold is to give the victim company a chance to flag the fake.[1]

2. Verified legal contact on file for every filer. State AG breach portals should require a verified legal entity identifier (a state-issued business registration number, a federal EIN, a registered agent in the state) before accepting a notice filing. A filer who wants to file "VRChat, Inc." in the form should have to demonstrate that they are authorized to file on behalf of VRChat, Inc. That single change would have killed the VRChat filing, because the named filer was using a fictitious employee contact on a non-VRChat email address.[1]

3. A published takedown SLA for verified fakes. Once a company has confirmed a filing is fabricated, the state AG's office should be required to take the notice down within a defined window (24 to 72 hours) and publish a "filing withdrawn, verified fabricated" annotation in the public record in place of the original notice. The current Maine AG process took the VRChat notice down on a press-driven timeline, not on a defined SLA. A defined SLA would give the press, the regulators, and the public a clear signal that the notice was fake, and would let downstream news coverage correct itself before the next news cycle.[1]

None of these changes are technically hard. The 24-hour hold is a software change. The verified contact is a registration requirement. The takedown SLA is a public policy commitment. Any single one of them would have caught the VRChat filing.

Why the State AGs Will Not Fix It Alone

The state AG offices are the right place to fix the portal, but they are not going to do it without federal coordination. Three structural reasons.

First, the political cost of a delay in publishing breach notices is concentrated on the residents who are not getting the notice fast enough. The political cost of a fake breach notice getting published is concentrated on the company that has to publicly deny it. State AGs hear the first complaint, not the second, and the first complaint is louder. A state AG who slows down the notice pipeline for a 24-hour hold will get yelled at by state legislators and consumer protection advocates. A state AG who lets a fake notice get published will get a quiet letter from the victim company's outside counsel. The political incentive points the wrong way.[1]

Second, the state AGs do not have the federal authority to coordinate a uniform pre-publication process across all forty-plus portals. Each state sets its own breach notification statute. The state AGs cannot bind each other. A filing made in Maine and then taken down in Maine can be re-filed in California, New York, Texas, or any other state with its own breach portal. The fix has to be a multi-state compact, a federal breach notification floor, or a single federal breach notification portal that supersedes the state ones. None of those exist today.[1]

Third, the federal breach disclosure infrastructure has the same gap at the top of the stack. The SEC's EDGAR system publishes corporate filings with similar minimum-verification rules. The FTC's breach reporting requirements apply to specific regulated industries, not to every company that touches consumer data. There is no federal agency that runs a public breach notification database with a pre-publication check. CISA's role is cybersecurity defense, not consumer breach notice publication. The federal breach disclosure floor is a 50-state patchwork, and the patchwork has the same vulnerability in every state.[1]

The fix is a federal breach notification pre-publication review standard, applied to every state AG portal that publishes breach notices as public records, and applied at the federal level for filings that cross state lines. That is a policy fight, not a technology fight. The technology is straightforward. The policy fight is the slow part.

What You Can Do Today

  • Verify breach headlines with the named company before reacting. If you see a "data breach" headline about a company you use, do not assume the breach happened. Go to the company's official website, find their security or trust center page, and look for an actual breach notice. If the company has not published one, the headline may be a fabricated filing that the company is still working to take down. The Maine AG portal has now published at least one fabricated notice that was widely reported. The reporting on a fake breach is just as loud as the reporting on a real one, and your "delete my account" panic is the deliverable the attacker wanted.[1]
  • Check the date of the breach discovery in the notice. A real breach notice has dates that line up with the company's actual response timeline. A fake breach notice often has dates that are inconsistent, in the future, or in the distant past. The Discord filing cited a consumer notification date of January 1, 2000, an obvious internal inconsistency. The VRChat filing was more polished, but the "May 10 to May 12" window and the "engaged in forensic investigation" language are stock phrases that any consumer breach notice writer would recognize. If the dates and the language are too clean, be skeptical.[1]
  • Push your state AG to commit to a 24-hour pre-publication hold. The technical fix is small. The political fix requires state AGs to commit to a slower notice pipeline in exchange for fewer fabricated notices. If you live in a state with a breach notification portal, ask the state AG's office whether they run any pre-publication verification, whether they notify the named company before publication, and what the takedown SLA is for a verified fabrication. The answer in most states today is: no verification, no notification, no defined SLA. The fix starts with the question.[1]
  • File an SEC tip if you see a fake breach notice move a stock. A fabricated breach notice posted on a state government website, used to move the stock of a public company, is a textbook market manipulation pattern. The SEC's tip line accepts reports on suspected market manipulation, and a coordinated fake breach notice filed on a state portal is the kind of pattern the SEC's Market Abuse Unit tracks. The more coordinated the filings (multiple companies, multiple states, the same filer pattern), the more clearly it fits an enforcement profile.[1]
  • Forward this story to your state AG's office. The state AGs are overworked, and the breach portal question is not on most consumer protection agendas. The fact that an unverified web form on a state government website was used to publish a fabricated breach notice, and that the fake notice was cited in a national security publication's headline, is the kind of example that moves the question up the queue. The more constituents raise it, the higher it goes.

The Bottom Line

Someone filed a fake VRChat breach notice on a state government website on June 11, 2026, and the state government website published it. VRChat is publicly denying it. Maine is taking it down. The fake notice was polished enough to get a national security publication to write a headline on top of it. The fake notice cited a non-existent employee. The fake notice claimed 2.4 million users were impacted. The fake notice would not have been caught by anyone except the victim company. The victim company was not contacted before publication. The state is the public records custodian for a notice it did not verify.[1][2][4]

That is the structural problem. It is not a Maine problem. It is a forty-state problem, and the federal breach disclosure infrastructure is not set up to fix it. The fix is a 24-hour pre-publication hold, a verified legal contact requirement, and a defined takedown SLA. The technology for all three is straightforward. The policy fight is the slow part, and the slow part is the part that is now costing real companies their public reputation, costing real reporters their time on fabricated stories, and costing real attackers a single free shot at any company on any state portal any week of the year.

VRChat got lucky: the CEO and the Head of Community were both available for comment the same evening, and the Maine AG's office was responsive to a press inquiry. The next company to get a fake notice may not get a same-day denial. The next state AG office may not take the notice down on a press-driven timeline. The next press outlet may not catch that the notice is fake before the headline hardens. The structural fix has to be in place before one of those breakages happens at scale.

Sources

  1. BleepingComputer: "Maine breach portal abused to publish fake data breach disclosures" (Bill Toulas, June 11, 2026, 18:44 ET)
  2. Maine Office of the Attorney General: "Data Breach Notices" public database (the public-facing portal where the fake VRChat notice was posted before being taken down)
  3. Cybersecurity Insiders: "VRChat says Data Breach notification filed with Maine Attorney General was Fake" (June 11, 2026, coverage of the fake filing and the company's denial)
  4. Security Magazine: "2.4M Impacted by VRChat Breach" (June 11, 2026, headline citing "a notice filed by the organization" without independent verification with VRChat)
  5. Maine Office of the Attorney General: "Data Security Breaches" public information page (the policy context for the breach notification portal and the public-records framing of the notice database)