Maine Portal Hosts Fake Breach Notices
Coverage from Simply Secure Group, SecurityWeek, and others

An unknown third party used the Maine Attorney General's public breach-reporting portal to post a convincing but fraudulent notice claiming that more than 2.
4 million VRChat users were affected. VRChat said its systems and user data were not compromised, while Maine characterized the filing and a separate Discord submission as hoaxes and temporarily disabled the public portal. The episode shows how unverified regulatory submissions can spread false breach information, create reputational harm, and trigger unnecessary concern before affected organizations can respond.
The update adds concrete detail to the fraudulent VRChat notice, including the claimed scale and specific data categories, while confirming VRChat's denial and Maine's view that both the VRChat and Discord filings were hoaxes. It also clarifies that the portal was temporarily taken offline because submissions could be posted before validation.
The story is now more clearly framed as an operational abuse of Maine's breach-reporting process, with added emphasis that the state has removed false notices and is reviewing verification procedures. Coverage also more explicitly situates the incident around hoax filings rather than any confirmed VRChat or Discord breach.
