Maine AG Data Breach Notification Portal Abused to Publish Fraudulent Breach Disclosures Impersonating VRChat and Discord — Threadlinqs Intelligence
As of 2026-06-14, Maine AG Data Breach Notification Portal Abused to Publish Fraudulent Breach Disclosures Impersonating VRChat and Discord is a medium-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0792 · Severity: MEDIUM · Status: MONITORING · Category: THREAT_INTEL
An unknown actor abused the Office of the Maine Attorney General's public data breach notification portal — which auto-published submissions without verification — to file fraudulent breach notices
On June 11, 2026, BleepingComputer reported that the Office of the Maine Attorney General's public-facing data breach notification database had been abused to publish fabricated breach disclosures falsely attributed to VRChat and Discord. Maine, like many U.S. states, operates a statutory breach-notification system where entities self-report incidents; the portal's design automatically published submitted notices to the public database without any independent verification or human review. The Maine AG's office confirmed: "We don't have any independent knowledge of the breaches, the submitting entity fills out the information and it goes directly onto the site." This trust-by-default workflow is the root cause that the actor exploited.
The fake VRChat filing claimed a breach affecting more than 2.4 million users, alleging that attackers accessed VRChat's cloud environment between approximately May 10-12 and exposed usernames, emails, VRChat+ subscription status, login history, device/hardware IDs, and linked Steam/Meta user IDs. VRChat's Head of Community, Charles Tupper, confirmed the filing was fraudulent: "VRChat did not submit this Notice of Data Incident, and the employee/email cited does not exist." The notice had been submitted under the name of a fictitious employee.
A second fraudulent notice impersonated Discord, claiming "more than 10 million people" were affected via "Insider wrongdoing." This filing was submitted on June 8, 2026 by "Xavier Morrison," listed as a "Data Subject / Reporter" rather than an official Discord representative, using a personal Gmail account and a placeholder/inactive phone number. The submission carried multiple red flags: an alleged breach date of July 9, 2024 with discovery not until August 2, 2025 (over a year gap), an anachronistic consumer-notification date of January 1, 2000, vague affected-data elements ("Name or other personal identifier in combination with"), no identity-theft protection offered, no copy of any consumer notice, and an absence of the professional legal representation (e.g., BakerHostetler) that handled prior legitimate Discord filings. These fabricated claims are distinct from Discord's genuine 2025 incidents (a September/October 2025 Zendesk third-party vendor compromise and a separate incident affecting roughly 70,000 users via stolen ID photos).
The abuse forced both companies to publicly deny the false claims before any verification occurred. On June 12, 2026, the Maine Attorney General's Office disabled public access to the breach notification database, stating: "After conversations with VRChat, one of two affected companies, it has become clear that the reported data breaches were hoaxes submitted by an unknown entity unrelated to either company." The office said it would review its reporting procedures to reduce similar abuse; entities can still submit notifications, but public access now requires contacting the AG's office directly. The office stated it was previously "not aware of another example" of intentional misrepresentation through the system. This event is best understood as an abuse-of-functionality / disinformation operation against a trusted public-sector data channel rather than a software vulnerability — there is no CVE, no malware, and no technical compromise of VRChat, Discord, or the State of Maine.
Weaknesses (CWE)
CWE-345, CWE-862, CWE-602
Target sectors: government, technology, gaming, social media
Target regions: North America, United States
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, T1591, T1589, T1589, T1589, T1591, T1593, T1585, T1583, T1190, T1036