Maine breach portal abused to publish fake data breach disclosures
A fraudulent data breach disclosure was falsely submitted to Maine’s official breach portal, attributed to VRChat, and subsequently published before verification. The fake notification detailed a supposed hack impacting 2.4 million users, including usernames, email addresses, and login data. This incident highlights the vulnerability of public breach portals to misinformation campaigns and the need for independent verification of such claims.
The Maine Attorney General's Office operates a breach disclosure portal where companies can report data breaches. However, this system has been exploited by malicious actors to spread false information. In this case, a fraudulent notification claiming a VRChat data breach was submitted, detailing unauthorized access to the company's cloud environment and exposing data of over 2.4 million users. The notification included details about compromised data like usernames, email addresses, and login history, mimicking a legitimate breach report. This incident underscores the potential for reputational damage and consumer panic when inaccurate information is disseminated through official channels.