Maine has taken its public breach notification database offline after Maine breach portal fake disclosures impersonating BleepingComputer-flagged companies VRChat and Discord were automatically published to the state’s website. The Maine Attorney General’s Office confirmed the filings were hoaxes submitted by an unknown entity with no connection to either company, and the database will remain inaccessible to the public while officials review how to prevent the same abuse in future.
What the fake filings actually claimed
The fraudulent VRChat notification alleged that the company had suffered a breach affecting over 2.4 million people. According to Bitdefender, the filing listed compromised data as including usernames, email addresses, VRChat+ subscription status, login history, device identifiers, IP addresses, and linked Steam or Meta account IDs, a convincingly detailed list designed to look plausible. The notification was submitted under the fabricated employee name “Scott Caruso” using the address scaruso@vrchat.com.
The Discord filing went further. According to gblock.app, it claimed that “insider wrongdoing” at Discord had exposed more than 10 million people, a figure calibrated to cause alarm. Discord did disclose a breach previously, but that incident was a very different matter: SecurityWeek reports that Discord confirmed roughly 70,000 people had copies of government-issued IDs compromised, with no evidence that figure reached anything close to 10 million. Whoever crafted the fake filing appeared to be leveraging the fact that a real prior incident existed, inflating it by orders of magnitude.
VRChat confirmed to BleepingComputer that the disclosure was entirely fabricated and that it had not submitted any notice to Maine authorities. Discord did not respond to BleepingComputer’s enquiries about the fraudulent filing submitted in its name.
How Maine’s breach portal became a vector for misinformation
The root problem was architectural. Prior to the shutdown, submitted breach notices were automatically published to Maine’s public database with no independent verification by the Attorney General’s Office. The office acknowledged as much in its statement: ‘We don’t have any independent knowledge of the breaches, the submitting entity fills out the information and it goes directly onto the site.’
Maine’s breach notification portal is widely used by journalists, researchers, and threat intelligence firms as an early-warning feed for newly disclosed security incidents. That utility is precisely what makes it an attractive target for abuse: a fake filing, once published, carries the implicit weight of a state government database and can be picked up before anyone thinks to question its authenticity. The VRChat and Discord filings demonstrate how little friction existed between submitting a notice and having it presented to the public as fact.
The Attorney General’s Office says companies can still submit breach notifications through the reporting service during the suspension. Members of the public wanting copies of disclosures must now contact the office directly rather than accessing the database themselves. The office has not stated a timeline for restoring public access, only that it will review procedures to reduce similar abuse before doing so.
It is unclear how many additional fraudulent notices may have been submitted through the portal before the state suspended public access. The two Maine breach portal fake disclosures that prompted the shutdown came to light only because BleepingComputer spotted and flagged them, raising the obvious question of what else may have passed through unnoticed.
The reputational stakes
The incident is a reminder of how easily automatically published regulatory filings can be weaponised. A falsely published breach notice claiming millions of affected users does not need to survive long to cause damage: screenshots circulate, aggregators index it, and corrections rarely travel as far as the original claim. The fake VRChat filing listed enough plausible technical detail (device identifiers, IP addresses, linked third-party account IDs) to pass a quick read from someone who was not already sceptical.
For the companies named, the damage is reputational. For the portal’s usual audience of researchers and journalists, the immediate practical consequence is losing a real-time feed they relied upon. Maine’s review of its reporting procedures will determine whether automatic publication returns in any form, or whether the state moves to a moderated or verified submission model before disclosures go live.

