Maine Shuts Down Data Breach Portal After Fake Filings

Fraudulent breach notifications impersonating Discord and VRChat were published on Maine's public portal, forcing its temporary shutdown.

By Central
Maine's data breach portal was taken offline after fake submissions targeting Discord and VRChat were published without verification.
Highlights
  • Maine's data breach portal lacked any verification mechanism, allowing anyone to submit and publish fake breach notices.
  • A fraudulent Discord breach notification claimed 10 million affected users but included obvious red flags like a Gmail contact address.
  • The second fake notice targeted VRChat with convincing detail, but VRChat confirmed it had no actual breach.

The state of Maine has taken its public data breach notification portal offline after fraudulent submissions impersonating two major technology companies were published without verification, raising serious questions about the integrity of such reporting systems. The abuse of the portal, which is designed to inform the public about security incidents, allowed fake breach notifications to appear as official records before any legitimacy checks could be performed.

Fake Discord Breach Notification Filed Through Maine Portal

The first fraudulent submission targeted Discord, the popular messaging platform used by hundreds of millions of users worldwide. The fake notification claimed that 10 million individuals had been affected by a data breach, but contained multiple red flags that should have prevented its publication. The filing included a Gmail contact address, a placeholder phone number, and listed a consumer notification date of January 1, 2000. It also lacked an example notification letter to affected customers, a standard component of legitimate breach filings.

Fabricated VRChat Breach Notice Contained Convincing Detail

A second fake notice, targeting the multiplayer social virtual reality platform VRChat, was somewhat more elaborate. The filing alleged that attackers had gained access to the company’s cloud environment in May and that data belonging to more than 2.4 million users had been exposed. The fabricated notice listed compromised data types including usernames, email addresses, VRChat+ subscription status, login history, device identifiers, IP addresses, and linked Steam or Meta account IDs.

The submission was made under the fake name “Scott Caruso” using the email address scaruso(at)vrchat.com. Charles Tupper, Head of Community at VRChat, confirmed that the notification was fraudulent, stating that the employee and email cited do not exist and that the company has no reason to believe its data or systems have been compromised.

How Did Fake Breach Notifications Get Published on Maine’s Portal?

The abuse was made possible because Maine’s data breach reporting system lacked a proper verification mechanism. Anyone could submit a breach notification form and have it added to the portal website without any authentication or validation of the submitter’s identity. This meant that any individual seeking to cause reputational harm to a company could submit a convincing-looking breach notice and see it published as an official record.

The office of the Maine Attorney General confirmed that it had no knowledge of any recent legitimate data breach reports from either VRChat or Discord, and has since temporarily disabled public access to the breach notification database while procedures are reviewed to reduce the likelihood of similar abuse in the future. The false reports have been removed.

Broader Implications for Breach Notification Integrity

It remains unclear who was behind the false submissions, whether the targets were chosen deliberately, or how many other fraudulent breach notices may have been submitted through the portal before public access was suspended. The incident underscores a critical vulnerability in the trust model underlying public breach notification systems, where the absence of basic identity verification can allow bad actors to weaponize a transparency mechanism intended to protect consumers.

Many journalists and security researchers rely on state breach notification portals to track and report on security incidents, making the integrity of these systems important for public awareness. The Maine incident demonstrates that without proper controls, these portals can become vectors for disinformation rather than reliable sources of incident data.

What Affected Users Should Do to Protect Themselves

While the fraudulent notifications in this case were not based on actual breaches, the incident serves as a reminder of the importance of verifying security alerts through official company channels. Users who receive a data breach notification from any source should take the following steps: visit the company’s official website or trusted support channels to confirm the incident, change passwords for any accounts where credentials may have been involved, enable two-factor authentication on all supported accounts, and monitor financial and online accounts for suspicious activity. Using a reputable VPN with a verified no-logs policy and AES-256 encryption can help protect your privacy online, particularly when accessing accounts on public Wi-Fi networks. For comprehensive security, consider a multi-layer endpoint protection solution that includes real-time threat detection and behavioral analysis to guard against credential theft and other common attack vectors.

Share This Article