VRChat says Data Breach notification filed with Maine Attorney General was Fake

Shark-AI-security-cyber

In the aftermath of a cybersecurity incident, organizations are generally required to notify affected stakeholders and, where applicable, file data breach disclosures with regulatory authorities. Such notifications help authorities assess the scope of an incident, understand potential risks to consumers, and monitor compliance with data protection regulations.

However, a recent incident involving VRChat has raised concerns about an unusual and potentially troubling trend—the filing of fraudulent data breach notifications with government agencies.

VRChat, a popular online social and virtual reality platform, has publicly stated that a breach notification recently submitted to the Maine Attorney General’s Office was fraudulent and did not originate from the company. The filing alleged that VRChat had suffered a cybersecurity incident resulting in the compromise of user data.

In response to media inquiries, Charles Tupper, Head of Community at VRChat, clarified that the company had not experienced the data breach described in the filing and that the notification itself was fake. According to Tupper, VRChat’s internal investigation found no evidence of the alleged incident outlined in the notice.

The company also attempted to verify the details included in the submission. However, the contact information attached to the breach notification reportedly led nowhere. The phone number listed could not be reached, while the associated email address failed to respond to inquiries. These findings strengthened VRChat’s conclusion that the filing had been fraudulently submitted by an unknown party.

The incident has highlighted a potentially serious cybersecurity and regulatory concern. If malicious actors begin filing fabricated breach notifications with state Attorney General offices or other regulatory agencies, organizations could face reputational damage, unnecessary scrutiny, and confusion among customers and business partners. Experts warn that such tactics could become more common if adequate verification mechanisms are not implemented.

Interestingly, independent reporting has suggested that VRChat may have experienced a separate security incident earlier this year. According to reports, the company’s cloud environment was allegedly compromised in mid-May, potentially exposing data associated with approximately 2.5 million users. While details surrounding the reported incident remain limited, it has been claimed that the exposed information included usernames, email addresses, subscriber-related information, login histories, and metadata linked to user accounts.

Reports further indicate that no financial information, payment card details, or government-issued identification data were affected. Nevertheless, exposure of personal account information can still pose privacy and security risks, including phishing attempts and account-targeted attacks.

VRChat has acknowledged concerns surrounding the reported compromise and stated that it has taken steps to strengthen its security posture. The company says it continues to invest in protective measures designed to reduce cyber risks and prevent similar incidents from occurring in the future.

The episode serves as a reminder that organizations today must contend not only with cyberattacks themselves but also with misinformation, fraudulent disclosures, and other tactics that can complicate incident response efforts and erode public trust.

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display