LIVE · cybersecurity feed
Live wire
breach

Maine forced to take down data breach portal after fake notices filed with authorities

The US state of Maine has taken its public data breach notification portal offline after someone submitted fraudulent breach disclosures impersonating two well-known technology companies. Read more in my article on the Hot for Security blog

zeroday.news · 47d ago

The state of Maine has temporarily taken down its public data breach notification portal after malicious actors submitted fraudulent breach disclosures, impersonating well-known technology companies. The false reports were publicly posted before their authenticity could be verified, leading the named companies to deny any breach had occurred.

The incident involved two companies: Discord, a popular messaging platform, and VRChat, a multiplayer social virtual reality platform. The fraudulent notification for Discord claimed that 10 million users were impacted by a data breach. However, this filing contained several red flags, including a Gmail address for contact, a placeholder phone number, and an unrealistic consumer notification date of January 1, 2000. It also lacked a standard component of legitimate filings: an example notification letter to affected customers.

A second, more convincing fake notice targeted VRChat. This filing alleged that hackers had accessed the company's cloud environment in May, exposing the data of over 2.4 million users. The fabricated notice listed compromised data such as usernames, email addresses, VRChat+ subscription status, login history, device identifiers, IP addresses, and linked Steam or Meta account IDs. This notification was submitted under the name "Scott Caruso" using a VRChat email address that does not exist.

Charles Tupper, Head of Community at VRChat, confirmed the notification was fraudulent, stating that VRChat did not submit it and the cited employee and email address are not real. He added that the company has no reason to believe its data or systems have been compromised. The office of the Maine Attorney General also confirmed it had no knowledge of any recent legitimate data breach reports from either VRChat or Discord.

Investigations suggest the system's vulnerability stemmed from a lack of a proper verification mechanism. The Maine data breach reporting system allowed anyone to submit a breach notification form, which would then be added to the portal website without any verification process. This enabled malicious actors to potentially cause reputational damage to companies by submitting seemingly legitimate, yet fabricated, breach notices.

The portal has been temporarily disabled to allow for a review of its procedures and to implement measures to prevent future abuse. The false reports concerning VRChat and Discord have been removed from the portal. It remains unknown who was responsible for the false submissions or whether the targeted companies were chosen deliberately. There is also uncertainty about how many other fraudulent breach notices, if any, might have been submitted before public access was suspended. The state hopes to enhance the portal's security when it is brought back online, as such services are relied upon by journalists and the public to disseminate information about data breaches.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]