VRChat data breach exposes 2.4M users, but they say it’s fake


VRChat says a widely reported breach notice claiming 2.4 million users were exposed is fake, and that it has no reason to believe its systems were compromised.

Key takeaways:

A breach notification was filed with the Office of the Maine Attorney General, claiming that VRChat had suffered a data incident.

ADVERTISEMENT

The notice said 2.4 million, the majority of VRChat’s global userbase, were compromised during the breach.

Data such as “name or other personal identifier in combination with…” was exposed, but little evidence was provided to support the claims.

vrchat notification maine
Screenshot from the Office of the Maine Attorney General

Media everywhere jumped on the news, reporting that VRChat has exposed the personal data of the majority of its user base.

However, VRChat has denied that it ever suffered a data breach and that the notification submitted was fake.

Cybernews has reached out to VRChat for comment.

VRChat didn’t submit the data incident notices and has “no reason to believe that [it’s] systems have been compromised,” the company said on Reddit.

reddit reply vrchat
Screenshot from Reddit
ADVERTISEMENT

The notice included a PDF written and sent by an employee who doesn’t exist, according to VRChat staff.

The PDF has since been taken down, but, at the time of writing, the notice is still visible on the Attorney General’s website.

An actor posing as VRChat filed the notice, saying that the company had been breached between May 10th and May 12th.

The supposed hack involved unauthorized access to VRChat’s cloud environment, and the hacker allegedly took users’ login and profile data, according to Malwarebytes.

office maine general screenshot
Screenshot from the Office of the Maine Attorney General

Data included VRChat usernames, email addresses, VRChat+ subscription statuses, and login history (device information, hardware identifiers, and IP addresses).

VRChat isn’t the first to be framed by unknown actors. Discord was accused of a breach that allegedly affected 10 million users.

Discord users were allegedly impacted by "insider wrongdoing," but the report was riddled with red flags suggesting it may be bogus.

discord data breach

Similar to VRChat, the entity responsible for the breach notification, a person named “Xavier Morrison,” provided fake contact information.

ADVERTISEMENT

There was also no trace of customer notification emails, suggesting that an outside individual filed the notification just to stir up trouble.

jurgita justinasv Izabelė Pukėnaitė vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google

Unlock more exclusive Cybernews content on YouTube.