DisclosureLens
Feed News/Feed status · Maine AG

Someone Faked a Discord Breach. Maine Turned Off America's Best Breach Database.

Maine's attorney general pulled the nation's most-cited breach registry offline after two hoax filings. Six weeks on, it's still dark — and our complete 5,913-record copy is preserved.

By DisclosureLens · July 24, 2026 · Updated July 26, 2026
Editorial illustration: a lobster in a Maine fishing shack, wearing a beanie and a “Maine” hoodie, typing a fake breach filing (“Red Lobster Hospitality LLC”) into the state Attorney General's breach-reporting portal, a masked cat beside it.
Illustration. The June hoax filings impersonated Discord and VRChat; no seafood company was involved.
DarkSource: state_ag_maine
Last capture
June 12, 2026
Poller
372 failed runs
Holdings
5,913 records
Last checked
July 31, 2026 · failed

The badge and figures above are read live from /v1/health/sources on each render. Hourly weekday poller (13:30–22:30 UTC) + ~weekly re-probe of the AG page's “remain offline” language.

For six years, the quiet workhorse of American breach transparency wasn't a federal agency. It was a plain government web page in Augusta, Maine. On June 12, the Maine Attorney General's office turned it off — on purpose — and six weeks later it is still dark, with no timeline for coming back.

What happened. It took two forged filings to bring it down. On June 8, someone submitted a breach notice impersonating Discord — 10 million users, an "insider wrongdoing" story, a contact address at Gmail, and a consumer-notification date of January 1, 2000. On June 11, a second hoax impersonating VRChat claimed 2.4 million users hacked; VRChat says it filed nothing. Both went live instantly, because — as the AG's office admitted on the record — "the submitting entity fills out the information and it goes directly onto the site." No verification. No gatekeeper. The office pulled the public database, removed the fakes, attributed them to "an unknown entity unrelated to either company," and said it was reviewing procedures. No one has been identified. And despite the design flaw existing in plenty of states, we found no reporting of the same trick actually landing anywhere but Maine.

Why it stings. Maine punched far above its 1.4 million residents. State law demands notification if a single Mainer is affected — and, rare among states, demands the nationwide total. That quirk turned a small state's portal into a national breach ticker, quietly load-bearing for journalists, researchers, threat-intel teams, and class-action lawyers. Reports still flow in, through a submission-only AccessGov form. Nothing flows out: no list, no search, no export. Want a record? Email the office. The old public listing URL no longer serves the database — it returned a flat 404 through late July and now redirects to the AG's consumer-protection page. All that survives in the open is a redacted archive frozen at September 2020.

Prognosis. Unknown, and we won't pretend otherwise. The AG has promised only to make abuse "less likely… while preserving the public availability of such information" — no date, no fix described. As of today, the page still reads that the database "will remain offline until then." No US state has ever taken a breach feed down and brought it back, so there's no precedent to reassure anyone. Those four words — remain offline until then — are our tripwire. When they vanish from the page, we treat it as the first sign the lights may be coming back on.

What we saved. Before the door closed, we captured what we believe is the database's complete online life: 5,913 Maine records, July 7, 2020 through June 11, 2026 — the final filing landing one day before the takedown. (SecurityWeek independently pegged the portal at "nearly 6,000 incidents since mid-2020.") Maine is about 19% of our 17-state AG corpus and 8% of everything we track — and it still works for a living: roughly 56% of those records link to a breach we also see filed in another state, and about 10.5% corroborate an entirely different channel — an SEC 8-K, an HHS filing, a ransomware leak post, a news report. The public portal went dark; the intelligence in it did not.

How we're watching. Maine is the lone entry on our "known-dark" list — muted from alerts, never dropped from monitoring. Our collector still knocks on the door every run and fails loudly on purpose; as of today that's 388 straight failures, each one a deliberate check that the source hasn't quietly returned. We re-read the AG's "remain offline" language roughly weekly. The moment Maine flips — restored, relocated, or gone for good — you'll hear it from us first.

Update log

  1. July 26, 2026
    URL change

    The old agviewer listing URL now 302-redirects to the AG's consumer-protection page instead of returning 404. The database itself remains offline — the “remain offline” language is still live — but a redirect is a state change worth logging: our poller only self-heals if the database returns at the original URL, so a relaunch elsewhere needs a poller update too.

  2. July 24, 2026
    Filed

    Six weeks dark. Re-verified the AG page still carries the “remain offline” language and the old listing URL returns 404. Our 5,913-record archive remains the complete preserved copy; the live poller has failed 388 consecutive times by design.

DisclosureLens tracks the state of every source it collects, not just the records. When this feed changes — restored, relocated, or gone for good — we log it here and notify subscribers. Browse the preserved per-state archives under /breach-notifications.