For six years, the quiet workhorse of American breach transparency wasn't a federal agency. It was a plain government web page in Augusta, Maine. On June 12, the Maine Attorney General's office turned it off — on purpose — and six weeks later it is still dark, with no timeline for coming back.
What happened. It took two forged filings to bring it down. On June 8, someone submitted a breach notice impersonating Discord — 10 million users, an "insider wrongdoing" story, a contact address at Gmail, and a consumer-notification date of January 1, 2000. On June 11, a second hoax impersonating VRChat claimed 2.4 million users hacked; VRChat says it filed nothing. Both went live instantly, because — as the AG's office admitted on the record — "the submitting entity fills out the information and it goes directly onto the site." No verification. No gatekeeper. The office pulled the public database, removed the fakes, attributed them to "an unknown entity unrelated to either company," and said it was reviewing procedures. No one has been identified. And despite the design flaw existing in plenty of states, we found no reporting of the same trick actually landing anywhere but Maine.
Why it stings. Maine punched far above its 1.4 million residents. State law demands notification if a single Mainer is affected — and, rare among states, demands the nationwide total. That quirk turned a small state's portal into a national breach ticker, quietly load-bearing for journalists, researchers, threat-intel teams, and class-action lawyers. Reports still flow in, through a submission-only AccessGov form. Nothing flows out: no list, no search, no export. Want a record? Email the office. The old public listing URL no longer serves the database — it returned a flat 404 through late July and now redirects to the AG's consumer-protection page. All that survives in the open is a redacted archive frozen at September 2020.
Prognosis. Unknown, and we won't pretend otherwise. The AG has promised only to make abuse "less likely… while preserving the public availability of such information" — no date, no fix described. As of today, the page still reads that the database "will remain offline until then." No US state has ever taken a breach feed down and brought it back, so there's no precedent to reassure anyone. Those four words — remain offline until then — are our tripwire. When they vanish from the page, we treat it as the first sign the lights may be coming back on.
What we saved. Before the door closed, we captured what we believe is the database's complete online life: 5,913 Maine records, July 7, 2020 through June 11, 2026 — the final filing landing one day before the takedown. (SecurityWeek independently pegged the portal at "nearly 6,000 incidents since mid-2020.") Maine is about 19% of our 17-state AG corpus and 8% of everything we track — and it still works for a living: roughly 56% of those records link to a breach we also see filed in another state, and about 10.5% corroborate an entirely different channel — an SEC 8-K, an HHS filing, a ransomware leak post, a news report. The public portal went dark; the intelligence in it did not.
How we're watching. Maine is the lone entry on our "known-dark" list — muted from alerts, never dropped from monitoring. Our collector still knocks on the door every run and fails loudly on purpose; as of today that's 388 straight failures, each one a deliberate check that the source hasn't quietly returned. We re-read the AG's "remain offline" language roughly weekly. The moment Maine flips — restored, relocated, or gone for good — you'll hear it from us first.
