VRChat disclosed that unauthorized access to its cloud environment exposed data belonging to 2,436,782 users after an intrusion between May 10 and May 12. According to the company’s filing, the compromised information included VRChat usernames, associated email addresses, VRChat+ subscription status, login history, device and hardware identifiers, IP addresses, and linked Steam or Meta user IDs. VRChat said passwords, payment card data, and government ID documents used for age verification were not believed to be affected.
The company said it contained the incident, added security controls, and brought in external security experts to monitor for further threats. The breach raises immediate risks of phishing, account targeting, and credential-stuffing attempts against users who may have reused passwords on other services, while linked platform identifiers could enable broader identity correlation. Reporting also noted that VRChat disclosed the incident through a filing with Maine’s attorney general rather than a broad public announcement, and it did not offer identity theft or credit monitoring services.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Maine officials said their public breach notification portal was abused to publish a fabricated VRChat breach notice and removed the false entry while temporarily restricting public access and reviewing publication procedures. VRChat publicly denied any compromise, saying the notice was fake and that the named employee did not exist.
VRChat disclosed the incident in a filing with the Maine attorney general, stating that passwords, payment card data, and government ID documents used for age verification were not believed to be affected. The filing also said the company had contained the intrusion, added security controls, and engaged external security experts.
VRChat said unauthorized access to its cloud environment occurred between May 10 and May 12, 2026, exposing data tied to 2,436,782 users. The accessed information included usernames, email addresses, VRChat+ subscription status, login history, device and hardware identifiers, IP addresses, and linked Steam or Meta user IDs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcehello.vrchat.com
Open sourcemalware.news
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.