Author Archives: James Jardine

Fake Breach Reports: Serious or Silly?

There was an interesting report that recently came out regarding fake data breach reports being submitted to the Main Data Breach Reporting Portal. The fake reports were focused on VRChat and Discord. According to the reports (article linked below), a user was able to submit a breach notification to the portal of a company they are not a part of. It might not seem like a big deal, but the more I think about it, the more I consider different risks and costs for the companies at hand. In addition, there is a potential risk for a sophisticated social engineering attack from this. Let’s talk about it.

User Perspective

It might not seem apparent, but there was a specific threat scenario I thought of right away. Since the actual issue is not directly related to the end user, it will typically lead us to a social engineering attack of some sort. One of the things that makes a social engineering attack more credible is using official sites. In this case, it is the Main Data Breach Reporting Portal.

Imagine that an attacker has identified the company they want to target. They create a fake data breach report and get it on an official, trusted site. The stage is set. Not there are a few different options that could happen (and of course these are not all of them). Two potential options are to send an email asking users to login in to change their password and reference the legitimate site. However, rather than take them to the real site for password reset, they are directed to a malicious site controlled by the attacker, that looks like the official site. The attacker captures the credentials and takes over the account.

In scenario two, the attackers alert the user to the breach as if it is from the official company. The user is then told they have received free identity protection services and are provided a link to sign up. The link is to the attacker controlled site and may collect personal details that shouldn’t be shared.

These are just two examples, and if you know me, you know how much I hate how we default to social engineering as the the only attack vector. Don’t get me wrong, I do not see this as a common attack vector, but more so just highlighting how this could be used.

Company Perspective

Let’s switch gears and talk about the target company concerns when a fake breach report is submitted. I want to start with the idea that a company is often guilty until proven innocent. What I mean by that is people are quick to believe what they hear. If someone starts the rumor that a company was breached, that will spread quickly without any fact checking. Add in this situation where a simple fact check to a trusted site confirms the report and now a company has to start playing catchup.

This comes with many potential costs, both from monetary and resource related. I can already see the panic setting in when they get this word that they have been breached. Sure, you can say that you, or no one else from your company submitted that report, but in today’s landscape, that is going to be tough. Even if you are able to quickly say it is not true, there is going to be some level of effort to verify that before responding.

From a business perspective, there is going to be some level of effort to verify no breach actually occurred. Additionally, the company may have to try to contain any reputational harm. What goes on the internet, stays on the internet. It is tough to put a genie back in a bottle. So when you get negative exposure there is going to be work to try and correct that.

We do see this already with researchers publicly announcing vulnerabilities and issues with organizations. I would like to hope that in many of those cases they have the evidence that shows their claims are real. I think this is different then a false report on a trusted site.

Wrap Up

This reminds me a little of a few years ago when hackers filed a complaint with the SEC when a company didn’t want to play ball with them and the company failed to file an 8K report (link below). We have seen some interesting tactics over the years. This is interesting because we don’t really know the motive behind it. Maybe it was just because they were upset with the companies targeted, bored, or had some other malicious intent.

It does raise questions about how these state breach portals work and verify the claims that are submitted. Maine ended up taking their site offline to review how the process works so that they can make proper changes to stop this from happening in the future. It will be interesting to see what process changes happen to help solve the problem. Like all new tactics we see, this is another mole that has popped its head up that security will whack down while we wait to see what else pops up.

Events like this are interesting, but not earth shattering. I think it is valuable to be aware of these things as it raises our awareness, but shouldn’t be seen as critical events until we actually see evidence that warrants that.

References:

Maine Takes Data Breach Reporting Portal Offline After Fake VRChat and Discord Filings

Hackers Complain to SEC Company They Hacked Failed to Disclose the Incident

Internet Search is Changing – Is it for the better?

Have you noticed how internet search is changing?
As long as I can remember, search worked by feeding it a few keywords or a question and it would return back thousands, or even hundreds of thousands of results. These results were prioritized by custom algorithms that take in multiple factors to prioritize them to direct you to a website for more information.
This is what most of us think of when we refer to “Googling” something. It is akin to the idea of going into a library and asking the librarian where to find a specific section of books. It didn’t lead to any direct answers, just a pointer to shelves full of books that we would then spend time searching through to find the answer we wanted.

Google Regular Search

As AI has started to take hold, I have seen how it has been embedded into our internet searches. This was a pretty cool enhancement in that the search engine would put together a simple response to your request in summary. I don’t know the statistics of it, but I am really interested to know how many searches end here, and the user never needs to click into one of the reference links.
This became more of a hybrid approach where it would give you a quick answer, but then provide a list of results like before to continue searching the book shelves for the answer you wanted.

Google AI Summary

Google’s new AI Mode takes it to the next step of a conversation. At this level, it is like you are holding a conversation with a guru of any subject. You are able to ask questions to get the answers. If the answer wasn’t quite right, you could change your question to get more specific. You keep asking questions until the response is acceptable. You will still see a list of references, related to the answer, but you won’t get hundreds of links. Think of it as if the guru gives you an answer and also provides a list of the books he used to get it. This is helpful because you may want more context or to even verify for yourself that the guru is correct.

Google AI Mode

Why do I bring this up? There was an interesting discussion on the Down the Security Rabbithole podcast, Episode 671 – It’s the End of the Internet As We Know It, that this was mentioned.
The discussion really got me thinking about how search is changing and the effects it has on the internet as a whole. I want to talk about two examples.

Effect on critical thinking
The advancement of how we search for information is absolutely amazing. The speed that we are able to find the answer to most questions has improved our ability to our jobs, grow our knowledge and help advance key research for things like technology, medicine, etc. The time it would have taken to look something up in a book was long when we were going to the library or digging through our collection of encyclopedias. I am amazed every day at the information that is available to my kids that I could have only dreamed of growing up.
I must consider the cost as well. Without guardrails in place, how do we ensure that people are still able to think critically about a problem? The results we are seeing come back from these search results can be pretty good, but they can also be pretty bad. How do people know when to believe the answer, or when to question it and dig deeper to verify the results?
The longer we go just taking the default answer from a search engine’s AI system, the further we get from spending cycles verifying the answers on our own.
These systems are getting better, but I am sure will always have their faults or build their own biases. What happens when a person asks what is 2+2 and the system returns 5? 20 years ago, I would have believed every person would question that based on their fundamental education. Today, in 2025, I believe there are people that would take this answer as fact without a question at all.
As time goes on, and people turn to Googling everything, at some point we lose that fundamental knowledge. We stop learning how to do simple addition because “why waste my time on that, when I can just ask ChatGPT?”.
Another example I give on the podcast is around cooking recipes. Have you ever just Googled how to make something simple, like chocolate chip cookies? With the new results we get from AI searches, they will just spit out a recipe. Sure, there might be some links to actual cooking sites, but why not just take the initial AI answer?
Do you know enough about food ingredients to trust the answer provided? What happens when the ingredients include something that is actually dangerous to humans? Would you know not to use that and question the recipe?
There are real world consequences to this.
Don’t get me wrong, there are similar consequences to you just following the recommendations on some random cooking site, or that influencer’s TikTok channel.

Ad Revenue
The other thing I find interesting is around ad revenue that powers both search engines and the organizations behind the links you click during historic searches. Search is free because they are making money through the ads payed by many of those links displayed and clicked. How will this affect the search providers when links are no longer displayed or they are not clicked because the AI answer was enough?
This question actually takes me back up to the pervious section where I discussed consumers just taking the AI answer and not digging deeper. What happens when the answers are biased by the target companies buying the promotions? Does this end up distorting the answers toward paid bias, and if so, how long does it take before one can easily sway the world to start believing something that just isn’t true? It just seems true because enough money was put into it to make it the theme of the answer. Then add to it that people no longer perform critical thinking and just take the answer as fact.

On the organization side, the side that pays for their ads to be in the search results, what effect do we see? If the consumer is just interacting with a bot and no links are displayed, you lose the visibility you once had. The chances of someone just finding you from a simple search decreases and less traffic may come to your site. Maybe there is some path that this tactic changes to be part of the AI results somehow, but that gets us back into the bias in those results if they are driven by sponsors.

It could just be that marketing has left search results behind. Maybe organizations have solved this through the use of social media channels. Maybe we will see commercials or ad banners start appearing in the AI chat bots.

Final Thoughts
It is an interesting time when we think about internet search offerings and how they are changing. Change isn’t always bad and the positive value in this case may outweigh the negatives. Our ability to get to answers more quickly has a lot of positive value to advancing a lot of things. However, there are some negatives that just need to be considered. We need to make sure that the responses provided are accurate and unbiased as to not start retraining our knowledge on inaccurate information. A small shift in our understandings can have a huge ripple effect years down the road.