We’re sharing an update about a security incident at Canny, the service that powers VRChat’s feedback site at feedback.vrchat.com. This incident is limited to the feedback site and did not involve VRChat’s platform, app, or account systems.
Everyone affected has now been emailed directly with details about the information involved. If you haven’t received an email from us about this, your account was not affected. Check your inbox and spam folder for the email address associated with your feedback site account if you’re not sure.
On August 28, Canny told us an unauthorized party had accessed one of their internal systems. We disconnected our integrations and replaced the affected credentials shortly after, and found no evidence that those credentials were used against VRChat directly.
For affected accounts, the information likely accessed included things like usernames, public account images, email addresses, account IDs, and account activity dates on the feedback site.
Your VRChat account and login are unaffected. VRChat passwords, payment information, uploaded content, and in-world activity were not part of this incident, and you don’t need to change your VRChat password.
Canny has completed its investigation with an outside forensics firm, found no further unauthorized activity after August 28, and has no evidence that the information involved has been published or shared.
Be cautious of messages referencing Canny or the feedback site, especially ones asking you to click a link or enter a password. VRChat will never ask you to confirm your password by email.
For questions: TSsupport@vrchat.com