Threat reportData BreachTL-2026-3247

Rockstar Games Breaches: Lapsus$ Source Code Theft, ShinyHunters Anodot/Snowflake OAuth Data Theft (78.6M Records), and Cyberleek Fake GTA VI Build Malware

highACTIVE

Rockstar Games Breaches (TL-2026-3247), also tracked as Rockstar Games breach, is a high-severity data breach, first published 2026-10-10. It is attributed to ShinyHunters with medium confidence, affects Rockstar Games / Take-Two Interactive Snowflake data warehouse, maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1078.004), and is covered by 9 detection rules and 8 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
3ShinyHunters
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-3247

Threat ID
TL-2026-3247
Also known as
Rockstar Games breach, Anodot supply-chain token theft, Fake GTA VI 113GB build
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution
ShinyHunters, LAPSUS, Cyberleek
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
gaming, entertainment, technology, saas
Target regions
Global, North America, united kingdom
Detection rules
9
Indicators of compromise
8

Malware and tooling in Rockstar Games Breaches

Malware and tooling: Dataleak, Fake GTA 6 Mobile app

How Rockstar Games Breaches works

Rockstar Games has been hit by three separate incidents: a 2022 Lapsus$ intrusion (MFA-fatigue, plaintext credentials in Slack/Confluence) that exposed source code and ~90 development videos; an April 2026 ShinyHunters theft of ~78.6M analytics records from Snowflake using tokens stolen from SaaS provider Anodot; and an August 2026 Cyberleek gameplay leak that criminals used as cover for a fake 113GB GTA VI build carrying a ~50KB malicious payload.

This record consolidates three distinct, unrelated-in-mechanism incidents affecting Rockstar Games (Take-Two Interactive) as reported by Cyber Security News (2026-10-07) and corroborated by BleepingComputer, Deepwatch, Vectra, Security Affairs, TechRadar and others.

1) Lapsus$ (September 2022). Per reporting, the attacker used legitimate credentials and repeatedly triggered MFA approval prompts until an employee accepted (MFA fatigue / push bombing). Inside the environment the attacker searched Slack and Atlassian Confluence for credentials and API keys shared in plaintext and used them to pivot toward development systems. Roughly 90 development videos and source code were stolen. UK court proceedings later identified Arion Kurtaj as a Lapsus$ member involved in the intrusion; Rockstar reportedly put the cost at about $5 million.

2) ShinyHunters / Anodot / Snowflake (April 2026). ShinyHunters compromised Anodot, a SaaS analytics/anomaly-detection provider, and stole long-lived authentication (OAuth) tokens that Anodot held to connect to customer cloud data platforms. Anodot reported connector outages for Snowflake, Amazon S3 and Amazon Kinesis on 2026-04-04; by 2026-04-07 stolen tokens were reported in use against more than a dozen customer environments. Because the tokens were valid and reusable, the attackers authenticated as a trusted integration without cracking passwords or defeating MFA. Deepwatch (CA-A-26-006) describes bulk SELECT and COPY INTO activity by service accounts and possible creation of unauthorized external stages, blending with normal administrative traffic. ShinyHunters posted the Rockstar claim on 2026-04-11 (leak-site text: 'Your Snowflake instances metrics data was compromised thanks to Anodot.com'), set an extortion deadline of 2026-04-14, and leaked data after it lapsed. The ~78.6M records cover in-game revenue and purchase metrics, player-behavior tracking, GTA Online / Red Dead Online economy data, Zendesk customer-support analytics, and fraud-detection and anti-cheat model testing data; per reporting this excludes passwords, payment data, source code and GTA VI assets. Rockstar stated that 'a limited amount of non-material company information was accessed in connection with a third-party data breach.' Snowflake confirmed unusual activity in customer accounts tied to the third-party integration and locked affected accounts. Vimeo (~119,000 users) was another reported Anodot-linked victim.

3) Cyberleek / fake GTA VI build (August 2026). A persona calling itself Cyberleek began publishing unreleased GTA VI gameplay footage on 2026-08-18 (13+ videos mapping the 'Leonida' setting); per the source article associated domains were registered on 2026-08-14. Take-Two filed DMCA subpoenas on 2026-08-20 against Microsoft and Discord to identify the persona. Riding the hype, a ~113GB 'playable GTA VI build' circulated; a researcher (@Aidas29506493, analysis posted 2026-08-22) found it to be ~99.99% zero padding with a ~50KB malicious payload. Decompiled content reportedly contained a PowerShell Defender exclusion of the system drive (Add-MpPreference -ExclusionPath %SystemDrive%\) and taskkill -f to terminate security tools; some commentary speculates ransomware but the payload family is not confirmed. Security Affairs additionally reports torrent/piracy-site, Discord and mirror distribution, fake GTA 6 sites with Windows installers using DLL side-loading, a counterfeit 'GTA 6 Mobile' app redirecting to infostealer/ransomware domains, and phishing pages mimicking Rockstar Social Club login. No hashes, IPs or domains were published in any source reviewed; BeaconBeagle correlation was not applicable because no network IOCs are available.

Contributing weaknesses (Lares): poor isolation of prerelease development environments, long-lived reusable OAuth tokens not bound to a client, plaintext credentials in collaboration tools, and approval-prompt MFA. Single-source caveat: the originating article is not a priority CTI source; core facts are corroborated by the additional sources listed.

MITRE ATT&CK techniques used in TL-2026-3247

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1078.004 Valid Accounts: Cloud Accounts

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

Execution

T1204.002 User Execution: Malicious File

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Credential Access

T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1621 Multi-Factor Authentication Request Generation

Exfiltration

T1567 Exfiltration Over Web Service

stealth

T1574.001 DLL

Impact

T1657 Financial Theft

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Rockstar Games Breaches

  • Rockstar Games / Take-Two Interactive — Snowflake data warehouse analytics (GTA Online, Red Dead Online)
    Vulnerable versions: Anodot-integrated tenant, April 2026
  • Anodot — Anodot SaaS analytics platform (Snowflake, Amazon S3, Amazon Kinesis connectors)
    Vulnerable versions: Customer OAuth/authentication tokens held by Anodot, April 2026
  • Snowflake — Snowflake customer accounts with third-party integrations
    Vulnerable versions: Accounts using stolen Anodot integration tokens
  • Rockstar Games — Internal Slack / Atlassian Confluence / dev environment (2022)
    Vulnerable versions: September 2022
  • Microsoft — Windows (targets of fake GTA VI build payload)
    Vulnerable versions: Windows systems executing the fake build

Remediation for Rockstar Games Breaches

Immediate actions

  • Revoke and rotate all OAuth/API tokens issued to Anodot and other third-party analytics integrations; review Snowflake, S3 and Kinesis connector access
  • Review Snowflake query and access history for bulk SELECT / COPY INTO by integration service accounts and for newly created external stages
  • Block and warn users against downloading purported leaked GTA VI builds (113GB ISO/archive); do not execute
  • Hunt for Add-MpPreference exclusions covering the system drive and taskkill -f against security tooling

Workarounds

  • Restrict Snowflake network policies to known integration egress ranges where the vendor supports it
  • Alert on Defender exclusion changes and on tamper events

Longer-term hardening

  • Cryptographically bind service tokens to authorized clients (sender-constrained tokens) and enforce short lifetimes with automated rotation
  • Replace approval-prompt MFA with phishing-resistant hardware keys
  • Isolate prerelease development environments and auto-quarantine networks exceeding 50GB outbound to unfamiliar destinations
  • Monitor collaboration tools (Slack, Confluence) for mass downloads, plaintext credentials and credential testing
  • Apply least privilege and baseline activity windows for third-party integrations; correlate token usage across platforms

Weaknesses (CWE) in Rockstar Games Breaches

CWE-522, CWE-798, CWE-308

Timeline of Rockstar Games Breaches

  • Lapsus$ intrudes on Rockstar via valid credentials plus MFA-fatigue, searches Slack and Confluence for plaintext credentials/API keys, and steals source code and ~90 development videos (exact day not given in the sources reviewed)
  • Anodot reports outages on its Snowflake, Amazon S3 and Amazon Kinesis connectors
  • BleepingComputer reports stolen Anodot tokens being used to access data in more than a dozen customer environments
  • ShinyHunters posts the Rockstar claim on its leak site: 'Your Snowflake instances metrics data was compromised thanks to Anodot.com'
  • ShinyHunters tells Reuters it holds 78.6M records; Rockstar confirms 'a limited amount of non-material company information' was accessed via a third-party breach; Snowflake locks affected accounts
  • Extortion deadline expires and ShinyHunters begins publishing the stolen Rockstar analytics data
  • Domains associated with Cyberleek are registered (per Cyber Security News)
  • Cyberleek begins publishing unreleased GTA VI gameplay footage (13+ videos)
  • Take-Two files DMCA subpoenas in New York federal court against Microsoft and Discord seeking records identifying the Cyberleek persona
  • Researcher @Aidas29506493 publishes analysis showing the 113GB 'GTA VI build' is ~99.99% zero padding with a ~50KB malicious payload that excludes the system drive from Defender and kills security tools
  • Cyber Security News consolidates the three Rockstar incidents and Lares mitigation guidance

Sources cited for Rockstar Games Breaches

Detection coverage for TL-2026-3247

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3247 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats