Threat reportData BreachTL-2026-3247
Rockstar Games Breaches: Lapsus$ Source Code Theft, ShinyHunters Anodot/Snowflake OAuth Data Theft (78.6M Records), and Cyberleek Fake GTA VI Build Malware
Rockstar Games Breaches (TL-2026-3247), also tracked as Rockstar Games breach, is a high-severity data breach, first published 2026-10-10. It is attributed to ShinyHunters with medium confidence, affects Rockstar Games / Take-Two Interactive Snowflake data warehouse, maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1078.004), and is covered by 9 detection rules and 8 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 3ShinyHunters
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-3247
- Threat ID
- TL-2026-3247
- Also known as
- Rockstar Games breach, Anodot supply-chain token theft, Fake GTA VI 113GB build
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution
- ShinyHunters, LAPSUS, Cyberleek
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- gaming, entertainment, technology, saas
- Target regions
- Global, North America, united kingdom
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in Rockstar Games Breaches
Malware and tooling: Dataleak, Fake GTA 6 Mobile app
How Rockstar Games Breaches works
Rockstar Games has been hit by three separate incidents: a 2022 Lapsus$ intrusion (MFA-fatigue, plaintext credentials in Slack/Confluence) that exposed source code and ~90 development videos; an April 2026 ShinyHunters theft of ~78.6M analytics records from Snowflake using tokens stolen from SaaS provider Anodot; and an August 2026 Cyberleek gameplay leak that criminals used as cover for a fake 113GB GTA VI build carrying a ~50KB malicious payload.
This record consolidates three distinct, unrelated-in-mechanism incidents affecting Rockstar Games (Take-Two Interactive) as reported by Cyber Security News (2026-10-07) and corroborated by BleepingComputer, Deepwatch, Vectra, Security Affairs, TechRadar and others.
1) Lapsus$ (September 2022). Per reporting, the attacker used legitimate credentials and repeatedly triggered MFA approval prompts until an employee accepted (MFA fatigue / push bombing). Inside the environment the attacker searched Slack and Atlassian Confluence for credentials and API keys shared in plaintext and used them to pivot toward development systems. Roughly 90 development videos and source code were stolen. UK court proceedings later identified Arion Kurtaj as a Lapsus$ member involved in the intrusion; Rockstar reportedly put the cost at about $5 million.
2) ShinyHunters / Anodot / Snowflake (April 2026). ShinyHunters compromised Anodot, a SaaS analytics/anomaly-detection provider, and stole long-lived authentication (OAuth) tokens that Anodot held to connect to customer cloud data platforms. Anodot reported connector outages for Snowflake, Amazon S3 and Amazon Kinesis on 2026-04-04; by 2026-04-07 stolen tokens were reported in use against more than a dozen customer environments. Because the tokens were valid and reusable, the attackers authenticated as a trusted integration without cracking passwords or defeating MFA. Deepwatch (CA-A-26-006) describes bulk SELECT and COPY INTO activity by service accounts and possible creation of unauthorized external stages, blending with normal administrative traffic. ShinyHunters posted the Rockstar claim on 2026-04-11 (leak-site text: 'Your Snowflake instances metrics data was compromised thanks to Anodot.com'), set an extortion deadline of 2026-04-14, and leaked data after it lapsed. The ~78.6M records cover in-game revenue and purchase metrics, player-behavior tracking, GTA Online / Red Dead Online economy data, Zendesk customer-support analytics, and fraud-detection and anti-cheat model testing data; per reporting this excludes passwords, payment data, source code and GTA VI assets. Rockstar stated that 'a limited amount of non-material company information was accessed in connection with a third-party data breach.' Snowflake confirmed unusual activity in customer accounts tied to the third-party integration and locked affected accounts. Vimeo (~119,000 users) was another reported Anodot-linked victim.
3) Cyberleek / fake GTA VI build (August 2026). A persona calling itself Cyberleek began publishing unreleased GTA VI gameplay footage on 2026-08-18 (13+ videos mapping the 'Leonida' setting); per the source article associated domains were registered on 2026-08-14. Take-Two filed DMCA subpoenas on 2026-08-20 against Microsoft and Discord to identify the persona. Riding the hype, a ~113GB 'playable GTA VI build' circulated; a researcher (@Aidas29506493, analysis posted 2026-08-22) found it to be ~99.99% zero padding with a ~50KB malicious payload. Decompiled content reportedly contained a PowerShell Defender exclusion of the system drive (Add-MpPreference -ExclusionPath %SystemDrive%\) and taskkill -f to terminate security tools; some commentary speculates ransomware but the payload family is not confirmed. Security Affairs additionally reports torrent/piracy-site, Discord and mirror distribution, fake GTA 6 sites with Windows installers using DLL side-loading, a counterfeit 'GTA 6 Mobile' app redirecting to infostealer/ransomware domains, and phishing pages mimicking Rockstar Social Club login. No hashes, IPs or domains were published in any source reviewed; BeaconBeagle correlation was not applicable because no network IOCs are available.
Contributing weaknesses (Lares): poor isolation of prerelease development environments, long-lived reusable OAuth tokens not bound to a client, plaintext credentials in collaboration tools, and approval-prompt MFA. Single-source caveat: the originating article is not a priority CTI source; core facts are corroborated by the additional sources listed.
MITRE ATT&CK techniques used in TL-2026-3247
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1078.004 Valid Accounts: Cloud Accounts
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
Execution
T1204.002 User Execution: Malicious File
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Credential Access
T1528 Steal Application Access Token; T1552.001 Unsecured Credentials: Credentials In Files; T1621 Multi-Factor Authentication Request Generation
Exfiltration
T1567 Exfiltration Over Web Service
stealth
Impact
defense-impairment
Affected products and versions in Rockstar Games Breaches
- Rockstar Games / Take-Two Interactive — Snowflake data warehouse analytics (GTA Online, Red Dead Online)
Vulnerable versions: Anodot-integrated tenant, April 2026 - Anodot — Anodot SaaS analytics platform (Snowflake, Amazon S3, Amazon Kinesis connectors)
Vulnerable versions: Customer OAuth/authentication tokens held by Anodot, April 2026 - Snowflake — Snowflake customer accounts with third-party integrations
Vulnerable versions: Accounts using stolen Anodot integration tokens - Rockstar Games — Internal Slack / Atlassian Confluence / dev environment (2022)
Vulnerable versions: September 2022 - Microsoft — Windows (targets of fake GTA VI build payload)
Vulnerable versions: Windows systems executing the fake build
Remediation for Rockstar Games Breaches
Immediate actions
- Revoke and rotate all OAuth/API tokens issued to Anodot and other third-party analytics integrations; review Snowflake, S3 and Kinesis connector access
- Review Snowflake query and access history for bulk SELECT / COPY INTO by integration service accounts and for newly created external stages
- Block and warn users against downloading purported leaked GTA VI builds (113GB ISO/archive); do not execute
- Hunt for Add-MpPreference exclusions covering the system drive and taskkill -f against security tooling
Workarounds
- Restrict Snowflake network policies to known integration egress ranges where the vendor supports it
- Alert on Defender exclusion changes and on tamper events
Longer-term hardening
- Cryptographically bind service tokens to authorized clients (sender-constrained tokens) and enforce short lifetimes with automated rotation
- Replace approval-prompt MFA with phishing-resistant hardware keys
- Isolate prerelease development environments and auto-quarantine networks exceeding 50GB outbound to unfamiliar destinations
- Monitor collaboration tools (Slack, Confluence) for mass downloads, plaintext credentials and credential testing
- Apply least privilege and baseline activity windows for third-party integrations; correlate token usage across platforms
Weaknesses (CWE) in Rockstar Games Breaches
Timeline of Rockstar Games Breaches
- Lapsus$ intrudes on Rockstar via valid credentials plus MFA-fatigue, searches Slack and Confluence for plaintext credentials/API keys, and steals source code and ~90 development videos (exact day not given in the sources reviewed)
- Anodot reports outages on its Snowflake, Amazon S3 and Amazon Kinesis connectors
- BleepingComputer reports stolen Anodot tokens being used to access data in more than a dozen customer environments
- ShinyHunters posts the Rockstar claim on its leak site: 'Your Snowflake instances metrics data was compromised thanks to Anodot.com'
- ShinyHunters tells Reuters it holds 78.6M records; Rockstar confirms 'a limited amount of non-material company information' was accessed via a third-party breach; Snowflake locks affected accounts
- Extortion deadline expires and ShinyHunters begins publishing the stolen Rockstar analytics data
- Domains associated with Cyberleek are registered (per Cyber Security News)
- Cyberleek begins publishing unreleased GTA VI gameplay footage (13+ videos)
- Take-Two files DMCA subpoenas in New York federal court against Microsoft and Discord seeking records identifying the Cyberleek persona
- Researcher @Aidas29506493 publishes analysis showing the 113GB 'GTA VI build' is ~99.99% zero padding with a ~50KB malicious payload that excludes the system drive from Defender and kills security tools
- Cyber Security News consolidates the three Rockstar incidents and Lares mitigation guidance
Sources cited for Rockstar Games Breaches
- Hackers Steal Rockstar Source Code, 78.6 Million Records and Playable GTA VI Build
- Stolen Rockstar Games analytics data leaked by extortion gang
- CA-A-26-006: ShinyHunters Breaches Rockstar Games via Third-Party Cloud Integration
- The rise of supply chain driven data theft in SaaS environments
- Millions of Rockstar Games business records stolen, hacking group says
- Rockstar hackers publish 78.6 million stolen records
- Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data
- Cybercriminals Turn GTA VI Leaks Into Malware Bait
- Fake GTA VI ISO download is malware: 113GB is 99.99% zeroes with a tiny virus attached
- Take-Two files subpoenas asking Microsoft and Discord for records in hunt for GTA 6 leaker
- Teenager involved with hack which led to GTA 6 leak, court finds
Detection coverage for TL-2026-3247
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3247 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.