# Rockstar Games Breaches: Lapsus$ Source Code Theft, ShinyHunters Anodot/Snowflake OAuth Data Theft (78.6M Records), and Cyberleek Fake GTA VI Build Malware

> Rockstar Games has been hit by three separate incidents: a 2022 Lapsus$ intrusion (MFA-fatigue, plaintext credentials in Slack/Confluence) that exposed source code and ~90 development videos; an April 2026 ShinyHunters theft of ~78.6M analytics records from Snowflake using tokens stolen from SaaS provider Anodot; and an August 2026 Cyberleek gameplay leak that criminals used as cover for a fake 113GB GTA VI build carrying a ~50KB malicious payload.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3247
- **ID:** TL-2026-3247
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Actor:** ShinyHunters
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)

## Description

This record consolidates three distinct, unrelated-in-mechanism incidents affecting Rockstar Games (Take-Two Interactive) as reported by Cyber Security News (2026-10-07) and corroborated by BleepingComputer, Deepwatch, Vectra, Security Affairs, TechRadar and others.

1) Lapsus$ (September 2022). Per reporting, the attacker used legitimate credentials and repeatedly triggered MFA approval prompts until an employee accepted (MFA fatigue / push bombing). Inside the environment the attacker searched Slack and Atlassian Confluence for credentials and API keys shared in plaintext and used them to pivot toward development systems. Roughly 90 development videos and source code were stolen. UK court proceedings later identified Arion Kurtaj as a Lapsus$ member involved in the intrusion; Rockstar reportedly put the cost at about $5 million.

2) ShinyHunters / Anodot / Snowflake (April 2026). ShinyHunters compromised Anodot, a SaaS analytics/anomaly-detection provider, and stole long-lived authentication (OAuth) tokens that Anodot held to connect to customer cloud data platforms. Anodot reported connector outages for Snowflake, Amazon S3 and Amazon Kinesis on 2026-04-04; by 2026-04-07 stolen tokens were reported in use against more than a dozen customer environments. Because the tokens were valid and reusable, the attackers authenticated as a trusted integration without cracking passwords or defeating MFA. Deepwatch (CA-A-26-006) describes bulk SELECT and COPY INTO activity by service accounts and possible creation of unauthorized external stages, blending with normal administrative traffic. ShinyHunters posted the Rockstar claim on 2026-04-11 (leak-site text: 'Your Snowflake instances metrics data was compromised thanks to Anodot.com'), set an extortion deadline of 2026-04-14, and leaked data after it lapsed. The ~78.6M records cover in-game revenue and purchase metrics, player-behavior tracking, GTA Online / Red Dead Online economy data, Zendesk customer-support analytics, and fraud-detection and anti-cheat model testing data; per reporting this excludes passwords, payment data, source code and GTA VI assets. Rockstar stated that 'a limited amount of non-material company information was accessed in connection with a third-party data breach.' Snowflake confirmed unusual activity in customer accounts tied to the third-party integration and locked affected accounts. Vimeo (~119,000 users) was another reported Anodot-linked victim.

3) Cyberleek / fake GTA VI build (August 2026). A persona calling itself Cyberleek began publishing unreleased GTA VI gameplay footage on 2026-08-18 (13+ videos mapping the 'Leonida' setting); per the source article associated domains were registered on 2026-08-14. Take-Two filed DMCA subpoenas on 2026-08-20 against Microsoft and Discord to identify the persona. Riding the hype, a ~113GB 'playable GTA VI build' circulated; a researcher (@Aidas29506493, analysis posted 2026-08-22) found it to be ~99.99% zero padding with a ~50KB malicious payload. Decompiled content reportedly contained a PowerShell Defender exclusion of the system drive (Add-MpPreference -ExclusionPath %SystemDrive%\) and taskkill -f to terminate security tools; some commentary speculates ransomware but the payload family is not confirmed. Security Affairs additionally reports torrent/piracy-site, Discord and mirror distribution, fake GTA 6 sites with Windows installers using DLL side-loading, a counterfeit 'GTA 6 Mobile' app redirecting to infostealer/ransomware domains, and phishing pages mimicking Rockstar Social Club login. No hashes, IPs or domains were published in any source reviewed; BeaconBeagle correlation was not applicable because no network IOCs are available.

Contributing weaknesses (Lares): poor isolation of prerelease development environments, long-lived reusable OAuth tokens not bound to a client, plaintext credentials in collaboration tools, and approval-prompt MFA. Single-source caveat: the originating article is not a priority CTI source; core facts are corroborated by the additional sources listed.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1199 Trusted Relationship
- T1528 Steal Application Access Token
- T1621 Multi-Factor Authentication Request Generation
- T1552.001 Unsecured Credentials: Credentials In Files
- T1078.004 Valid Accounts: Cloud Accounts
- T1213 Data from Information Repositories
- T1530 Data from Cloud Storage
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft
- T1204.002 User Execution: Malicious File
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1574.001 DLL

## Sources

- [Hackers Steal Rockstar Source Code, 78.6 Million Records and Playable GTA VI Build](https://cybersecuritynews.com/playable-gta-vi-build/)
- [Stolen Rockstar Games analytics data leaked by extortion gang](https://bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang)
- [CA-A-26-006: ShinyHunters Breaches Rockstar Games via Third-Party Cloud Integration](https://www.deepwatch.com/labs/ca-a-26-006-shinyhunters-breaches-rockstar-games-via-third-party-cloud-integration/)
- [The rise of supply chain driven data theft in SaaS environments](https://www.vectra.ai/blog/the-rise-of-supply-chain-driven-data-theft-in-saas-environments)
- [Millions of Rockstar Games business records stolen, hacking group says](https://www.ctvnews.ca/sci-tech/article/millions-of-rockstar-games-business-records-stolen-hacking-group-says/)
- [Rockstar hackers publish 78.6 million stolen records](https://www.techradar.com/pro/security/rockstar-hackers-publish-78-6-million-stolen-records-but-many-of-us-will-be-disappointed)
- [Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data](https://www.bitdefender.com/en-au/blog/hotforsecurity/rockstar-games-data-breach)
- [Cybercriminals Turn GTA VI Leaks Into Malware Bait](https://securityaffairs.com/197772/malware/cybercriminals-turn-gta-vi-leaks-into-malware-bait.html)
- [Fake GTA VI ISO download is malware: 113GB is 99.99% zeroes with a tiny virus attached](https://techradar.com/pro/of-course-this-fake-gta-vi-iso-download-is-malware-testers-reveal-113gb-download-is-99-99-empty-zeroes-with-a-tiny-virus-attached)
- [Take-Two files subpoenas asking Microsoft and Discord for records in hunt for GTA 6 leaker](https://videogameschronicle.com/news/take-two-files-subpoenas-to-microsoft-and-discord-in-hunt-for-gta-6-leaker/)
- [Teenager involved with hack which led to GTA 6 leak, court finds](https://www.techradar.com/gaming/teenager-involved-with-hack-which-led-to-gta-6-leak-court-finds)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3247
