Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GitHub AI Scans Code for Hidden Passwords Before Commits
October 8, 2026
FBI and Ghana Police Bust Cybercrime Ring, Seize 300+ Devices
October 8, 2026
Web3 Blockchain C2 Conceals Supply Chain Attacks on Cloud Credentials
October 8, 2026
Home/Threats/Rockstar Games Suffers Data Breach, GTA VI Source Code Stolen
Threats

Rockstar Games Suffers Data Breach, GTA VI Source Code Stolen

Key Takeaways Rockstar Games experienced multiple security incidents over several years, not a single, unified attack. Breaches led to the theft of Grand Theft Auto VI (GTA VI) source code, a...

David kimber
David kimber
October 7, 2026 5 Min Read
14 0

Key Takeaways

  • Rockstar Games experienced multiple security incidents over several years, not a single, unified attack.
  • Breaches led to the theft of Grand Theft Auto VI (GTA VI) source code, a playable development build, and 78.6 million business records.
  • Attack vectors included stolen employee credentials, multi-factor authentication (MFA) fatigue attacks, and compromised OAuth tokens from a third-party analytics provider.
  • Fake GTA VI downloads containing malware have also been observed, exploiting public interest in the unreleased game.
  • The incidents highlight critical vulnerabilities in identity management, third-party access, and the segmentation of sensitive development environments.

Gaming giant Rockstar Games has been hit by a series of distinct cyberattacks that collectively resulted in the compromise of its proprietary source code, a playable development build of the highly anticipated Grand Theft Auto VI (GTA VI), and a substantial 78.6 million business records. These incidents, occurring over several years, demonstrate a multifaceted threat landscape rather than a single, large-scale breach.

Table Of Content

  • Key Takeaways
  • Playable GTA VI Build Compromised
  • Build Security and Mitigation Strategies
  • What You Should Do

Investigations into these intrusions point to various initial access methods. These include the use of stolen employee credentials, persistent authentication prompt spamming to induce approval, and the exploitation of compromised access tokens belonging to an external service provider. Compounding these breaches, malicious actors have also leveraged the intense public interest in GTA VI by circulating fake game downloads embedded with malware, posing an additional risk to unsuspecting players.

Cybersecurity researchers at Lares, after analyzing the various incidents, identified one such malware instance disguised as a 113GB GTA VI build. This large file size was largely padding, concealing a much smaller, 50KB malicious payload. Such deceptive tactics underscore how the anticipation surrounding unreleased games can be weaponized to infect users’ systems. A detailed report from Lares said in a report shared with Cyber Security News (CSN) indicated that these attacks exposed weaknesses in how trusted accounts, connected services, and development systems are secured. The September 1 analysis by Lares specifically linked the breaches to issues with identity abuse and insufficient segmentation of sensitive development environments.

Playable GTA VI Build Compromised

In September 2022, the notorious hacking group Lapsus$ successfully acquired approximately 90 development videos and proprietary source code related to GTA VI. The Lares report outlines that the attacker gained entry by utilizing legitimate corporate credentials and repeatedly bombarding an employee with authentication requests until one was inadvertently approved, granting unauthorized access.

Once inside, the attacker systematically searched Rockstar’s collaboration platforms, including Slack and Atlassian Confluence, for sensitive information. This search yielded credentials, application keys, and internal server details that developers had unfortunately shared in plain text. These platforms, intended for communication and coordination, effectively became conduits for attackers to escalate privileges and access more critical resources. This particular incident underscores the importance of robust access control measures beyond just securing software itself. While previous reports on Lapsus$ detailed their methods of recruiting company insiders, Lares attributes this specific Rockstar intrusion to the exploitation of credentials and the tactic of repeated approval requests.

A separate incident in April 2026, attributed to the group ShinyHunters, resulted in the theft of 78.6 million records. Lares’ findings indicate that the attackers initially compromised Anodot, an analytics provider, from which they obtained long-lived OAuth tokens belonging to Anodot’s customers. These tokens were then leveraged to access Rockstar’s Snowflake data warehouse. These OAuth tokens acted as persistent access passes, allowing attackers to authenticate without needing to compromise a Rockstar employee account directly, as possession of the token was sufficient for access and not tied to the provider’s infrastructure. It is important to note that the analytics data stolen in April specifically concerned business analytics and did not include player passwords, payment information, source code, or GTA VI development assets, distinguishing it from the earlier source code theft.

Build Security and Mitigation Strategies

Lares places the Cyberleek incident in August 2026, noting that related domains were registered on August 14, with leaked material beginning to surface on August 18. This breach involved at least 13 gameplay videos and detailed mapping information of the fictional Leonida setting. The researchers characterize this footage as evidence of an unfinished, playable development build. However, they acknowledge several potential methods for how this build might have been executed: circumvented authentication checks, locally compiled stolen source code, or direct access to a modified development kit.

The Cyberleek group also reportedly linked further disclosures to cryptocurrency payments, influencing the release schedule of stolen content. In response to these leaks, Take-Two Interactive, Rockstar’s parent company, initiated copyright takedowns and pursued legal subpoenas to identify individuals involved in distributing the stolen material from platforms like Microsoft, Discord, and X (formerly Twitter).

Lares refutes unconfirmed rumors of a separate breach impacting Rockstar India, stating that forensic evidence does not support such claims. This clarification is crucial, as distinguishing between leaked footage, stolen analytics, and malicious downloads helps in understanding the diverse security challenges faced by the company.

What You Should Do

  • Isolate Development Environments: Implement strict network segmentation to completely isolate pre-release development environments from production systems and general corporate networks.
  • Monitor Large Data Transfers: Deploy robust monitoring solutions to detect unusually large outbound data transfers, especially from development networks to unfamiliar external destinations. Lares suggests an automated quarantine threshold for transfers exceeding 50GB.
  • Strengthen Employee Authentication: Replace simple multi-factor authentication (MFA) approval prompts with phishing-resistant hardware security keys for employee accounts to prevent MFA fatigue attacks.
  • Secure Third-Party Access: For connected services and third-party integrations, ensure OAuth tokens are cryptographically bound to their authorized clients, have strictly limited access durations, and are regularly rotated. Monitor service-account login and query patterns for anomalies.
  • Audit Collaboration Tools: Actively monitor collaboration platforms like Slack and Confluence for excessive downloads, suspicious credential testing, and the unencrypted sharing of sensitive information such as API keys or server details.
  • Conduct Realistic Attack Simulations: Regularly perform red team exercises and penetration tests that simulate real-world attack scenarios, including identity abuse and supply chain compromises, to validate existing security defenses.
  • Continuous Verification of Trust: Adopt a “never trust, always verify” security posture. Do not assume that an authenticated account or a third-party integration is inherently secure; continuously assess and verify their access and activity.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachMalwarephishingSecurity

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Earth Sirrush Uses Notepad++ Plugins and Steganography for Espionage

Next Post

Critical Atlassian Jira RCE Exploit Released for CVE-2023-22524

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Citrix NetScaler CVE-2023-3519 Exploit Steals Config Data
October 8, 2026
Empire Market Co-Creator Sentenced to 40 Years for Drug and Hacking Crimes
October 8, 2026
GhostAction Supply Chain Campaign Steals CI/CD Credentials via GitHub Actions
October 8, 2026
Top Authors
David kimber
David kimber
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us