Rockstar Games has been hit by several separate intrusions over four years. These were distinct attacks, not one breach that took everything at once. Together they have exposed proprietary source code, development footage, internal business and player-spending data, and what researchers describe as a playable Grand Theft Auto VI development build. In a September 1 analysis, security firm Lares links three incidents: the 2022 Lapsus$ intrusion, an April 2026 ShinyHunters compromise of Rockstar data held in Snowflake, and an August 2026 "Cyberleek" exfiltration of a playable build. Lares and Mitiga put the April data theft at 78.6 million records. Rockstar's own public statement on that incident said only that "a limited amount of non-material company information" was accessed through a third party. That gap has not been resolved. Separately, Dutch police have arrested a 24-year-old Amsterdam man whom the FBI calls "one of the alleged leaders" of ShinyHunters. A further ShinyHunters claim from late September, involving roughly 8.1GB of data including anti-cheat code, remains unverified.
What Happened
None of the eight sources behind this brief is a primary disclosure from Rockstar, a regulator or a CERT. Everything below is reported or assessed by researchers and the press, and is attributed accordingly.
September 2022 (Lapsus$). Lares and GBHackers (via ZeroHour) report that an attacker linked to Lapsus$ got in using valid corporate credentials. The attacker then sent repeated MFA push prompts until an employee approved one. Once inside, they searched Slack and Atlassian Confluence for secrets. They took about 90 GTA VI development videos and proprietary source code.
April 2026 (ShinyHunters). Mitiga reports that ShinyHunters first compromised Anodot, a SaaS analytics provider with authenticated access to customer Snowflake environments. The group stole service account tokens and used them to pull Rockstar data. Mitiga says the attack went from initial access to public data release in under two weeks. Kotaku reports that ShinyHunters tried to extort Rockstar, Rockstar did not pay, and the data was then leaked. Several outlets say the leak included non-public GTA Online financial data, including apparent weekly revenue. At the time, Rockstar said: "We can confirm that a limited amount of non-material company information was accessed in connection with a third-party data breach. This incident has no impact on our organization or our players."
August 2026 (Cyberleek). Lares describes a separate exfiltration of a playable GTA VI development build and attributes it to poorly segmented development pipelines. GamesRadar refers to "the Cyberleek leaks that emerged last month" and says they are distinct from the April incident. The sources available here include no public Rockstar statement on Cyberleek.
September 2026 (unverified ShinyHunters claim). Tech-Insider, citing Security Affairs, reports that ShinyHunters posted a claim on its leak site on September 21. The group says it breached Rockstar again and published about 8.1GB of anti-cheat components, internal game data and analytics records. Tech-Insider notes that independent verification is limited and that Rockstar had not confirmed the scope or authenticity of the material. This brief treats the claim as unconfirmed.
The arrest. Dutch police arrested a 24-year-old Amsterdam man on September 15 on suspicion of involvement in ShinyHunters. Kotaku dates the police announcement to September 28 and GTA BOOM to September 29. Kotaku, citing Reuters, reports that the man is Pepijn van der Stap, a security professional who had claimed to be reformed. The FBI alleges he has been one of the group's leaders since 2025. FBI cyber division assistant director Brett Leatherman said the suspect and his co-conspirators allegedly breached "more than 140 organizations" and collected at least $70 million in extortion payments. Kotaku instead describes the group's victims as "over 100 businesses and organizations." GTA BOOM reports that a Rotterdam court ordered another 90 days of pretrial custody. The sources do not establish whether this individual personally took part in the Rockstar intrusion. Kotaku says only that the FBI considers it likely.
What Was Taken
- 2022: About 90 GTA VI development videos and proprietary source code (Lares, GBHackers).
- April 2026: 78.6 million records from Rockstar's Snowflake environment, per Lares and Mitiga. Mitiga describes them as including financial data and player-spending metrics. GBHackers frames the 78.6 million figure as ShinyHunters' claim. Rockstar called the exposed data "limited" and "non-material" and said players were unaffected. No source reconciles the attacker's figure with Rockstar's description, so readers should treat 78.6 million as a claimed and researcher-reported number, not one Rockstar has confirmed.
- August 2026: A playable GTA VI development build, as reported by Lares and summarised by Cyber Security News.
- September 2026 (claimed, unverified): About 8.1GB including anti-cheat source code, game data and analytics, according to a ShinyHunters leak-site post reported by Security Affairs and Tech-Insider.
Lares also flags a secondary threat to players. Malware is circulating as a 113GB "GTA VI build", padded with filler to hide a 50KB malicious payload. Interest in leaked, unreleased games is being used to infect consumers.
Note: CVE-2023-24059, a GTA V for PC flaw exploited in January 2023, is sometimes grouped with these events. GBHackers says it is a separate issue and not part of these identity-based intrusions.
Why It Matters
Lares sums up the pattern: "Attackers do not hack in; they log in." None of the reported intrusions relied on a perimeter exploit or a zero-day. Mitiga stresses that no Snowflake vulnerability was involved. Every reported entry point was a trusted identity: an employee's credentials, an approved MFA prompt, or a vendor's service token.
For defenders, three lessons stand out:
- Third-party SaaS integrations are now a main attack path. One compromised analytics vendor reportedly gave access to downstream customer data warehouses, and the activity looked like normal service-account traffic.
- Collaboration platforms hold credentials. Plaintext secrets in Slack and Confluence turned one compromised account into broad access in 2022.
- Development environments need the same protection as production. A playable pre-release build is a high-value asset. Lares ties its theft to weak segmentation.
The anti-cheat claim, if verified, would cause lasting operational damage. Anti-cheat logic only works while it stays hidden, and Tech-Insider notes that GTA VI is due on November 19, 2026. The arrest and the FBI's attribution of 140+ victims show that ShinyHunters is running a large extortion operation across many sectors, not just gaming.
The Attack Technique
Lares and GBHackers map the reported activity to these MITRE ATT&CK techniques:
- T1078 Valid Accounts: stolen employee credentials (2022) and vendor service identities (2026).
- T1621 MFA Request Generation: push-notification fatigue until an employee approved a prompt (2022).
- T1213 Data from Information Repositories: searching Slack and Confluence for keys, credentials and server details (2022).
- T1199 Trusted Relationship / T1528 Steal Application Access Token: compromising Anodot and using its Snowflake-connected tokens (April 2026). Lares describes these as long-lived OAuth bearer tokens. GBHackers notes that Lares presents parts of this chain as assessment, not confirmed fact.
Mitiga notes that because the attackers authenticated as legitimate service accounts, detection built to catch unauthorised login attempts would not have triggered. Lares attributes the August build theft to unsegmented development pipelines. The sources available here do not describe the exact initial access vector for Cyberleek.
What Organizations Should Do
- Replace push-approval MFA with phishing-resistant factors. Use FIDO2/WebAuthn or number-matching at minimum, and alert on repeated denied or unanswered prompts for the same user.
- Inventory and constrain third-party tokens. List every SaaS integration that has access to your data warehouses, including Snowflake, BigQuery and Databricks. Enforce least privilege, short token lifetimes, IP allow-listing and regular rotation, and revoke unused integrations.
- Monitor service accounts as closely as human users. Baseline query volume, timing and source IP for each integration identity. Alert on bulk exports or new query patterns, and keep warehouse access logs long enough to investigate.
- Scan collaboration tools for secrets. Run automated secret detection and DLP across Slack, Confluence, Jira and wikis. Rotate anything found and move secrets into a managed vault.
- Segment build and development environments. Treat pre-release builds and source repositories as crown-jewel assets. Place them behind separate identity boundaries with just-in-time access and egress monitoring for large transfers.
- Plan for extortion and leak-lure fallout. Prepare a response playbook for leak-site claims, and warn users and staff that "leaked build" downloads are a common malware delivery method.
Sources: Hackers Steal Rockstar Source Code, 78.6 Million Records and Playab... | Police arrest "one of the alleged leaders" of group behind Rockstar... | Technical Analysis of the Rockstar Games Compromises: Exploit Chain... | Alleged Rockstar Games Hacker Arrested In Connection With Data Brea... | ShinyHunters & Rockstar: Snowflake Data Breach Leads to ... | Rockstar Games Attacks Expose MFA Fatigue, OAuth Token Theft and De... | Dutch Police Arrest Alleged ShinyHunters Leader Linked to Rockstar... | ShinyHunters Breach Rockstar Again, Leak 8.1GB 2026