VYPR
breachPublished Oct 7, 2026· 1 source

Rockstar Games Hit by Multiple Breaches: Source Code, 78.6 Million Records, and GTA VI Build Stolen

Rockstar Games has been the target of several sophisticated cyberattacks, resulting in the theft of source code, a massive dataset of business records, and a playable build of Grand Theft Auto VI.

Rockstar Games has recently been subjected to a series of significant cyber intrusions, leading to the compromise of its proprietary source code, the exfiltration of approximately 78.6 million business records, and the theft of a playable development build of the highly anticipated Grand Theft Auto VI. These incidents, spanning several years, highlight a concerning pattern of sophisticated attack vectors, including the abuse of stolen employee credentials, relentless multi-factor authentication (MFA) prompt fatigue, and the exploitation of compromised third-party OAuth tokens.

The first major breach, reported in September 2022, saw the Lapsus$ hacking group gain access to Rockstar's systems. Researchers from Lares noted that the attackers utilized legitimate corporate credentials and employed a tactic of repeatedly sending authentication requests until an employee inadvertently approved one. Once inside the network, the threat actors were able to access sensitive information by searching collaboration platforms like Slack and Atlassian Confluence for credentials, application keys, and internal server details that had been inadvertently shared in plain text. This incident underscored the risks associated with inadequate access controls and the potential for collaboration tools to become attack vectors.

A separate incident in April 2026, attributed to the ShinyHunters group, resulted in the theft of 78.6 million business records. The attackers reportedly compromised Anodot, an analytics provider used by Rockstar. By obtaining Anodot's long-lived OAuth tokens, the threat actors were able to bypass Rockstar's security measures and directly access the company's Snowflake data warehouse. These tokens acted as reusable access passes, allowing the attackers to authenticate from their own systems without needing to compromise individual Rockstar employee accounts, demonstrating a critical vulnerability in how third-party service access is managed.

More recently, in August 2026, a group identified as Cyberleek was linked to the leak of gameplay footage and mapping information related to Grand Theft Auto VI. Researchers described this material as originating from an unfinished, playable development build. The exact method of access remains under investigation, with possibilities including bypassed authentication checks, locally compiled stolen source code, or access to a modified development kit. Cyberleek also reportedly tied the disclosures to cryptocurrency transactions, influencing the subsequent release of stolen materials.

Adding to the threat landscape, a separate attack involved malware disguised as a large download for the GTA VI build. Researchers at Lares identified that malicious actors were distributing a 113GB file, which, upon closer inspection, contained a small 50KB malicious payload hidden within padded files. This tactic exploits the intense public interest in unreleased games to trick users into downloading and executing malware, leading to potential infections on their computers.

In response to these incidents, Take-Two Interactive, Rockstar's parent company, has initiated copyright takedown procedures and issued legal subpoenas to platforms like Microsoft, Discord, and X to identify those distributing the stolen content. Lares researchers have also dismissed rumors of a separate breach at Rockstar India, stating that forensic evidence does not support such claims.

Lares has provided several recommendations to prevent similar incidents. For development environments, they suggest isolating prerelease systems and implementing monitoring for unusually large outbound data transfers, potentially quarantining networks if transfers exceed 50GB to unfamiliar external addresses. For employee accounts, the adoption of phishing-resistant hardware authentication keys over simple approval prompts is advised. Regarding connected services, recommendations include cryptographically binding tokens to authorized clients, limiting token access duration, and closely monitoring service account login and query patterns. Furthermore, monitoring collaboration tools for excessive downloads and suspicious credential testing, coupled with regular, realistic attack exercises, is crucial for validating defenses.

The series of breaches against Rockstar Games serves as a stark reminder of the multifaceted threats facing large organizations. The attacks highlight the critical need for robust security measures that address not only direct network intrusions but also the vulnerabilities introduced through third-party integrations, employee credentials, and the exploitation of public interest. Continuous verification of trusted access, rather than assumptions of inherent safety, is paramount in today's evolving threat landscape.

Synthesized by Vypr AI