Rockstar Games
Incident posture
Linked entities
- Victim
- Rockstar Games
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A cybercriminal using the online persona "CyberLeek" published extensive pre-release gameplay footage and proprietary data of an unreleased major video game title, triggering one of the highest-profile data extortion incidents of the year. The leaked material included watermarked videos containing crypto wallet addresses and links to a memecoin, indicating the actor was pursuing financial gain despite framing the breach as hacktivism protesting the publisher's decision to not release physical copies. The parent company responded aggressively through legal action, petitioning a federal court for DMCA subpoenas against Discord, Google, Microsoft, and X to identify the perpetrators, with federal judges granting subpoenas against three of the four platforms. The breach is being investigated as a likely insider threat, given that the leaker appeared to have access to an actual game build, prompting broader concerns about the scope of the legal requests targeting identifying data for every member of three Discord servers.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In the days leading up to August 25, 2026, the video game publisher Rockstar Games, a subsidiary of Take-Two Interactive Software, became the target of a high-profile data extortion incident focused on unreleased material from Grand Theft Auto VI. An online persona operating under the name "CyberLeek" began publishing gameplay footage and other proprietary files related to the still-in-development game. The leaks appeared publicly approximately one week before Rockstar had planned an official reveal of core portions of the title. The content posted by CyberLeek indicated that either an external threat actor had gained direct access to Rockstar's most sensitive internal systems, or that proprietary data had been provided to the leaker by an insider with legitimate access to development builds. The incident quickly became one of the most widely covered data extortion events of the year, with stolen footage spreading rapidly across social media platforms, gaming news outlets, and file-hosting services. The leaked materials included watermarked gameplay videos that referenced cryptocurrency wallet addresses, suggesting that monetization was a primary objective alongside the stated political messaging.
CyberLeek framed the release of the stolen material as an act of hacktivism, publishing an anti-corporate manifesto that criticized Rockstar's decisions regarding digital pre-orders and disc-less releases. Despite this stated motive, the operational behavior of the leaker displayed clear patterns of financial exploitation. Beyond the watermarked buy links embedded in the footage, CyberLeek launched a cryptocurrency token associated with the leaks, offered to sell advertising space for future disclosures, and maintained accounts across multiple platforms where the stolen content and monetization links were hosted. The conflicting motivations drew attention from cybersecurity professionals, who noted that threat actors frequently combine political messaging with monetization schemes to maximize both audience engagement and revenue. The persona's activity also included the promotion of a memecoin tied to the leaked content, further indicating that financial gain was a central driver of the operation. Throughout the period during which the leaks spread, websites associated with CyberLeek, including those hosting the leaked information and links to the memecoin, went offline as of the Monday prior to the publication of reporting on the incident.
Take-Two Interactive Software, Rockstar's parent company, responded to the incident through aggressive legal action rather than public statements. The company petitioned a federal court for subpoenas under the Digital Millennium Copyright Act against Discord, Google, Microsoft, and X, seeking the identities of the operators behind CyberLeek as well as additional user accounts accused of copyright infringement. Federal judges granted the subpoenas targeting Discord, Microsoft, and X, while the petition directed at Google remained unapproved as of the reporting date. Take-Two's legal representatives also issued copyright notices to each of the four technology companies, informing them of the infringing material published on their platforms, though it was unclear at the time of reporting whether any of the companies had been formally served with the signed subpoenas. The scope of the subpoena issued to Discord was particularly broad, requesting identifying data on CyberLeek, two additional users, and every member of three Discord servers where copyrighted material had been posted. The requested information reportedly included Windows device identifiers, login records, and cloud storage contents for individuals who had spoken in those servers dating back to June.
Security researchers analyzing the incident drew comparisons between the GTA VI leaks and prior high-profile entertainment industry breaches, including the 2014 Sony Pictures attack, the 2017 HBO hack, and the Iranian theft of "Game of Thrones" episodes. The pattern of stealing proprietary content, publishing samples, promising additional disclosures, and applying sustained public pressure mirrored tactics commonly associated with ransomware and data extortion operations, though applied to intellectual property rather than personal data. Researchers also noted similarities to a previous security incident involving Rockstar in 2022, when an 18-year-old British man affiliated with the Lapsus$ cybercriminal group leaked gameplay footage, an event that reportedly cost Rockstar, Uber, and Nvidia a combined total exceeding $10 million. That earlier incident resulted in an indefinite hospital order for the convicted individual. In the current case, the nature of the leaked content — including references to development builds, watermarks consistent with internal production environments, and access patterns suggesting familiarity with Rockstar's workflows — led several analysts to characterize the event as a likely insider threat exploitation. Possible vectors identified included an insider saving a copy of the game build to a cloud service, uploading it to a file-hosting platform, or removing it from company facilities using an external storage device.
The financial and reputational stakes for Take-Two and Rockstar were magnified by the cultural significance of the Grand Theft Auto franchise. Grand Theft Auto V and its online component had sold more than 230 million copies and generated over $11 billion in revenue since the game's release in 2013. Industry analysts projected that Grand Theft Auto VI was positioned to generate between $3.3 billion and $5.2 billion in cumulative global sales by the end of its launch week in November 2026. While no customer data or critical infrastructure was reported to be at risk, the exposure of pre-release creative and technical material represented a direct threat to the company's competitive positioning and the carefully managed rollout of one of the most anticipated entertainment releases in recent memory. The incident also produced ripple effects across the cybersecurity industry, drawing coverage from outlets and researchers who would not typically report on gaming-related security matters. Throughout the eight days during which leaks continued to surface, Take-Two maintained its legal posture without issuing public statements on the underlying breach, and Discord declined to confirm whether it had been formally served with the subpoena or to describe any actions taken in response. The leaker's monetization infrastructure, including the associated websites and memecoin channels, went offline as legal pressure increased, though the broader investigation into the source of the breach remained ongoing at the time of the available reporting.
Sources
Sources available to members: 1 source.