Hackers Steal Rockstar Source Code, 78.6 Million Records and Playable GTA VI Build

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Rockstar Games has faced separate intrusions involving proprietary source code, 78.6 million business records, and what researchers describe as a playable GTA VI development build.

The incidents span several years, rather than one attack that stole everything together. The reported entry points include stolen employee credentials, repeated authentication prompts, and compromised access tokens belonging to an outside service provider.

Alongside these breaches, supposed leaked game downloads have created another route for criminals to infect players’ computers.

After reviewing the incidents, Lares researchers noted malware masquerading as a 113GB GTA VI build, with padded files concealing a 50KB malicious payload. Related fake game download attacks illustrate how interest in unreleased games can expose users to infections.

The attacks reveal weaknesses in how trusted accounts, connected services, and development systems are protected, Lares said in a report shared with Cyber Security News (CSN).

Its September 1 analysis links the incidents to identity abuse and inadequate separation of sensitive environments.

Playable GTA VI Build

In September 2022, Lapsus$ obtained approximately 90 development videos and proprietary source code, according to Lares.

The report describes an attacker using legitimate corporate credentials and repeatedly sending authentication requests until an employee approved one, allowing access.

Once inside, the attacker searched Slack and Atlassian Confluence for credentials, application keys, and internal server details that developers had shared in plain text.

These collaboration platforms became stepping stones toward more sensitive resources rather than remaining isolated communication tools. The case highlights why controlling access matters alongside securing software.

Earlier reporting on Lapsus recruiting company insiders documented attempts to obtain employee access, although Lares attributes the Rockstar intrusion described here to credential abuse and repeated approval requests.

A separate April 2026 incident involved ShinyHunters and the theft of 78.6 million records. Lares says attackers first compromised analytics provider Anodot, obtained its customers’ long-lived OAuth tokens, and used them to access Rockstar’s Snowflake data warehouse.

These tokens functioned as reusable access passes. Because possession was sufficient for authentication, and they were not tied to the provider’s infrastructure, attackers could reuse them from their own systems without first compromising a Rockstar employee account.

Reporting on Rockstar analytics data theft distinguishes those records from the earlier source code loss. The April dataset concerned business analytics, and the coverage stated that player passwords, payment information, source code, and GTA VI development assets were not included.

Build Security

Lares places the Cyberleek incident in August 2026, stating that domains were registered on August 14 and material began appearing on August 18. It reports at least 13 gameplay videos and mapping information covering the fictional Leonida setting.

The researchers describe the footage as evidence of an unfinished playable development build. However, their explanation leaves multiple possibilities for how it ran: bypassed authentication checks, locally compiled stolen source code, or access to a modified development kit.

Cyberleek also tied disclosures to cryptocurrency purchases that influenced which material appeared next, according to the report.

Take-Two Interactive responded with copyright takedowns and legal subpoenas seeking identifying information from Microsoft, Discord, and X about those distributing stolen content.

Lares rejects rumors of a separate Rockstar India breach, saying forensic evidence does not substantiate them. That distinction matters because leaked footage, stolen analytics, and malicious downloads represent distinctly different security issues.

Lares recommends isolating prerelease development environments and monitoring unusually large outbound transfers.

Its proposed detection threshold would automatically quarantine development networks when transfers exceed 50GB to unfamiliar external addresses, limiting further data movement while defenders investigate the activity.

For employee accounts, the report recommends phishing-resistant hardware authentication keys instead of simple approval prompts.

For connected services, it calls for cryptographically binding tokens to their authorized clients, restricting access duration, and watching service-account login and query patterns.

The researchers also recommend monitoring collaboration tools for excessive downloads and suspicious credential testing, then validating defenses through realistic attack exercises.

The broader lesson is to verify trusted access continuously rather than assuming an authenticated account or integration is automatically safe.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Hackers Steal Rockstar Source Code, 78.6 Million Records and Playable GTA VI Build appeared first on Cyber Security News.