Skip to main content

Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day

0
Critical
Published: 10/06/2026 (10/06/2026, 19:55:08 UTC)
Source: Reddit NetSec

Description

Rockstar Games has suffered multiple confirmed security compromises from 2018 through 2026, involving diverse attack vectors rather than zero-day exploits. These include MFA fatigue attacks, exploitation of hardcoded credentials in collaboration tools, stolen OAuth tokens from third-party SaaS vendors, and reverse-engineered P2P network vulnerabilities leading to remote code execution. The most severe incident in August 2026 involved exfiltration of a playable GTA VI development build and extensive gameplay data due to failures in internal segmentation and data loss prevention. The attacks highlight systemic weaknesses in identity management, token security, and internal network controls.

Reddit Discussion

r/netsec·posted by u/lares-hacks
00

Four incidents, four completely different initial access paths:

  • 2022, Lapsus$: MFA fatigue against an employee, then hardcoded creds and API keys sitting in plaintext in Slack and Confluence.
  • Early 2023, GTA Online: P2P netcode on PC reverse-engineered into RCE via malicious packets. The fix was kernel-level BattlEye.
  • April 2026, ShinyHunters: no human identity involved. Long-lived OAuth tokens stolen from a third-party SaaS vendor and replayed straight into Rockstar's Snowflake. Bearer tokens confer authority by possession alone.
  • August 2026, Cyberleek: exfiltration of a playable GTA VI dev build, 13+ gameplay videos and full map data. That volume of egress from a dev subnet without tripping alarms is a DLP and segmentation failure.

The writeup reconstructs each attack chain with MITRE mappings and detection strategies: egress baselining on dev subnets, Slack audit-log heuristics, and behavioral baselines for non-human identities in Snowflake.

Full breakdown: https://www.lares.com/blog/rockstar-games-attacks/

Question for the defenders here: which of these four would be hardest to catch in your environment? The OAuth token replay is arguably the nastiest of the bunch. No user to phish-train, no endpoint alert to fire.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/06/2026, 20:18:21 UTC

Technical Analysis

Between 2018 and 2026, Rockstar Games experienced four distinct confirmed compromises: (1) In 2022, the Lapsus$ group used MFA fatigue and plaintext credentials in Slack and Confluence to exfiltrate source code. (2) In early 2023, GTA Online's PC P2P netcode was reverse-engineered to achieve remote code execution, remediated by deploying kernel-level BattlEye. (3) In April 2026, ShinyHunters stole long-lived OAuth bearer tokens from a third-party SaaS vendor (Anodot) and used them to query Rockstar's Snowflake data warehouse without human involvement. (4) In August 2026, the Cyberleek group exfiltrated a playable GTA VI dev build and related data by exploiting unsegmented development environments and insufficient egress monitoring. These incidents demonstrate failures in zero-trust architecture, token proof-of-possession, DLP, and internal network segmentation. The analysis includes MITRE ATT&CK mappings and detection strategies such as behavioral baselining and Slack audit heuristics.

Potential Impact

The compromises resulted in significant intellectual property theft, including source code, development videos, and a playable GTA VI build. The breaches exposed sensitive internal data and enabled extortion attempts leveraging stolen assets. The OAuth token theft allowed unauthorized data access without user interaction. The P2P vulnerability enabled remote code execution on client machines. The Cyberleek incident revealed critical failures in internal segmentation and data loss prevention, allowing large-scale data exfiltration without triggering alarms. These breaches undermine Rockstar's operational security and expose it to financial and reputational damage.

Defensive Guidance

Rockstar and its parent company have taken remediation steps including deploying kernel-level anti-cheat protections (BattlEye) for the P2P vulnerability, initiating DMCA takedowns, and pursuing legal actions against threat actors. Recommended mitigations include eliminating push-notification MFA in favor of phishing-resistant methods such as FIDO2 hardware keys, enforcing Demonstrating Proof-of-Possession (DPoP) on all API tokens to prevent token replay, isolating pre-release build infrastructure with strict segmentation, and replacing static audits with continuous Purple Teaming exercises. Monitoring strategies include egress baselining on development subnets, Slack audit log heuristics, and behavioral baselines for non-human identities in cloud data platforms. No zero-day vulnerabilities were involved, so patching focuses on architectural and process improvements.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
netsec
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":43,"reasons":["external_link","newsworthy_keywords:zero-day,compromised","urgent_news_indicators","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["zero-day","compromised"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6ac557852cdf04f656db7536

Added to database: 10/06/2026, 20:18:13 UTC

Last enriched: 10/06/2026, 20:18:21 UTC

Last updated: 10/07/2026, 03:18:09 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses