The analysis by security consultancy Lares reconstructs incidents spanning the 2022 Grand Theft Auto VI leak, an April 2026 third-party breach and the unauthorised release of GTA VI material in August. Its detailed attack-chain findings, however, go beyond what Rockstar or parent Take-Two Interactive has publicly confirmed, making an important distinction between established events and technical assessments.
Take-Two has formally acknowledged the September 2022 intrusion. Regulatory filings say an unauthorised third party accessed and downloaded confidential information from Rockstar systems, including early development footage for the next Grand Theft Auto. About 90 development videos appeared online.
Rockstar said at the time that its services were unaffected and development would continue as planned. Take-Two later repeated in regulatory disclosures that the intrusion had not materially affected the company.
Lares attributes the initial access to MFA fatigue, in which repeated authentication prompts are used to induce a user to approve a fraudulent login. It further assesses that the attacker moved through collaboration systems, including Slack and Confluence, to locate credentials and internal information. Those specific mechanics have not been publicly established by Rockstar’s forensic disclosures.
The distinction matters because another breach in April 2026 was confirmed by Rockstar only at a broader level. The company said a limited amount of non-material company information was accessed in connection with a third-party data breach and that neither its organisation nor players were affected.
ShinyHunters claimed responsibility, saying it had reached Rockstar-related Snowflake data through cloud analytics provider Anodot. The group threatened to leak information unless Rockstar engaged with it. Public reporting on the incident showed the compromised material was associated with company metrics rather than player information or GTA VI assets.
Lares’ reconstruction says attackers obtained long-lived OAuth bearer tokens from the third-party service and replayed them against Rockstar’s Snowflake environment. It characterises this as a machine-identity failure: possession of a valid bearer token can provide access without a password prompt or direct compromise of an employee.
Rockstar has not publicly confirmed that token theft was the precise access mechanism, nor Lares’ claim that 78.6 million records were queried. Those details therefore remain the consultancy’s assessment rather than independently established forensic findings.
The analysis recommends cryptographically binding sensitive API credentials to authorised clients, shortening token lifetimes and monitoring service accounts for abnormal behaviour. It also argues that phishing-resistant authentication, including FIDO2-based security keys, can reduce exposure to push-notification abuse.
A separate wave of unauthorised GTA VI material appeared online in August 2026. Multiple gameplay clips and map images circulated under the Cyberleek name. Lares concludes that the volume and nature of the material indicate inadequate segmentation and outbound data-loss controls around development systems.
That conclusion is also inferential. Publicly visible leaks establish that development material was distributed, but they do not by themselves prove how it was obtained, whether an entire playable build was exfiltrated, or which internal security controls failed. Lares itself reconstructs possible paths from the characteristics of the leaked material.
The episodes nevertheless illustrate a wider security problem: enterprise access increasingly depends on identities and trusted software relationships extending beyond traditional network boundaries. An attacker using legitimate credentials or tokens may appear to internal systems as an authorised user or service until behavioural monitoring detects an anomaly.
Take-Two’s annual filings identify cyberattacks against source code, game assets and confidential information as continuing business risks. The company says theft or unauthorised publication of trade secrets could damage its competitive position, reputation and future sales, while sophisticated attacks may remain undetected for prolonged periods.
Follow Arabian Post
Select Arabian Post as your preferred source on Google and MSN News for trusted business news and Arab politics and updates.