Rockstar Games confirmed it was breached in an extortion campaign attributed to ShinyHunters, which claimed it had stolen confidential company data and threatened to publish it unless payment was made by April 14. Early reporting said the attackers may have reached Rockstar data through a third-party service, Anodot, with the compromise tied to Rockstar’s Snowflake environment rather than a direct intrusion into Rockstar’s own core systems.
Subsequent reporting said the attackers allegedly hijacked Anodot authentication tokens to access Rockstar’s Snowflake instance, stealing what Rockstar described as "non-material company information." Reports said the exposed data may include corporate documents such as GTA 6 marketing plans, while the game’s source code is not believed to be involved. Rockstar said the incident did not affect operations or players, and the case is being viewed as part of a broader pattern of ShinyHunters-linked compromises involving Snowflake environments connected through third-party integrations.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
BleepingComputer reported that ShinyHunters said it leaked more than 78.6 million records allegedly stolen from Rockstar Games, primarily internal analytics, support-related data, and operational metrics tied to online services. This appears to mark the public release of the data after the earlier extortion threat.
A Rockstar spokesperson acknowledged the incident and said the attackers obtained only 'non-material company information.' The company stated the breach did not affect operations or players.
ShinyHunters claimed responsibility for the intrusion and threatened to publicly leak the stolen Rockstar data unless payment was made. The extortion demand set an apparent deadline of April 14, 2026.
Reporting says attackers tied to ShinyHunters accessed Rockstar Games data by hijacking Anodot authentication tokens connected to Rockstar’s Snowflake environment, rather than directly breaching Rockstar systems or Snowflake itself. The exact scope of the stolen data was initially unclear, but reports suggested it involved corporate information rather than game source code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
17 references tracked. Mallory keeps watching after this page renders.
mitiga.io
Open sourcetechdirt.com
Open sourcehackread.com
Open sourcesecurityaffairs.com
Open sourcetomshardware.com
Open sourcekotaku.com
Open sourcethecybersecguru.com
Open sourcedexerto.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.