Rockstar Games confirmed that attackers accessed a limited amount of non-material internal company information through a third-party breach after the ShinyHunters group claimed it had infiltrated cloud-connected systems and demanded payment under a "pay or leak" ultimatum. Rockstar said the incident did not affect players or core operations, and reporting indicates the intrusion likely stemmed from compromised access tied to analytics vendor Anodot and Rockstar’s Snowflake-connected environment rather than a direct breach of Rockstar’s own infrastructure.
After Rockstar reportedly did not meet the ransom demand, ShinyHunters said it would publish the stolen data, and subsequent reports said 78.6 million records were released. Early assessments described the exposed material as internal corporate data such as contracts, financial documents, and marketing plans rather than player information, but the leak still created extortion, confidentiality, and supply-chain risk concerns for the game publisher as it prepares major releases including Grand Theft Auto VI.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
By April 14, reports indicated the attackers had published a large dataset they claimed was stolen from Rockstar, described in one report as 78.6 million records. The leak appeared to follow the previously announced extortion deadline.
Follow-up reporting said ShinyHunters planned to release the allegedly stolen Rockstar data after its ransom demands were not met. This marked an escalation from extortion threats to an announced intent to publish the material.
Early reporting indicated the intrusion may have stemmed from compromised authentication tokens tied to analytics vendor Anodot, which had integration with Rockstar systems, rather than a direct breach of Snowflake itself. This added technical detail reframed the incident as a third-party or supply-chain compromise.
Rockstar Games confirmed that unauthorized access occurred through a third-party data breach and said only a limited amount of non-material internal company information was accessed. The company stated the incident had no impact on its organization or players.
ShinyHunters publicly claimed it had accessed Rockstar Games data via a third-party/cloud environment and threatened to leak the stolen material unless a ransom was paid. Multiple reports say the group set a 'pay or leak' deadline of April 14, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
techradar.com
Open sourcekotaku.com
Open sourcethecyberexpress.com
Open sourcetheregister.com
Open sourceengadget.com
Open sourcepcgamer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.