A look back at the two major breaches that hit Rockstar Games — the 2022 intrusion linked to Lapsus$ and the 2026 hack claimed by ‘CyberLeek’ — and what they reveal about protecting development environments.
Published on August 26, 2026 — Étude de cas
In 2022, internal documents from Rockstar Games were leaked after an intrusion attributed to a group associated with Lapsus$. The attackers leveraged unrestricted access on messaging platforms such as Slack and Discord, combining social engineering with poor privilege management to exfiltrate confidential information related to GTA VI development.
In August 2026, Rockstar Games confirmed a new network intrusion, separate from the 2022 episode. An actor operating under the name 'CyberLeek' released dozens of videos from development builds of GTA VI along with portions of the game's map, before the attacker's signature — a tag sprayed in-game using an in-world weapon — began circulating widely. Unlike 2022, this appears to have been a direct network intrusion rather than a takeover of Slack/Discord accounts, showing that very different attack vectors can target the same organization only a few years apart.
In both cases, Rockstar Games had to manage the crisis publicly, under intense media pressure. In 2026, the publisher pursued legal action to obtain from Microsoft and Discord the data tied to suspected accounts — a step that highlights how important it is, from the earliest phase of incident response, to precisely document the compromise channels and preserve digital evidence that can hold up in court. Whether an intrusion stems from hijacked internal accounts or direct network access, how fast an incident is scoped and which stakeholders are mobilized — legal, technical, communications — remain decisive.
The main driver of the attack’s success was the lack of granular control over user accounts. Applying the principle of least privilege, regularly reviewing access rights, and enforcing multi‑factor authentication on collaborative tools can dramatically reduce the risk of escalation.
Slack and Discord have become prime targets for data exfiltration. It is critical to configure retention policies, monitor file sharing, and enable alerts on abnormal behavior. Integrating an anomaly detection solution, such as the one offered by EBH Security, enhances visibility into suspicious activity.
Social engineering played a major role in the operation’s success. Training teams to recognize phishing attempts, unusual information requests, and to verify the identity of interlocutors reduces the attack surface. Regular simulations and awareness campaigns are effective levers for maintaining constant vigilance.
Implement detailed logging, monitor for unusual logins, and use anomaly detection solutions that analyze account behavior in real time.
It limits access rights to only the resources needed, preventing a compromised account from reaching the entire system and mass‑exfiltrating information.
Provide regular employee training, conduct phishing simulations, and establish identity‑verification procedures for any request for sensitive information.
No, they are two separate incidents. The 2022 leak was attributed to a group linked to Lapsus$ and relied on hijacked Slack/Discord access; the 2026 leak, claimed by 'CyberLeek', is described by Rockstar Games as a network intrusion.