Suspect a breach? Report it immediately — response within 1 hour.Report an incident

Rockstar Games and GTA VI: Two Leaks, Two Security Lessons (2022 and 2026)

A look back at the two major breaches that hit Rockstar Games — the 2022 intrusion linked to Lapsus$ and the 2026 hack claimed by ‘CyberLeek’ — and what they reveal about protecting development environments.

Published on August 26, 2026Étude de cas

Leak Context and Attack Vectors

In 2022, internal documents from Rockstar Games were leaked after an intrusion attributed to a group associated with Lapsus$. The attackers leveraged unrestricted access on messaging platforms such as Slack and Discord, combining social engineering with poor privilege management to exfiltrate confidential information related to GTA VI development.

2026: A Second Intrusion, Claimed by 'CyberLeek'

In August 2026, Rockstar Games confirmed a new network intrusion, separate from the 2022 episode. An actor operating under the name 'CyberLeek' released dozens of videos from development builds of GTA VI along with portions of the game's map, before the attacker's signature — a tag sprayed in-game using an in-world weapon — began circulating widely. Unlike 2022, this appears to have been a direct network intrusion rather than a takeover of Slack/Discord accounts, showing that very different attack vectors can target the same organization only a few years apart.

What the Response to Both Incidents Teaches

In both cases, Rockstar Games had to manage the crisis publicly, under intense media pressure. In 2026, the publisher pursued legal action to obtain from Microsoft and Discord the data tied to suspected accounts — a step that highlights how important it is, from the earliest phase of incident response, to precisely document the compromise channels and preserve digital evidence that can hold up in court. Whether an intrusion stems from hijacked internal accounts or direct network access, how fast an incident is scoped and which stakeholders are mobilized — legal, technical, communications — remain decisive.

Access Management and the Principle of Least Privilege

The main driver of the attack’s success was the lack of granular control over user accounts. Applying the principle of least privilege, regularly reviewing access rights, and enforcing multi‑factor authentication on collaborative tools can dramatically reduce the risk of escalation.

Securing Communication Platforms

Slack and Discord have become prime targets for data exfiltration. It is critical to configure retention policies, monitor file sharing, and enable alerts on abnormal behavior. Integrating an anomaly detection solution, such as the one offered by EBH Security, enhances visibility into suspicious activity.

Training and Awareness Against Social Engineering

Social engineering played a major role in the operation’s success. Training teams to recognize phishing attempts, unusual information requests, and to verify the identity of interlocutors reduces the attack surface. Regular simulations and awareness campaigns are effective levers for maintaining constant vigilance.

FAQ

How can a compromise on corporate messaging tools be detected?

Implement detailed logging, monitor for unusual logins, and use anomaly detection solutions that analyze account behavior in real time.

What role does least privilege play in preventing data leaks?

It limits access rights to only the resources needed, preventing a compromised account from reaching the entire system and mass‑exfiltrating information.

How can resilience against social engineering be strengthened?

Provide regular employee training, conduct phishing simulations, and establish identity‑verification procedures for any request for sensitive information.

Is the 2026 leak connected to the 2022 one?

No, they are two separate incidents. The 2022 leak was attributed to a group linked to Lapsus$ and relied on hijacked Slack/Discord access; the 2026 leak, claimed by 'CyberLeek', is described by Rockstar Games as a network intrusion.