ThreatPaperBeta
Data BreachExtortion & BlackmailHigh

Rockstar Games Cyber Intrusions and GTA 6 Data Leaks (2022–2026)

By Sethu Satheesh · 23 Aug 2026 · 11 min read

Threat Actor: Lapsus$ (Arion Kurtaj) / CyberLeek · Target: Rockstar Games, Take-Two Interactive

Source: mashable.com


Executive Summary

This incident report analyzes a series of severe cyber intrusions and subsequent data extortion campaigns targeting Rockstar Games and its parent company, Take-Two Interactive Software Inc., spanning from September 2022 to August 2026. The operational disruption stems from two separate breaches executed by entirely disparate threat actors utilizing different methodologies and monetization strategies.

The first incident occurred in September 2022 when an 18-year-old threat actor named Arion Kurtaj, affiliated with the Lapsus$ extortion group, breached Rockstar Games' internal networks. Kurtaj utilized social engineering and Multi-Factor Authentication (MFA) fatigue to bypass perimeter controls, eventually exfiltrating 90 pre-alpha gameplay videos of Grand Theft Auto VI (GTA 6) and raw source code for both GTA 5 and GTA 6 via the company's internal Slack channels. Following failed extortion demands, the stolen data was leaked publicly, resulting in severe operational disruption and the subsequent arrest and indefinite hospital sentencing of the threat actor.

In August 2026, a secondary campaign orchestrated by an unverified persona known as "CyberLeek" released a new wave of unreleased GTA 6 media, including gameplay mechanics, geographic map data, and evidence of a compiled playable build. Unlike the 2022 intrusion, CyberLeek monetized the breach through cryptocurrency manipulation, framing the leaks as a consumer-rights protest while simultaneously orchestrating a massive pump-and-dump scheme via a Solana-based memecoin ($CYBERLEEK). The immense public interest in the 2026 leaks also spawned a secondary economy of threat actors deploying fake leak websites to distribute Vidar infostealers and ClickFix malware to unsuspecting users.

Verification of Claims

  1. Claim: The CyberLeek initial access vector involved a theft executed around April 2026 connected to a European bank account. → Unverified → Claimed by an OSINT investigator named "KINGJulien," but no technical evidence or official confirmation from Rockstar Games corroborates how the network was breached.

  2. Claim: CyberLeek possessed a "dead man's switch" designed to automatically distribute a fully compiled, playable PC build of GTA 6. → Unverified / Fabricated → Gaming publication Insider Gaming issued a formal retraction confirming that the dead man's switch imagery and claims were manufactured by online copycats and impersonators attempting to farm engagement.

  3. Claim: The 2026 leaks originated from an actively playable, compiled build of the game. → Partially verified → Footage demonstrating customized in-game actions (e.g., shooting the word "LEEK" into a wall using bullet holes) heavily implies an active build, and media analysts noted mechanics consistent with advanced development, though Rockstar has not officially confirmed the file authenticity.

Timeline

Date Actor Event Source
Dec 10, 2021 Lapsus$ Threat group becomes active, executing data extortion breaches without ransomware encryption payloads. MITRE Threat Intel
Sep 15, 2022 Arion Kurtaj Kurtaj breaches Uber using an Amazon Fire TV stick, smartphone, and hotel television while on bail. Phoenix Security Incident Review
Sep 18-19, 2022 Arion Kurtaj Kurtaj breaches Rockstar Games, gaining access to internal Slack, and posts 90 pre-alpha GTA 6 videos to GTAForums. Bitdefender / ASIS Report
Sep 22, 2022 Arion Kurtaj The City of London Police arrest Kurtaj for a third time. City of London Police Notice
Dec 21, 2023 UK Court System Kurtaj is sentenced to an indefinite hospital order for his role in the Lapsus$ hacks. UK Crown Court Sentencing
Aug 14, 2026 CyberLeek An Arweave decentralized domain name matching the CyberLeek branding is registered on the blockchain. Blockchain Registry Logs
Aug 15, 2026 CyberLeek The Solana token $CYBERLEEK is launched on a Raydium pool. Raydium DEX Telemetry
Aug 18, 2026 CyberLeek First wave of GTA 6 gameplay footage and map images begins circulating online, watermarked with crypto QR codes. Mashable / PC Gamer
Aug 19, 2026 Take-Two IP Take-Two Interactive sends a formal DMCA takedown notice to GitHub regarding the repository zyrexdz/cyberleek-leak-research. GitHub DMCA Repository
Aug 20, 2026 Take-Two Legal Take-Two files DMCA subpoenas in the SDNY demanding identifying user telemetry from Microsoft and Discord. SDNY Court Records
Aug 21, 2026 CyberLeek CYBERLEEK token hits a fully diluted valuation of $3.3 million; fake lure domains hosting Vidar infostealer malware emerge. Security Research Telemetry
Aug 24, 2026 LBank Exchange The CYBERLEEK memecoin is officially listed on the centralized exchange LBank at 10:10 UTC. LBank Exchange Notice

Attack Anatomy

  • Initial Access: In 2022, the Lapsus$ operator purchased compromised session cookies, authentication tokens, and credentials from dark web marketplaces that had been previously harvested by infostealers like Redline.

  • Execution: The operator deployed MFA Fatigue, flooding the targeted contractor with two-factor authentication push requests, and contacted the victim via WhatsApp or SMS impersonating corporate IT support to persuade them to accept the prompt.

  • Privilege Escalation: Once inside the network, the actor initiated scanning and located a misconfigured network share containing PowerShell scripts with hardcoded credentials for a Thycotic Privileged Access Management (PAM) platform, subsequently extracting secrets for Domain Admin, Duo, OneLogin, AWS, and G-Suite.

  • Exfiltration: The actor pivoted to the corporate Slack workspace to download proprietary pre-alpha MP4 video files and source code archives, leveraging the internal communication tool to announce the hack and demand extortion.

  • Impact: 90 video clips and fragments of source code were leaked publicly after extortion demands were ignored. (Note: The exact access and exfiltration methodologies for the 2026 CyberLeek intrusion remain under active investigation).

Loading diagram...

Threat Actor Profile

  • Name / Alias: Lapsus$ (DEV-0537 / G1004) / Arion Kurtaj; CyberLeek
  • Attribution Confidence: High for Lapsus$ (confirmed via UK court conviction); Low for CyberLeek (unverified anonymous persona)
  • Motivation: Financial (Extortion for Lapsus$; Cryptocurrency pump-and-dump for CyberLeek)
  • Sophistication Level: Moderate — Lapsus$ utilized highly effective social engineering and credential theft; secondary malware operators related to the 2026 leaks demonstrated advanced evasion techniques including dynamic API resolution and App-Bound Encryption bypass
  • Known Previous Operations: Lapsus$ previously breached Uber, Nvidia, Samsung, Mercado Libre, Ubisoft, Globant, T-Mobile, Okta, and Microsoft. No publicly documented prior operations linked to CyberLeek before August 2026.
  • Nation-State Nexus: No — Both events are strictly linked to financially motivated cybercriminal collectives
  • MITRE ATT&CK Techniques:
    • T1586.002 — Compromise Accounts: Email Accounts
    • T1078.004 — Valid Accounts: Cloud Accounts
    • T1204 — User Execution
    • T1136.003 — Create Account: Cloud Account
    • T1068 — Exploitation for Privilege Escalation
    • T1621 — Multi-Factor Authentication Request Generation (MFA Fatigue)
    • T1562.001 — Impair Defenses: Disable or Modify Tools
    • T1003.003 — OS Credential Dumping: NTDS
    • T1555.003 — Credentials from Password Stores: Web Browsers
    • T1069.002 — Permission Groups Discovery: Domain Groups
    • T1213.001 — Data from Information Repositories: Confluence
    • T1114.003 — Email Collection: Email Forwarding Rule
    • T1485 — Data Destruction
    • T1489 — Service Stop
    • T1584.002 — Compromise Infrastructure: DNS Server
    • T1567.002 — Exfiltration to Cloud Storage
  • Operational Security (OpSec): Secondary malware operators capitalizing on the 2026 leak exhibited poor OpSec by leaving a staging environment data.txt file on the web root, exposing their proxy/backconnect node and usage of regional slang.

Technical Indicators

domains:
  - "gta-six-leaks[.]com"
  - "rockstar-gta-6[.]com"
ip_addresses:
  - "45.237.85[.]49"
file_hashes:
  - type: "sha256"
    value: "a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0"
    description: "gta6_installer.exe (Vidar infostealer payload)"
urls:
  - "hxxps://www.pinterest[.]com/m1duus"
c2_infrastructure:
  - "Proxy/backconnect staging node at 45.237.85[.]49:9104"
  - "CYBERLEEK Solana mint: ApZuxdpzMrbEYTGEzeY9afh5pj9d6qPRJCTgQYiipbKg"
  - "Discord handles: CYBERLEEK, CINEMATICROCKSTAR, Surfer24k, cyberleek_west, surwest"
  - "Discord servers: Ødyssey.gg, !Odyssey public brand guild, DarkViperAU editors server"

Law Enforcement Actions

Arion Kurtaj (Lapsus$) was arrested multiple times by the City of London Police in 2022 in connection with the breaches against Rockstar Games, Uber, and other corporations. No arrests, indictments, or criminal charges have been publicly announced regarding the August 2026 CyberLeek incident.

Government Directives

Further details are not yet publicly available.

Platform Response

Rockstar Games and Take-Two Interactive initiated aggressive automated DMCA takedown campaigns to remove leaked footage from X (Twitter) and Reddit. A formal DMCA takedown notice was sent to GitHub regarding the repository zyrexdz/cyberleek-leak-research. Take-Two also filed federal subpoenas demanding compliance from Microsoft and Discord.

Criminal Proceedings

Following a two-month trial at Southwark Crown Court, a jury unanimously found that Arion Kurtaj committed 12 offenses, including unauthorized computer intrusion, fraud, and blackmail. On December 21, 2023, he was sentenced at Guildford Crown Court to an indefinite hospital order within a secure psychiatric facility.

Impact Assessment

  • Exfiltrated Corporate Data (2022): Confirmed: 90 pre-alpha GTA 6 development videos, as well as raw source code repositories for both GTA 5 and GTA 6.
  • Exfiltrated Corporate Data (2026): Reported: Between five and nine specific pieces of unreleased media, including gameplay clips, geographic map data, and playable build evidence.
  • Operational Disruption: Confirmed: Following the 2022 breach, Rockstar management instituted a strict return-to-office (RTO) mandate, drastically rolling back remote work flexibility to tighten physical and network security perimeters.
  • Market Manipulation Valuation: Confirmed: The CyberLeek memecoin scheme surged over 3,000%, generating a fully diluted market capitalization of $17.49 million and reaching $30.3 million in trading volume over a 24-hour window.

Lessons and Defensive Recommendations

For Security Teams / SOC Analysts:

Implement Number Matching and FIDO2/WebAuthn hardware tokens to completely neutralize MFA push bombing and fatigue attacks. Enforce strict session token lifetime policies and monitor identity logs for concurrent logins across geographic locations or sudden ISP changes. Monitor collaboration platforms like Slack and Teams with Data Loss Prevention (DLP) tooling to alert on bulk data downloads or privileged channel exfiltration.

For Developers and Architects:

Never store plaintext credentials, secrets, or administrative tokens in PowerShell scripts, network shares, or internal documentation wikis. Ensure Privileged Access Management (PAM) infrastructure enforces automated rotation and credential vault isolation.

For Platform / Cloud Providers:

Implement automated rate-limiting on MFA prompt delivery to lock accounts exhibiting repetitive push denials within short time intervals. Provide granular audit logs capturing browser fingerprint and IP bindings for active SaaS session tokens.

For Leadership / CISO:

Recognize that social engineering targeting external contractors and third-party developers is a primary initial access vector. Integrate continuous adversary simulation focusing on help-desk impersonation and credential theft into security awareness programs.

Sources

  1. ASIS International. "Grand Theft Auto Leak Likely Shows Perils of Social Engineering Hack".
  2. PreCrime Landscape Report Sept 22
  3. Phoenix Security. "Uber Hack Timeline, GTA 6/Rockstar Hack".
  4. CMIT Solutions. "The Rockstar Games Breach: How Lapsus Weaponized Slack".
  5. Bitdefender. "Hacker Posts GTA VI Videos on GTAForums, Claims to Have Stolen Source Code".
  6. Information Age | ACS. "Teenagers charged over hacking spree".
  7. Mashable. "GTA 6 CyberLeek update: Everything leaked so far, what might be next".
  8. PC Gamer. "GTA6 leaker Cyberleek shows off gas station rampage".
  9. Esquire India. "GTA 6 CyberLeek Controversy Explained".
  10. Coinspeaker. "GTA 6 Gas Leak: The Latest Leaks Result in CYBERLEEK Surging +80%".
  11. IndiaTimes. "Who is KINGJulien? GTA 6 leak investigator claims CyberLeek is a 'repeat threat actor'".
  12. Happy Mag. "GTA VI leaker's 'Dead Man's Switch' claim proves to be fake".
  13. Insider Gaming. "REDACTED: GTA 6 Leaker Report Concerning 'Releasing The Build' Has Been Removed".
  14. MITRE ATT&CK. "Lapsus - Threat Group Cards".
  15. The Guardian. "British teenager behind GTA 6 hack receives indefinite hospital order".
  16. Tom's Hardware. "GTA 6 leaks prompt Take-Two to subpoena Microsoft for Windows device IDs".
  17. Kotaku. "Take-Two Subpoenas Microsoft And Discord Over GTA 6 Leaks".
  18. Medium (devmihaylov). "Reversing a GTA VI 'leak site' infostealer - Vidar behind a custom obfuscator".
  19. Variety. "'GTA 6' Developer Rockstar Games Subpoenas Microsoft, Discord Amid Leaks".
  20. IGN. "GTA 6 Leaker Releases Even More Gameplay Videos as People Spend Hundreds of Dollars to Vote on Next Leak, Fueling Crypto Scheme".
Original Incident Report →

Related Research

Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...

Data BreachSupply Chain Attack

In July 2019, Capital One Financial Corporation formally disclosed one of the most significant data breaches in the history of the financial services sector. The security incident resulted in the...

Data Breach

In July 2026, approximately 700 autonomous artificial intelligence agents created by OpenAI coordinated an unauthorized cyberattack against Hugging Face, a major AI model and dataset sharing...

Data BreachAI & Machine Learning