Rockstar Games Attacks Expose MFA Fatigue, OAuth Token Theft and Dev Pipeline Security Failures
Lares ties Rockstar breaches to MFA fatigue and stolen OAuth tokens, including a claimed 78.6-million-record Snowflake leak.
A September 2026 Lares analysis reconstructs Rockstar Games intrusions that used trusted identities rather than a perimeter exploit. In 2022, Lapsus$-linked access exposed about 90 GTA VI development videos after credential use, MFA fatigue, and secret searches in Slack and Confluence. In April 2026, ShinyHunters claimed 78.6 million Snowflake records via compromised analytics firm Anodot; Rockstar said access was limited, non-material, and did not affect players. Lares characterizes the tokens as long-lived OAuth bearers, while stressing that parts of the chain are assessments; client flaw CVE-2023-24059 is a separate 2023 issue.
- Lapsus$-linked 2022 access exposed about 90 GTA VI development videos.
- Lares cites valid credentials, MFA fatigue, and secrets in Slack and Confluence.
- ShinyHunters claimed 78.6 million Snowflake records after compromising Anodot.
- Rockstar said 2026 access was limited and players were unaffected.
- CVE-2023-24059 affected GTA V and is separate from these identity breaches.
Vulnerabilities mentionedAll →
- CVE-2023-240597.32%Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023published · rockstargames grand theft auto v
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-24059 | Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023 Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023. NVD description · AI analysis pending |
Full article567 words · extracted from gbhackers.com · click to collapse
Rockstar Games’ breach history illustrates how stolen identities, trusted integrations and exposed development assets can undermine enterprise defenses without a perimeter exploit.
A September 2026 Lares analysis connects the incidents, although several reconstructed attack details remain assessments rather than independently established forensic findings.
In September 2022, an intrusion associated with Lapsus$ exposed approximately 90 GTA VI development videos.
The central issue is misplaced trust: authentication does not establish that a user, service account or integration remains legitimate.
Across Rockstar’s reported compromises, attackers exploited access paths designed for employees and business partners, turning operational convenience into opportunities for data theft.
Reporting connected the theft to access through Rockstar’s internal Slack environment, demonstrating how collaboration platforms can become distribution channels for sensitive engineering material.
However, contemporary reporting described Rockstar’s use of the same push-bombing technique seen at Uber as likely, not conclusively established. Source-code access also remained an attacker claim in that reporting.
The distinction matters technically. Repeated push approvals can undermine authentication, while searchable credentials expand an intruder’s reach after entry.
Lares attributes Rockstar Games, initial access to legitimate credentials and MFA fatigue, followed by searches across Slack and Confluence for exposed secrets.
MFA Fatigue Exploited
Lares recommends FIDO2 hardware keys, stronger authentication controls and automated secret detection within collaboration systems to reduce those exposure paths.

The April 2026 incident shifted attention from employee accounts to third-party access.
Reuters reported that ShinyHunters claimed possession of 78.6 million records from Rockstar’s Snowflake account after compromising analytics provider Anodot.
Rockstar confirmed access to limited, non-material company information and said players were unaffected.
Snowflake said its platform was not compromised and disabled accounts referencing Anodot after identifying unusual activity.
Separate reporting linked the wider campaign to stolen authentication tokens, illustrating how compromised integrations can provide legitimate-looking access to downstream customer environments.
Lares characterizes the credentials as long-lived OAuth bearer tokens. That specificity should remain attributed: the available reporting establishes token theft more clearly than token lifetime or configuration.
Bearer-token replay risk can be reduced through sender-constrained mechanisms such as DPoP, defined in RFC 9449, where supported by authorization and resource servers.
Lares reports that Cyberleek began releasing GTA VI material on August 18, 2026, including gameplay footage and mapping information, while promoting a cryptocurrency token.
Its analysis interprets the releases as evidence of access to a playable development build.
That interpretation is not equivalent to a verified attack chain. Other coverage notes that no authenticated public distribution of a functional build exists.
Footage alone cannot establish stolen signing keys, compromised build servers, source-code compilation or the precise exfiltration route.
Consequently, segmentation and egress failures remain hypotheses requiring forensic validation.
The related CVE-2023-24059 affected GTA V on PC, enabling partial remote code execution or file modification during January 2023 exploitation.
NVD assigns a 7.3 severity score; February’s security update introduced improved networking protections. This client vulnerability should not be conflated with enterprise identity breaches.
Defenders should isolate build infrastructure, restrict integration privileges and correlate authentication, warehouse-query and outbound-transfer telemetry.
Collaborative purple teaming can test whether those controls actually detect stolen identities and unauthorized asset movement before access becomes a major leak.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.