Lares Links Separate Rockstar Breaches to Stolen Identities
A 2026 Lares review links separate Rockstar intrusions to MFA fatigue and long-lived OAuth tokens, while reports disagree on source-code theft and a later leak.
A September 2026 Lares analysis reconstructs separate Rockstar Games intrusions that relied on trusted identities rather than a single perimeter exploit. In September 2022, Lapsus$-linked access used legitimate credentials and MFA fatigue or repeated authentication prompts, followed by searches of Slack and Confluence for secrets; both reports say about 90 GTA VI development videos were exposed, but only one also says proprietary source code was stolen. In April 2026, ShinyHunters were linked to 78.6 million Snowflake business-analytics records after analytics firm Anodot was compromised and long-lived OAuth tokens were reused. One source says the records were claimed, while the other treats the theft as completed; Rockstar said access was limited, non-material, and did not affect players, and one report says the set excluded passwords, payments, source code, and GTA VI assets. Lares describes the tokens as long-lived OAuth bearers while noting that parts of the chain are assessments. The second report alone adds that Cyberleek published August 2026 footage from what researchers call an unfinished playable GTA VI build, and that fake 113GB downloads concealed a roughly 50KB payload. CVE-2023-24059, a 2023 GTA V client issue, is presented as unrelated to these breaches.
- A September 2026 Lares analysis describes separate Rockstar Games intrusions that used trusted identities rather than a perimeter exploit.
- In September 2022, Lapsus$-linked attackers used legitimate credentials and MFA fatigue or repeated login prompts, then searched Slack and Confluence; both reports say about 90 GTA VI development videos were exposed.
- Sources disagree on the 2022 theft: only one report says proprietary source code was also taken.
- In April 2026, ShinyHunters were tied to 78.6 million Snowflake business-analytics records after Anodot was compromised and long-lived OAuth tokens were reused; one report says the group claimed the records, the other that they took them.
- Rockstar said the 2026 access was limited, non-material, and did not affect players; one report adds that the dataset excluded player passwords, payments, source code, and GTA VI assets.
- Lares calls the tokens long-lived OAuth bearers and says parts of that chain are assessments.
- Only the second report adds an August 2026 Cyberleek leak of footage from an unfinished playable GTA VI build, plus fake 113GB downloads hiding a roughly 50KB payload.
- CVE-2023-24059, a 2023 GTA V client flaw, is described as separate from these identity breaches.
Coverage timelineoldest first · each row is one article
- · 1d agoRockstar Games Attacks Expose MFA Fatigue, OAuth Token Theft and Dev Pipeline Security Failures
GBHackers· 58
Lares ties Rockstar breaches to MFA fatigue and stolen OAuth tokens, including a claimed 78.6-million-record Snowflake leak.
- · 1d agoHackers Steal Rockstar Source Code, 78.6 Million Records and Playable GTA VI Build
Cyber Security News· 74
Lares links separate Rockstar intrusions to stolen source code, 78.6 million analytics records, and a leaked GTA VI build.
Vulnerabilities in this storyAll →
- CVE-2023-240597.32%Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023published · rockstargames grand theft auto v
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-24059 | Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023 Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023. NVD description · AI analysis pending |