Urgent.News

What's breaking now, across thousands of outlets.

Tech

Rockstar attack review maps identity and pipeline weaknesses

A September security analysis of breaches affecting Rockstar Games has highlighted how compromised identities, third-party integrations and development assets can defeat enterprise controls without attackers exploiting a conventional network perimeter. The analysis by security consultancy Lares reconstructs incidents spanning the 2022 Grand Theft Auto VI leak, an April 2026 third-party breach and…

Rockstar attack review maps identity and pipeline weaknesses

An examination of security breaches affecting Rockstar Games, conducted by Lares security consultancy, reveals how vulnerabilities in identities, third-party integrations, and development assets can bypass traditional enterprise defenses even without targeting the network perimeter. The analysis covers incidents from the 2022 Grand Theft Auto VI leak, a March 2026 third-party breach, and an unauthorized August release of GTA VI material.

Lares identifies MFA fatigue as the method used to gain initial access in the 2022 breach. Attackers exploited repeated authentication prompts to deceive users into approving fraudulent logins. Subsequently, they navigated collaboration tools like Slack and Confluence to discover credentials and internal data. These tactics have not been publicly confirmed by Rockstar through their forensic investigations.

In the April 2026 third-party breach, the company disclosed only that limited, non-material information was accessed. ShinyHunters claimed responsibility, stating they gained access to Rockstar-related Snowflake data through cloud analytics provider Anodot. Public reports indicated the accessed data pertained to company metrics, not player information or GTA VI assets.

Lares believes attackers obtained long-lived OAuth bearer tokens and abused them to query 78.6 million records in Rockstar's Snowflake environment. However, Rockstar has not confirmed this particular access vector or the claimed volume of queried records.

The August 2026 leak of GTA VI-related content, distributed under the Cyberleek alias, highlighted inadequate segmentation and outbound data-loss controls around development systems. While publicly available leaks confirm the existence of leaked material, the consultancy's reconstruction suggests possible paths for obtaining the content, such as whether an entire game build was exfiltrated or which internal security measures failed.

These breaches underscore the growing reliance of enterprises on identities and trusted software relationships beyond traditional network boundaries. Attackers can blend in as legitimate users or services until anomaly detection flags their behavior. Take-Two's annual disclosures emphasize cybersecurity risks related to source code, game assets, and confidential information, warning that theft or unauthorized publication could harm the company's competitive standing, reputation, and future sales.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

More from Wednesday 7 October →