LIVE · cybersecurity feed
Live wire
Employee benefits platform Paylogix says hackers stole financial and health dataAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attackHackers target WordPress sites in miniOrange auth bypass attacksFake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Fake Microsoft security scans trick victims into uninstalling their antivirusCVE-2026-19478 · ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Vulnerability Gap: Why Discovery Is Outrunning Repair
breach

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

zeroday.news ·

Rockstar Games, a subsidiary of Take-Two Interactive Software, has been targeted in a high-profile data extortion attack involving the unauthorized release of gameplay footage from the highly anticipated *Grand Theft Auto VI* (GTA VI). The incident, which saw gameplay videos published online a week before the publisher's planned reveal, has been described by some as one of the most significant data extortion attacks of the year, drawing an unusually large public response due to the game's massive fanbase.

The online persona or group claiming responsibility for the leaks, "CyberLeek," has posted files that suggest direct access to Rockstar Games' sensitive systems or proprietary data obtained from an insider. While the financial and reputational stakes are high for Take-Two, the incident has garnered widespread attention because of the public's intense interest in the game. *Grand Theft Auto V*, the previous installment, has sold over 230 million copies and generated over $11 billion for Take-Two since its 2013 release, with analysts projecting *GTA VI* to achieve between $3.3 billion and $5.2 billion in global sales by the end of its launch week.

Take-Two has responded aggressively through its legal team, filing petitions for subpoenas under the Digital Millennium Copyright Act (DMCA) against Discord, Google, Microsoft, and X (formerly Twitter). These subpoenas seek to identify CyberLeek and other user accounts accused of copyright infringement. Federal judges have granted the subpoenas against Discord, Microsoft, and X, though the petition against Google remained pending. Additionally, Take-Two's legal representatives have issued copyright notices to these platforms regarding the unauthorized material. Following these legal actions, websites associated with CyberLeek that were hosting leaked information and promoting a memecoin have gone offline.

Initially, some observers speculated the leaks might be a marketing stunt, but Take-Two's robust legal response confirms the seriousness of the investigation and the authenticity of the shared content. The company's actions suggest it is treating the breach as an insider threat investigation, indicating that whoever leaked the footage may have had access to an actual build of the game, potentially saving it to a cloud service, uploading it to a file-hosting site, or removing it on an external drive.

CyberLeek has presented conflicting motivations for the leaks. The group claims to be protesting Rockstar's decision against physical game releases, publishing an "anti-corporate manifesto" targeting digital pre-orders and disc-less releases, framing the breach as hacktivism. However, the leaked videos are watermarked with crypto wallet addresses, suggesting a primary objective of financial gain. This combination of political posturing and clear financial monetization, including the launch of a cryptocurrency token and offers to sell ad space on future leaks, represents a novel monetization model for stolen pre-release content. This approach means traditional ransom negotiations or quiet payments may not be effective.

Despite the unique monetization strategy, cybersecurity experts note that the attack's rhythm—steal, publish a sample, promise more, deliver, repeat—is a familiar playbook, akin to ransomware attacks where criminals leverage various pressures, including the threat of future leaks, to profit. The attackers are effectively crowdsourcing pressure, with a significant portion of the player base amplifying the leaks as free content.

Parallels have been drawn to past attacks on major entertainment companies, such as the 2014 Sony Pictures hack and the 2017 HBO breach. While the Sony attack involved data destruction for political motives, the HBO incident, linked to Iranian threat actors, focused on intellectual property theft. This is not Rockstar's first security incident; in 2022, an 18-year-old member of the Lapsus$ cybercriminal gang was sentenced after leaking gameplay footage, an incident that reportedly cost Rockstar, Uber, and Nvidia over $10 million.

Security professionals anticipate an escalation of the situation, as leaks have continued daily for over a week.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

LACMA data breach last year exposed social security and medical data

The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]

breach

A Cautionary Tale About Data Breach Claims, Verification and Carhartt

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: 🚨Cyber

phishing

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]

ai

Hidden Prompts Trick AI Into False Email Summaries

With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.

nation-state

58 arrested in international cybercrime crackdown

Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.

security

Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice

Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice appeared first on CyberScoop.