Rockstar Games Confirms Data Breach Following ShinyHunters Threat
- Rockstar Games has confirmed that it was the target of a cybersecurity breach involving third-party data after the hacking group ShinyHunters claimed to have infiltrated the publisher's cloud...
- The group has issued a ransom demand, giving the company until April 14, 2026, to make a payment or risk the public release of confidential data.
- The breach was first identified by security outlets Hackread and Cybersec Guru.
Rockstar Games has confirmed that it was the target of a cybersecurity breach involving third-party data after the hacking group ShinyHunters claimed to have infiltrated the publisher’s cloud servers.
The group has issued a ransom demand, giving the company until April 14, 2026, to make a payment or risk the public release of confidential data.
The breach was first identified by security outlets Hackread and Cybersec Guru. In a statement provided to Kotaku, Rockstar Games characterized the incident as a third-party data breach
and stated that a limited amount of non-material company information was accessed
.
The company further asserted that the security event had no impact on our organization or our players
.
Technical Details of the Breach
ShinyHunters claimed that the infiltration was made possible through the compromise of Rockstar’s Snowflake instances via Anodot.com. The group’s operational methods typically differ from traditional hacking, as they frequently exploit API keys, third-party integrations, and user sessions to gain access to corporate environments.
On their website, the group issued a final warning to the game publisher:
Rockstar Games, your Snowflake instances were compromised thanks to Anodot.com. Pay or leak. Here’s a final warning to reach out by 14 Apr 2026 before we leak, along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline.
ShinyHunters
While the group has threatened that the leak would lead to several annoying (digital) problems
, they have not yet detailed the specific nature of the stolen data or the exact ransom amount demanded.
Threat Actor Profile
ShinyHunters is an experienced group with a history of targeting high-profile organizations. The group has been linked to previous data breaches affecting Google, Microsoft, and Ticketmaster.
Their ability to target cloud infrastructure and third-party service providers makes them a persistent threat to large-scale technology and entertainment firms.
Historical Security Context
This incident is the latest in a series of security challenges for Rockstar Games. In 2022, the company suffered a major breach orchestrated by the Lapsus$ group.
The 2022 attack was significantly more disruptive, as the hackers gained access to internal development channels. This resulted in the leak of nearly 100 early gameplay videos and assets for Grand Theft Auto VI. There were also allegations that the source code for both Grand Theft Auto V and Grand Theft Auto VI was acquired during that breach.
The legal aftermath of the Lapsus$ hack saw one of the responsible parties, an 18-year-old member of the group, sentenced to indefinite hospitalization
.
