Summary
- A threat actor operating as ‘CyberLeek’ has published GTA VI gameplay footage, pointing to either direct system compromise or insider access at Rockstar Games.
- The attacker wrapped financial monetisation — crypto wallets, ad space, a memecoin — inside a hacktivist manifesto, a combination that renders traditional ransom negotiation ineffective.
- Parent company Take-Two Interactive has pursued DMCA subpoenas against Discord, Microsoft, X, and Google, with the Discord subpoena sweeping in identifying data on every member of three servers.
- Security researchers draw parallels with the 2014 Sony Pictures and 2017 HBO breaches, while noting the audience-amplified pressure dynamic is a newer escalation tactic.
- The incident is a reminder that for any organisation with high-value IP, pre-release assets are crown jewels requiring protection equivalent to customer data or source code.
What happened
In the week before Take-Two Interactive planned a controlled reveal of Grand Theft Auto VI material, a threat actor using the online persona ‘CyberLeek’ began publishing gameplay footage. The files indicate the actor either compromised Rockstar Games’ internal systems directly or obtained proprietary data through an insider. Leaks have continued daily for more than eight days, including a fresh release on Tuesday morning.
Access vector points to insider or build leak
Infoblox staff threat researcher Zach Edwards assessed that whoever posted the footage may have had access to an actual build of the game. That framing — access to a compiled build rather than raw source — points toward an insider who copied material to a cloud service, uploaded it to a file-hosting site, or removed it on external media. Take-Two’s legal response, which targets individual user accounts across multiple platforms, is consistent with the company treating this as an insider threat investigation.
A monetisation model that breaks the usual playbook
CyberLeek claims the leaks are a protest against Rockstar’s decision not to release physical copies of the game. But the observed behaviour tells a different story. Watermarks on leaked footage point to cryptocurrency wallets, and the actor offered to sell advertising space on future leaks. Katie Moussouris, founder and CEO of Luta Security, described it plainly: ‘The leaker launched a cryptocurrency token, watermarked stolen footage with a buy link, and offered to sell ad space on future leaks. Each of those pays out in proportion to how many people are watching. The manifesto is what keeps them watching.’ Moussouris noted this model means the standard approach of negotiating a quiet ransom settlement will not work here.
Crowdsourced pressure: a familiar structure, new amplifier
Cynthia Kaiser, senior vice president at Halcyon’s ransomware research centre and former FBI cyber division deputy assistant director, described the underlying rhythm as consistent with ransomware operations: ‘Steal, publish a sample, promise more, deliver, repeat.’ What is different is the audience. A significant portion of the game’s player base is treating the leaked footage as free content and spreading it further, effectively amplifying the attacker’s pressure on Take-Two without any additional effort from CyberLeek. Kaiser drew comparisons to the Sony Pictures breach in 2014 and the 2017 HBO compromise, where Iranian actors affiliated with the Mabna Institute stole intellectual property in a hacking-for-hire scheme. Federal authorities unsealed a second wave of indictments against seventeen Mabna-linked individuals earlier this month.
The subpoena scope that concerns security professionals
Take-Two has petitioned for DMCA subpoenas against Discord, Microsoft, X, and Google. Federal judges approved the subpoenas against Discord, Microsoft, and X; the Google petition remained unapproved as of Monday. The Discord subpoena is the one drawing scrutiny from security professionals. According to Moussouris, it requests Windows device identifiers, login records, and cloud storage contents for every person who spoke in three Discord servers going back to June — not just the suspected threat actors. Discord said it reviews and complies with valid subpoenas when received but would not confirm whether it had been formally served. The breadth of that request has implications for platform users well beyond this case.
Context: Rockstar has been here before
This is not Rockstar’s first major security incident. In 2022, an eighteen-year-old British member of the Lapsus$ gang leaked gameplay footage. That incident, combined with related attacks on Uber and Nvidia, cost those organisations over ten million dollars according to BBC reporting. The prior compromise did not prevent a second major breach, which should prompt reflection on whether lessons were embedded in lasting controls.
Why it matters
For CISOs, this incident crystallises several converging risks. First, pre-release intellectual property — game builds, product roadmaps, unreleased research — warrants the same classification and access controls as regulated personal data. Second, insider threat programmes cannot focus solely on data exfiltration alerts; they must account for the window between an employee or contractor obtaining a build and walking out with it. Third, the attacker’s hybrid monetisation model — combining financial instruments with a public manifesto to sustain audience engagement — removes the possibility of a quiet resolution and turns your user base into involuntary pressure amplifiers. Finally, legal remedies such as DMCA subpoenas are available but move slowly, and the breadth of the Discord subpoena demonstrates that aggressive legal responses can create secondary reputational and trust issues of their own.
What to do now
- Classify pre-release builds, prototypes, and roadmap assets explicitly as high-value IP and apply access controls equivalent to those protecting sensitive personal data.
- Audit who currently has access to production builds and similar assets, and apply least-privilege principles — particularly for contractors and staff in the final stages of a major product cycle.
- Review data loss prevention coverage for cloud sync services and removable media, which the source material identifies as likely exfiltration vectors in this case.
- Ensure insider threat monitoring programmes cover asset removal scenarios, not just bulk data transfers, and include egress from collaboration and build environments.
- Brief legal and communications teams now on the trade-offs of broad subpoena requests, which the source material indicates can generate secondary scrutiny beyond the immediate investigation.
