Skip to main content
Emerging ThreatsData Breaches

Rockstar Games Leak Exposes Insider Threat Risks

Empty office with computer and papers, blurred cityscape behind.
"IP theft — whether it’s conducted by a cybercriminal, an insider, or even potentially [an artificial intelligence] model — rips away the hard work, passion, and livelihood among employees and companies that created the product in the first place," Cynthia Kaiser told CyberScoop.

The week-long release of early Grand Theft Auto VI footage by an online persona calling itself "CyberLeek" has turned a pre-launch marketing moment into a high-profile data-extortion case. The breach — and the public, recurring publication of stolen material — has exposed a fault line between traditional copyright enforcement, new monetization tactics used by threat actors, and the practical limits of quiet remediation when an audience is watching.

What CyberLeek published and what they claim

The individuals behind CyberLeek posted gameplay footage from Grand Theft Auto VI, along with a manifesto protesting Rockstar’s decision not to release physical copies of the game. The leaked videos were watermarked with cryptocurrency wallet addresses and links to a memecoin, indicating a simultaneous effort to monetize the leaks. Security researchers reported that the persona offered ad space on future leaks and launched a cryptocurrency token tied to the campaign.

Take-Two’s subpoenas against Discord, Microsoft and X — and Google left pending

Take-Two Interactive, Rockstar Games’ parent company, responded with legal action: it petitioned a federal court for subpoenas under the Digital Millennium Copyright Act seeking the identities of CyberLeek and other user accounts on platforms including Discord, Google, Microsoft and X. Federal judges granted subpoenas against Discord, Microsoft and X; the petition against Google remained unapproved as of Monday. Take-Two also sent copyright notices to those four companies. Take-Two and Rockstar did not respond to requests for comment in the reporting.

Security researchers, forensics and the insider hypothesis

Researchers and industry analysts who spoke to CyberScoop said the pattern of the release points to an insider or someone with access to an actual game build. Zach Edwards, a staff threat researcher at Infoblox and a self-described fan of the series, said he initially thought the leaks might be a guerrilla marketing campaign but concluded the company's legal moves "confirm that this is a real investigation, and the content being shared is likely real to some degree." Infoblox’s assessment aligns with other security commentary that emphasized the likelihood that an individual saved a build to cloud storage, uploaded it to a file-hosting site, or copied it to external media.

Monetization, motive and the new "alternative vulnerability economy"

The public posture of the leak mixes political complaint with clear monetization. Ben Bernstein of Huntress noted the anti-corporate manifesto, but also pointed to the visible financial channels. Katie Moussouris, founder and CEO of Luta Security, framed the campaign as "what the alternative vulnerability economy looks like," describing a model that pays based on audience size rather than discrete ransom negotiation. Moussouris highlighted three concrete revenue streams in the leaks: a crypto token launch, watermarked video buy links, and the sale of ad space tied to future disclosures. Cynthia Kaiser compared the cadence of the attack — "Steal, publish a sample, promise more, deliver, repeat" — to ransomware extortion playbooks, with the added pressure of fan engagement amplifying the release.

How technologists, regulators, and players are likely to respond

  • Technologists and security teams: Expect an emphasis on insider-threat forensics. Take-Two's subpoenas sought broad account and device identifiers, login records and cloud-storage details for people active in named Discord servers, signaling that forensic traces in cloud and collaboration services are central to the hunt.
  • Regulators and legal teams: The subpoenas and DMCA notices underline the legal route publishers are using to unmask leakers; but the mixed success of those subpoenas — granted against some platforms and not yet against others — shows uneven judicial outcomes and will inform future litigation strategy.
  • Players and the public: The leaks have increased daily attention to GTA VI; as Infoblox’s Zach Edwards observed, the campaign has arguably amplified the game’s reach while placing the leaker at greater risk of identification and prosecution.

Leaked footage has appeared daily for eight days, including additional material released Tuesday morning, and some of the sites where CyberLeek posted links and memecoin pitches were offline as of Monday. Industry observers drew parallels to previous entertainment-industry breaches, citing 2014 and 2017 incidents, and flagged an earlier 2022 event in which a member of the Lapsus$ gang leaked gameplay footage — a breach that the BBC reported cost Rockstar and other victims more than $10 million.

The record in this case is both concrete and open-ended: concrete in the files posted, the subpoenas granted, and the monetization mechanics visible on the watermarked videos; open-ended in how courts and platforms will balance disclosure, user privacy, and the investigation, and in whether the public attention will aid or impede the search for those responsible. As Katie Moussouris put it in describing the leaks’ business model, the audience is the currency — and when currency mixes with copyright claims, cloud forensics and platform takedowns, the investigative and legal playbooks collide in public view.

Read the original CyberScoop story: https://cyberscoop.com/grand-theft-auto-6-data-theft-extortion-leaks/