Rockstar Games Confirms Breach Through Third-Party Vendor

The breach shows how attackers bypass hardened targets by compromising vendor integrations rather than direct infrastructure.

Illustration: Rockstar Games Confirms Breach Through Third-Party Vendor
AI-generated illustration · Sylvaris

The breach path

On April 13, 2026, Rockstar Games confirmed unauthorized access to company data following claims by the ShinyHunters hacking group. The breach did not originate from Rockstar's own systems. Instead, attackers gained entry through Anodot, a third-party cloud cost monitoring service used by Rockstar.

ShinyHunters posted a message on its dark web leak site stating that Rockstar's Snowflake cloud data had been compromised via Anodot. The group set a payment deadline of April 14, threatening to leak the data and cause additional digital disruptions if demands were not met.

What was taken

Rockstar described the accessed information as a limited amount of non-material company data. The company stated there was no impact on game operations or player information. Early evaluations suggest the stolen data includes corporate materials such as financial reports and user spending analytics, but no game development assets or source code for upcoming titles.

The supply chain pattern

The incident follows a pattern ShinyHunters has used in other breaches: targeting APIs, identity systems, and SaaS integrations rather than attacking hardened corporate networks directly. Security researchers noted that the group has been linked to breaches at multiple organizations using similar vendor-compromise tactics.

This is not Rockstar's first major security incident. In 2022, the company experienced a different breach that resulted in early gameplay footage from Grand Theft Auto VI being leaked online after an attacker gained access to the company's Slack workspace.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.