{"id":5581,"date":"2026-08-31T08:34:34","date_gmt":"2026-08-31T08:34:34","guid":{"rendered":"https:\/\/justfineinfotech.com\/the-gta-vi-leaks-are-breaking-the-internet-security-researchers-have-seen-this-before\/"},"modified":"2026-08-31T08:34:34","modified_gmt":"2026-08-31T08:34:34","slug":"the-gta-vi-leaks-are-breaking-the-internet-security-researchers-have-seen-this-before","status":"publish","type":"post","link":"https:\/\/justfineinfotech.com\/fr\/the-gta-vi-leaks-are-breaking-the-internet-security-researchers-have-seen-this-before\/","title":{"rendered":"The GTA VI leaks are breaking the internet. Security researchers have seen this before."},"content":{"rendered":"<p>Grand Theft Auto VI, widely heralded as the game event of the decade, took a significant hit last week after a cybercriminal sent much of the internet into pandemonium after publishing gameplay footage a week before the game\u2019s publisher planned to <a href=\"https:\/\/www.ign.com\/articles\/grand-theft-auto-6-an-extended-look-global-release-times-confirmed\" rel=\"nofollow noopener\" target=\"_blank\">reveal core portions<\/a> of the game to the public.\u00a0\u00a0<\/p>\n<p>The files posted by the online persona \u201cCyberLeek\u201d indicate either a hacker had direct access to Rockstar Games\u2019 most sensitive systems or was given proprietary data by an insider, eventually becoming one of the highest-profile data extortion attacks of the year \u2014 a vexing, almost-daily occurrence hitting industries of all types<\/p>\n<p>While most data extortion attacks rattle companies due to regulatory or privacy concerns, this particular incident has caused an outsized response from Rockstar\u2019s parent company, Take-Two Interactive Software, because it has an audience. While no lives are at risk, as they would be in an attack on critical infrastructure, the financial and reputational stakes are magnified precisely because people are watching every drip of stolen footage become a news story or a trending topic.\u00a0<\/p>\n<p>\u201cIP theft \u2014 whether it\u2019s conducted by a cybercriminal, an insider, or even potentially [an artificial intelligence] model \u2014 rips away the hard work, passion, and livelihood among employees and companies that created the product in the first place,\u201d Cynthia Kaiser, senior vice president of Halycon\u2019s ransomware research center, told CyberScoop.The game\u2019s prior release, GTA V, along with its online component, has sold over 230 million copies and earned Take-Two <a href=\"https:\/\/www.gtaboom.com\/gta-v-keeps-selling-millions-and-gta-6-is-five-months-away-ed49\" rel=\"nofollow noopener\" target=\"_blank\">over $11 billion<\/a> since its release in 2013. <a href=\"https:\/\/newzoo.com\/articles\/gta-6-first-week-pre-order-sales\" rel=\"nofollow noopener\" target=\"_blank\"><a href=\"https:\/\/justfineinfotech.com\/tiktok-ads-benchmarks-by-industry-updated-2026-data-triple-whale\/\" title=\"TikTok Ads Benchmarks by Industry (Updated 2026 Data) | Triple Whale\">Industry<\/a> analysts say<\/a> GTA VI is on pace to make between $3.3 billion to $5.2 billion in cumulative global sales by the end of its launch week in November.\u00a0<\/p>\n<p>\u201cThe crown jewels of a company are whatever makes it differentiated and special,\u201d said Kaiser, the former deputy assistant director of the FBI\u2019s cyber division. \u201cFor some, that means customer data or  jewel is the surprise.\u201d<\/p>\n<p>While Take-Two hasn\u2019t said anything publicly about the leaks, it has responded feverishly ubpoenas under the Digital Millennium Copyright Act against Discord, Google, Microsoft and X, seeking the identity of CyberLeeks and other user accounts it accuses of copyright infringement<\/p>\n<p>Federal judges granted the subpoenas against Discord, Microsoft and X, but the petition against Google remained unapproved as of Monday. Take-Two\u2019s legal representatives also sent copyright notices to the four companies, informing them of the copyrighted material published on their platforms, but it\u2019s unclear if any of the tech companies have been formally served with the signed subpoenas.\u00a0<\/p>\n<p>Take-Two and Rockstar did not respond to a request for comment.The subpoenas may have been enough to spook those responsible for the leaked footage. As of Monday, the websites where those behind CyberLeek were posting leaked information and links to a memecoin were offline<\/p>\n<p>Zach Edwards, staff threat researcher at Infoblox and a self-proclaimed fan of the series, initially thought the leaks were part of a Rockstar guerrilla <a href=\"https:\/\/justfineinfotech.com\/b2b-marketing-on-tiktok-what-you-need-to-know-martech\/\" title=\"B2B marketing on TikTok: What you need to know | MarTech\">marketing<\/a> campaign. But the company\u2019s response \u201cconfirms that this is a real investigation, and the content being shared is likely real to some degree,\u201d he said.\u00a0<\/p>\n<p>Take-Two\u2019s actions thus far indicate the company is approaching the breach and leaks like an insider threat investigation, Edwards said. Whoever leaked the footage may have had access to an actual build of the game, he added. That could point to an insider, someone who could have saved a copy to a cloud service, uploaded it to a file-hosting site, or walked out with it on an external drive<\/p>\n<p>The hacker or group behind CyberLeek claim they are releasing the gameplay videos to protest Rockstar\u2019s decision to <a href=\"https:\/\/www.hollywoodreporter.com\/business\/business-news\/grand-theft-auto-vi-digital-only-no-disc-rip-physical-media-1236629695\/\" rel=\"nofollow noopener\" target=\"_blank\">not release physical copies of the game<\/a>. Yet, watermarks on the leaked videos include addresses to crypto wallets, which indicate CyberLeek is also, and perhaps primarily, seeking a payout.\u00a0<\/p>\n<p>\u201cThe persona behind the leaks, CyberLeek, published an anti-corporate manifesto targeting digital pre-orders and disc-less releases to frame the breach as hacktivism,\u201d Ben Bernstein, manager of Huntress\u2019 cybersecurity advisors team, told CyberScoop. \u201cYet behind the political posturing, there\u2019s clear financial monetization and clout-chasing.\u201d<\/p>\n<p>Kaiser draws the same conclusion. \u201cLet\u2019s separate stated motive from observed behavior,\u201d she said. \u201cThreat actors who talk about principle while running a monetization channel are usually only telling you what they think will land with an audience, not actually what is driving them.\u201d<\/p>\n<p>Katie Moussouris said \u201cthis is what the alternative vulnerability economy looks like.\u201d The founder and CEO at Luta Security has spent decades building legitimate channels for people who find security problems to get paid without turning to crime<\/p>\n<p>\u201cThe leaker launched a cryptocurrency token, watermarked stolen footage with a buy link, and offered to sell ad space on future leaks. Each of those pays out in proportion to how many people are watching. The manifesto is what keeps them watching,\u201d Moussouris said.\u00a0<\/p>\n<p>\u201cThat is a genuinely new monetization model for stolen pre-release content, and it means the usual playbook of negotiating a ransom payment quietly or paying to make it stop won\u2019t work,\u201d she added<\/p>\n<p>Despite its unique characteristics, the rhythm of the attack and its fallout is familiar territory for cybersecurity experts.\u00a0<\/p>\n<p>\u201cSteal, publish a sample, promise more, deliver, repeat. Just like ransomware attacks, in cases like these criminals use every lever of pressure they can against a company \u2014 including the fear of what is coming next \u2014 to profit from their actions,\u201d Kaiser said.\u00a0<\/p>\n<p>\u201cThe attackers are crowdsourcing their pressure tactics. A meaningful share of the player base is treating the leaks as free content and amplifying them,\u201d she added<\/p>\n<p>Kaiser also sees some clear parallels with previous attacks targeting major entertainment companies, including the 2014 attack on Sony Pictures and the HBO hack in 2017.\u00a0<\/p>\n<p>\u201cThe Sony comparison is useful for how these things escalate, but this incident reminds me more of the Iranian hackers\u2019 leak of \u2018Game of Thrones\u2019 episodes a few years back,\u201d she said. \u201cNorth Korea attacked Sony for political purposes, destroying its data along the way; Iranian threat actors compromised HBO, along with hundreds of universities and over forty other companies, in a hacking-for-hire scheme stealing American intellectual property.\u201d<\/p>\n<p>Federal authorities earlier this month unsealed a second wave of indictments against 17 Iranians affiliated with the tech firm Mabna Institute who allegedly stole troves of data from government agencies and dozens of companies, including HBO<\/p>\n<p>This isn\u2019t the first time Rockstar has been hit with a security incident. In 2022, an 18-year old British man who was a member of the Lapsus$ cybercriminal gang was sentenced to an indefinite hospital order after leaking gameplay footage. <a href=\"https:\/\/www.bbc.com\/news\/technology-67663128\" rel=\"nofollow noopener\" target=\"_blank\">According to the BBC<\/a>, the incident cost Rockstar, along with ridehauling company Uber and chipmaker Nvidia, over $10 million.\u00a0<\/p>\n<p>Security professionals expect the situation to escalate on all sides. Leaks have hit the internet daily for the past eight days, including a series of leaks Tuesday morning. Meanwhile, Take-Two has not relented on its subpoenas. Its broadest move was a subpoena against Discord, seeking identifying data on CyberLeek, two other users and every member of three Discord servers where the copyrighted material was posted.\u00a0\u00a0<\/p>\n<p>Moussouris said the scope of that inquiry should worry people well beyond this case.\u00a0<\/p>\n<p>\u201cTake-Two asked for Windows device identifiers, login records, and cloud storage contents for every person who spoke in three Discord servers going back to June,\u201d she said. \u201cThe people with the best chance of uncovering the culprits are those doing the unglamorous investigation forensics work of figuring out how the build may have leaked.\u201d<\/p>\n<p>Discord would not say whether it had been formally served or what it has done in response. A company spokesperson said it reviews and complies with valid subpoenas when they are received.\u00a0<\/p>\n<p>While the breach and leak of \u2018GTA VI\u2019 material is a serious matter, Edwards noted that Take-Two is also benefiting from greater interest in the unreleased game on a daily basis.\u00a0<\/p>\n<p>\u201cThe threat actor leaking these videos has failed by essentially creating a successful underground marketing campaign for the game while also putting themselves at serious risk of being eventually caught,\u201d he said.\u00a0<\/p>\n<p>\u201cThis incident is playing out like a classic insider threat exploitation scheme. Someone got access to sensitive data, they had a political agenda which clashed with the owner of the sensitive data, and they decided to do something stupid to try and force a <a href=\"https:\/\/justfineinfotech.com\/how-to-change-your-primary-market-in-shopify\/\" title=\"How to Change Your Primary Market in Shopify\">change<\/a>,\u201d Edwards added. \u201cThis attack has done nothing but spread \u2018GTA VI\u2019 content further than it would have otherwise, and it\u2019s creating ripples across other industries like cybersecurity who would have never covered \u2018GTA 6\u2019 issues previously.\u201d<\/p>\n<div style=\"clear:both;margin:30px 0 15px 0\">\n<p>\n    <strong>Related:<\/strong><br \/>\n    <a href=\"https:\/\/yoursite.com\/automation-training-benin\/\" title=\"Digital Automation Training Benin: 5 Winning Skills Employers Demand in 2026\" target=\"_blank\" rel=\"noopener\"><br \/>\n      Digital Automation Training Benin: 5 Winning Skills Employers Demand in 2026<br \/>\n    <\/a>\n  <\/p>\n<p>\n    <a href=\"https:\/\/yoursite.com\/automation-africa\/\" title=\"WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria\" target=\"_blank\" rel=\"noopener\"><br \/>\n      WhatsApp Marketing Automation Africa: 6 Dangerous Mistakes Brands Make in Nigeria<br \/>\n    <\/a>\n  <\/p>\n<\/div>\n<div style=\"clear:both;margin:30px 0;padding:25px;background:#f8f9fc;border:1px solid #ddd;border-radius:8px;text-align:center\">\n<h3>Want to learn this practically?<\/h3>\n<p>Join <strong>Justfine Infotech<\/strong> and build real digital skills in AI, automation, web development, digital marketing, office productivity, e-commerce, freelancing and cybersecurity.<\/p>\n<p><strong>Available Programmes:<\/strong><br \/>\n  6 Weeks Certificate \u2022 3 Months Professional Certificate \u2022 6 Months Diploma \u2022 Full Professional Diploma<\/p>\n<p><strong>WhatsApp:<\/strong><br \/>\n  +229 01 57 57 99 15<br \/>\n  +229 01 66 68 11 60<\/p>\n<p><a href=\"https:\/\/api.whatsapp.com\/send?phone=2348132690270&amp;text=Hello\" target=\"_blank\" rel=\"noopener\">Enroll Now<\/a><\/p>\n<\/div>\n<p class=\"ani-source\">Source: <a href=\"https:\/\/cyberscoop.com\/grand-theft-auto-6-data-theft-extortion-leaks\/\" target=\"_blank\" rel=\"nofollow noopener\">cyberscoop.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Grand Theft Auto VI, widely heralded as the game event of the decade, took a significant hit last week after a cybercriminal sent much of the internet into pandemonium after publishing gameplay footage a week before the game\u2019s publisher planned to reveal core portions of the game to the public.\u00a0\u00a0<\/p>","protected":false},"author":1,"featured_media":5583,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[71],"tags":[1513,298,1529,841,299],"class_list":["post-5581","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-online-scam-alerts","tag-breaking","tag-internet","tag-leaks","tag-researchers","tag-security"],"_links":{"self":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/5581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/comments?post=5581"}],"version-history":[{"count":1,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/5581\/revisions"}],"predecessor-version":[{"id":5582,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/5581\/revisions\/5582"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media\/5583"}],"wp:attachment":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media?parent=5581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/categories?post=5581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/tags?post=5581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}