
Rockstar Games Suffered Multiple Security Breaches Since 2018 Without Zero-Day Exploits
cybersecuritydata breachRockstar GamesMFA fatigueOAuth tokensGTA VI leakLapsus$ShinyHuntersCyberleeksecurity incidents
Rockstar Games experienced four security incidents between 2022 and 2026 using different attack methods: the 2022 Lapsus$ breach used MFA fatigue and hardcoded credentials from Slack/Confluence; early 2023 saw GTA Online's P2P netcode exploited for RCE; April 2026 involved ShinyHunters using stolen OAuth tokens from a third-party SaaS vendor to access Snowflake; and August 2026's Cyberleek incident exfiltrated a playable GTA VI build, videos, and map data indicating DLP and segmentation failures. A detailed writeup includes MITRE mappings and detection strategies for each attack chain.