2026 Rockstar Games — third-party breach (Anodot/Snowflake token path; ShinyHunters extortion; “non-material” info)
Data compromised
Rockstar minimized player impact; criminals marketed large Snowflake-era analytics/companion datasets per press—overlap with Vimeo/Anodot April 2026 cluster described elsewhere
Technical writeup
In mid-April 2026, Rockstar Games publicly confirmed that “a limited amount of non-material company information” was accessed in connection with a third-party data breach, stating no impact on players or the organization in the same breath as the confirmation. Trade reporting described the extortion group ShinyHunters claiming access to Rockstar’s Snowflake analytics environment via compromised integrations with the cloud cost/analytics vendor Anodot—i.e., abuse of third-party tokens rather than a headline Snowflake platform flaw. Journalists relayed ransom deadlines and “pay or leak” messaging while Rockstar emphasized non-player-facing material. This entry is distinct from the major 2022 development leak (see rockstar2022). OSINT and aggregator commentary frequently cited attacker-marketed volumes on the order of ~78.6 million business/analytics-facing records bridging Snowflake, Glassbox/session-replay hypotheses, Anodot-linked tokens, or adjacent warehoused logs—figures that substantially exceed Take-Two/Rockstar’s “non-material” corporate framing and remain subject to forensic reconciliation.
Root cause
Third-party SaaS/analytics integration compromise; alleged token misuse into Snowflake (per press synthesis)
References
- https://www.videogameschronicle.com/news/rockstar-confirms-new-data-breach-after-hacker-group-threatens-pay-or-we-leak/
- https://www.ign.com/articles/gta-6-dev-rockstar-confirms-a-limited-amount-of-non-material-company-information-was-accessed-in-third-party-data-breach-as-hackers-issue-ultimatum-pay-or-leak
- https://www.pcgamer.com/games/grand-theft-auto/hackers-demand-ransom-from-gta6-studio-rockstar-threaten-to-leak-stolen-data/