← Rockstar Games

2026 Rockstar Games — third-party breach (Anodot/Snowflake token path; ShinyHunters extortion; “non-material” info)

2026 78.6M records affected Share on X

Data compromised

Rockstar minimized player impact; criminals marketed large Snowflake-era analytics/companion datasets per press—overlap with Vimeo/Anodot April 2026 cluster described elsewhere

Technical writeup

In mid-April 2026, Rockstar Games publicly confirmed that “a limited amount of non-material company information” was accessed in connection with a third-party data breach, stating no impact on players or the organization in the same breath as the confirmation. Trade reporting described the extortion group ShinyHunters claiming access to Rockstar’s Snowflake analytics environment via compromised integrations with the cloud cost/analytics vendor Anodot—i.e., abuse of third-party tokens rather than a headline Snowflake platform flaw. Journalists relayed ransom deadlines and “pay or leak” messaging while Rockstar emphasized non-player-facing material. This entry is distinct from the major 2022 development leak (see rockstar2022). OSINT and aggregator commentary frequently cited attacker-marketed volumes on the order of ~78.6 million business/analytics-facing records bridging Snowflake, Glassbox/session-replay hypotheses, Anodot-linked tokens, or adjacent warehoused logs—figures that substantially exceed Take-Two/Rockstar’s “non-material” corporate framing and remain subject to forensic reconciliation.

Root cause

Third-party SaaS/analytics integration compromise; alleged token misuse into Snowflake (per press synthesis)

References