In April 2026, the BBC reported that Rockstar Games, the developer behind the hugely popular Grand Theft Auto (GTA) franchise, had once again become the target of a cyber-related incident. Although the company publicly downplayed the significance of the event and reassured stakeholders that its operations had not been severely affected, the incident attracted considerable attention due to Rockstar’s history with cyber security breaches.
What happened in the Rockstar Games / Grand Theft Auto 6 cyber attacks?
Cybercrime group ShinyHunters claimed it breached Rockstar Games through a third-party vendor compromise, alleging it obtained access to Rockstar’s Snowflake environment using authentication tokens connected to Anodot, a SaaS analytics/monitoring provider. The attackers then issued an extortion demand, setting 14th April 2026 as the deadline and threatening to publish stolen data if payment in cryptocurrency wasn’t made.
ShinyHunters later said it had released the data and told Reuters it stole 78.6 million records, while Rockstar told the BBC that only a limited amount of “non-material company information” was accessed and that there was no impact on its organisation or players.
The Cybercrime group ShinyHunters have claimed to be responsible for many other high profile attacks including Instructure at the beginning of May 2026 where this specific “cyber attack affected an estimated 9,000 institutions in the US, Canada, Australia and the UK, with exams disrupted after the Canvas service went down”. Also, they are responsible for other breaches like Google, AT&T Wireless, Ticketmaster and SoundCloud.
This incident also lands in the shadow of an earlier, widely reported Rockstar breach a few years before, in which the attacker stole and leaked internal materials related to GTA 6, including video clips of an unfinished build. The individual, known online as “TeaPot”, alleged that they were able to access Rockstar Games’ internal Slack messages and early code for the upcoming Grand Theft Auto title through the misuse of an employee’s credentials.
The attacker in questions was a key member of international gang Lapsus$. Some other attacks by the gang were on Uber, Revolut, Nvidia and BT/EE. Rockstar Games stated in court hearings that the hack cost them $5m to recover from plus thousands of hours of staff time.
Breaking Down the Two Major Attacks on Rockstar Games
In this section, we’ll explore the two major cyber attacks that affected Rockstar Games. First, an internal network breach that led to the theft of company data including valuable intellectual property (IP) and the second, a supply chain attack. These incidents demonstrate the different ways attackers can target an organisation.
When the Crown Jewels Are Stolen: Why IP Matters
The theft of Rockstar Games’ Grand Theft Auto VI development data demonstrates that not all cyber attacks focus on customer or financial information. In many organisations, intellectual property (IP) is just as valuable as personal data. IP can include source code, product designs, research, formulas, business processes and future product plans that give a company its competitive advantage.
For Rockstar Games, the leaked development footage and source code represented years of investment and innovation. While the attack did not expose customer data, it targeted the company’s “crown jewels” the assets that help differentiate its products from competitors. The premature disclosure of this information risked damaging marketing plans, revealing proprietary development processes and affecting the commercial success of a highly anticipated product.
This type of risk extends far beyond the gaming industry. Pharmaceutical companies rely on confidential research and drug formulas, manufacturers protect proprietary production techniques and technology firms depend on source code and product roadmaps. If these assets are stolen, competitors, cyber criminals or nation-state actors may gain insights that undermine a company’s unique selling proposition (USP), reduce its competitive advantage and potentially cause significant financial and reputational damage.
The Rockstar incident serves as a reminder that organisations must identify and protect their most valuable digital assets, not just personal or financial data. For many businesses, their intellectual property is the foundation of their success and therefore a prime target for attackers.
Supply Chain Attacks: A Persistent and Growing Risk
Supply chain attacks have become one of the most widely discussed topics in cyber security, largely because of the number of high-profile incidents that continue to make headlines. Despite the attention they receive organisations are still frequently compromised through trusted third parties, demonstrating that supply chain security remains a significant challenge across all industries.
What makes these attacks particularly effective is that attackers often exploit weaknesses in suppliers rather than targeting the primary organisation directly. In many cases, a “back to basics” approach to cyber security (such as strong access controls, multi-factor authentication (MFA), regular patching and robust monitoring) could significantly reduce the likelihood of a successful attack. While these measures may seem simple, they are often overlooked or inconsistently applied across supplier networks.
The Rockstar incident highlights the importance of understanding the risks introduced by third-party relationships. Organisations should conduct regular supplier risk assessments to evaluate how their vendors manage cyber security, what data they can access and whether appropriate security controls are in place. By identifying and addressing weaknesses within the supply chain, businesses can reduce their exposure to attacks that originate outside their direct control.
Ultimately, supply chain attacks are a reminder that an organisation’s security is only as strong as that of the partners and suppliers it trusts.
Rockstar Games’ experiences illustrate how modern threat actors can exploit different attack vectors and target various organisational assets. The attacks ranged from compromises involving trusted third-party relationships to attacks aimed at stealing high-value intellectual property often regarded as the company’s “crown jewels”.
These incidents highlight the importance of taking a holistic approach to cyber security, one that not only protects customer data but also safeguards critical business assets and manages supplier risk. While cyber threats continue to evolve organisations that focus on strong security fundamentals, regular risk assessments and the protection of their most valuable information will be better positioned to reduce their exposure and respond effectively when incidents occur.
Cyber Risk Assurance with vSOC Assure
The lessons from Rockstar Games are clear: organisations must protect not only their data, but also their suppliers, business processes and intellectual property. At Data Connect, our Cyber Risk Management service, vSOC Assure, helps organisations identify potential weaknesses across their attack surface, understand the risks that leave you the most vulnerable and prioritise actions that improve security and resilience.
By working closely with both IT teams and board-level stakeholders, we help bridge the gap between technical security challenges and strategic business risk, ensuring cyber risks are understood and managed across the organisation. By taking a proactive, risk-based approach, businesses can reduce their exposure to the types of attacks that continue to make headlines.
If you would like to discuss your cyber strategy, please get in contact today.
