惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Securelist
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Tailwind CSS Blog
V
V2EX
小众软件
小众软件
博客园 - 聂微东
H
Help Net Security
阮一峰的网络日志
阮一峰的网络日志
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
M
MIT News - Artificial intelligence
人人都是产品经理
人人都是产品经理
F
Fortinet All Blogs
S
Schneier on Security
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Vercel News
Vercel News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Google DeepMind News
Google DeepMind News
Google Online Security Blog
Google Online Security Blog
Webroot Blog
Webroot Blog
A
Arctic Wolf
量子位
博客园 - 叶小钗
I
Intezer
C
Check Point Blog
Cloudbric
Cloudbric
IT之家
IT之家
Last Week in AI
Last Week in AI
GbyAI
GbyAI
Attack and Defense Labs
Attack and Defense Labs
T
The Blog of Author Tim Ferriss
Y
Y Combinator Blog
Jina AI
Jina AI
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
T
Threat Research - Cisco Blogs
C
CERT Recently Published Vulnerability Notes
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cisco Blogs
J
Java Code Geeks
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Engineering at Meta
Engineering at Meta
酷 壳 – CoolShell
酷 壳 – CoolShell
L
Lohrmann on Cybersecurity
有赞技术团队
有赞技术团队
Simon Willison's Weblog
Simon Willison's Weblog
The Register - Security
The Register - Security
T
Threatpost

Consumer Insights

South Korea diplomatic academy hack exposes diplomat data Credential stuffing attack at Chick-fil-A comes with data breach notice for customers Coca-Cola halts Fairlife production across US after ransomware attack Qantas data breach started with a fake IT support call Lidl warns customers after data breach How to find out if your identity has been exposed by infostealers Texas breach exposes PII of 3 million hunting and fishing license customers Maine forced to take down data breach portal after fake notices filed with authorities Carnival breach exposes data of nearly 6 million people 7-Eleven data breach exposes data of 185,000 people UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years DAEMON Tools Lite breach prompts urgent update after malware-laced installer Instructure confirms breach; millions of Canvas users potentially impacted Stalkerware data leak exposes private screenshots linked to celebrities and influencers Hackers claim to have breached Udemy, stealing 1.4 million user records Rituals data breach exposes customer details Booking.com says breach exposed travelers’ data Basic-Fit data breach exposes member information across Europe Lapsus$ claims AstraZeneca breach exposes code and credentials Aura data breach exposes 900,000 records after phishing attack Telus Digital data breach confirmed after ShinyHunters claims 1PB theft Was Your Data Exposed in the Latest Under Armour Breach? Here’s What You Should Do Breach at Tinder, Hinge and OkCupid exposes user data Europe Fines Big Tech €1.2 Billion under GDPR in 2025 European Space Agency's cybersecurity in freefall as yet another breach exposes spacecraft and mission data European Space Agency Confirms New Data Breach; Classified Info May Have Been Stolen Rainbow Six Siege Servers Offline After Massive Breach Floods Accounts with Billions of R6 Credits 21,000 Nissan Customers Exposed After Third-Party Server Breach Spotify Catalog Scraped, 300TB Music and Metadata Dumped via Torrent University of Sydney Confirms Data Breach Affecting Thousands Leroy Merlin Breach Alert: French Customers Notified After Cyberattack Exposes Personal Data CodeRED Emergency Alerts Disrupted Across US After Ransomware Breach
Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data
Vlad CONSTANTINESCU · 2026-04-14 · via Consumer Insights

Rockstar Games says a third-party breach exposed internal analytics data after ShinyHunters linked the incident to Anodot and Snowflake.

Key takeaways

  • Rockstar Games confirmed a data breach tied to a third-party incident rather than a compromise of its own systems
  • The ShinyHunters extortion gang claims it leaked more than 78 million records from analytics environments connected to Rockstar
  • Rockstar says the exposed information was limited and non-material and that the incident did not affect players or core operations
  • The leaked material appears to center on internal analytics, including online service monitoring, support metrics and business intelligence tied to GTA Online and Red Dead Online
  • The breach is part of a broader campaign linked to Anodot and Snowflake-connected environments, where stolen authentication tokens were allegedly used to access customer data
  • The incident highlights third-party integration risk, especially when cloud analytics tools have privileged access to operational datasets

Third-party breach pulls Rockstar into wider campaign

Rockstar Games has confirmed that company data was accessed in a breach tied to a third-party provider, after the ShinuHunters extortion gang listed the studio on its leak site. The incident appears connected to a broader wave of attacks involving stolen authentication tokens linked to Anodot, a SaaS analytics integration platform.

In a statement first shared with Kotaku, Rockstar said a “limited amount” of non-material company information was exposed and added that the incident had no impact on its organization or its players. Available reporting suggests internal business telemetry rather than customer account compromise.

What the leaked Rockstar data appears to contain

The stolen files appear to center on analytics used to monitor Rockstar’s online operations, including service performance, support workflows and internal business metrics, according to reporting on the leak. References reportedly point to Grand Theft Auto Online and Red Dead Online, with data tied to player behavior, revenue patterns and support analytics.

There were also reported signs of fraud-detection and anti-cheat testing data in the exposed material. Even if the company is accurate in describing the breach as non-material, those categories can still be valuable to threat actors because they reveal how a publisher measures abuse, monetization and platform health behind the scenes.

Snowflake and Anodot connection

The Rockstar breach is part of a broader campaign targeting customers in environments connected to a compromised third-party integration. Snowflake has said it detected unusual activity affecting a few customer accounts tied to such an integration and moved to lock down impacted environments and notify customers.

Snowflake later confirmed that Anodot was the third-party company at the center of that investigation.

Another reputational hit for Rockstar Games

For Rockstar, the breach revives uncomfortable memories of the 2022 intrusion that led to the leak of Grand Theft Auto VI material.

This time, however, the immediate message from the company is far more contained, as the leak allegedly didn’t impact players or disrupt operations and there is no sign that it includes consumer credentials.

Frequently asked questions (FAQ)

What happened in the Rockstar Games breach?

Rockstar Games confirmed that some company information was accessed in a third-party data breach after ShinyHunters claimed responsibility and listed the company on its leak site. Rockstar said the incident didn’t affect players or operations.

Was player data stolen in the Rockstar breach?

Based on Rockstar’s public statement and current reporting, there is no indication that player accounts or player-facing systems were affected. The company described the exposed information as non-material internal data.

Who is ShinyHunters?

ShinyHunters is a cybercrime group known for data theft, extortion and leak-site pressure tactics. In this case, the group claimed responsibility for the Rockstar incident and threatened to publish stolen information if its demands were not met.

Has Rockstar been breached before?

Yes. Material from Rockstar’s Grand Theft Auto VI was leaked in a major security incident in 2022. The latest breach is separate but it adds to the company’s history of high-profile cyber incidents.