惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
人人都是产品经理
人人都是产品经理
小众软件
小众软件
博客园 - Franky
WordPress大学
WordPress大学
Jina AI
Jina AI
Google DeepMind News
Google DeepMind News
I
InfoQ
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
博客园 - 【当耐特】
IT之家
IT之家
G
Google Developers Blog
J
Java Code Geeks
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
云风的 BLOG
云风的 BLOG
Recent Announcements
Recent Announcements
有赞技术团队
有赞技术团队
V
Visual Studio Blog
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
GbyAI
GbyAI
雷峰网
雷峰网

Business Insights

The New AI Arms Race Starts Before the Attack Bitdefender Threat Debrief | September 2026 Why Are So Many Security Professionals Keeping Breaches Quiet? Everyone Says Security Consolidation Saves Money. Four Organizations Did the Math The Next MDR Evolution: Digital Sovereignty, Trusted AI, Continuous Protection SilkParasite: Tracking a China-Nexus APT Across Central Asia Frontier AI and the Changing Dynamics of Cybersecurity Bitdefender Threat Debrief | August 2026 Rapidly Rising Risk: AI in the Shadows GravityZone Achieves Top Results in AV-Comparatives Testing When Visibility Becomes the Target: Bitdefender at Black Hat USA 2026 Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core Bitdefender Recognized as a Major Player in the 2026 IDC MarketScape for Worldwide MDR Service for Midmarket Are You Falling for the Privacy Illusion? What’s New in GravityZone July 2026 (v 6.75) Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR Bitdefender Threat Debrief | July 2026 Trust Under Attack: How Deepfakes Are Rewriting Cybercrime Your AI SOC Won’t Catch Ransomware by Itself 2026 Cybersecurity Assessment: The Gap Between Knowing and Doing Your Last Red Team Tested the Wrong Attack MSP Strategic Defense: Why MDR Is the New Security Baseline for MSPs Technical Advisory: FortiBleed Credential Exposure Campaign Targeting Internet-Facing Fortinet Devices Bitdefender Recognized in the 2026 Gartner® Europe Context: Magic Quadrant™ for Endpoint Protection CISA Mandates Change for Structured, Prioritized Updates and Vulnerability Management Claimed Twice: Five Reasons the Same Ransomware Victim Shows Up Under Two Flags What’s New in GravityZone June 2026 (v 6.74) Bitdefender Threat Intelligence: Built for How Security Teams Work Bitdefender Threat Debrief | June 2026 Cut Complexity in Half While Reducing Risk Across Your Endpoint Environment
CyberLeek: Extortion Built for an Audience, Not a Victim
Jade Brown · 2026-09-01 · via Business Insights

CyberLeek positions itself as a financially motivated extortionist group, taking part in the theft of data and intellectual property to intrigue an audience and grow potential revenue streams in the process.

The recent CyberLeek operation, backed by a message ofNo Disc, No Peace puts on the appearance that the threat actor advocates for gamers everywhere, despite self-serving motives. 

For Grand Theft Auto (GTA) fans, 2026 is big. Fans have been waiting for more than four years for the new release, GTA VI, to become available in November. Months ahead of that timeline, in mid-August, CyberLeek published leaked scenes and gameplay consisting of Grand Theft Auto (GTA) VI material spanning twelve gameplay subjects, including a mix of old and new content.

Leaked videos and images featured a hypercar, plane, taser scene, junkie, nudist town, a basketball video, and map sneak peeks. A video tied to the group was also distributed online which established that they apparently have a GTA VI build in their possession and could potentially spoil the ending of the game.

On the group’s leak site, it claims this is CberLeek’s effort to push back against corporate profits in the gaming industry.

The Gaming Leaks Precedent

This GTA VI leak may come as a surprise, however this is not the first leak of its kind. GTA VI has been in development since early 2022, making it a highly anticipated installment. In 2022, LAPSUS$ targeted several video game developers and also orchestrated a leak that consisted of 90 GTA VI video clips in addition to segments of the game source code. No connection has been drawn between LAPSUS$ and CyberLeek to date, but there is a precedent for this type of gaming leak.

Grand Theft Auto is known for having an open, heavily involved mapping community. These are groups spread across Discord communities, gaming marketplaces, and gaming related sites. that develop and share custom maps and game modifications. Mappers share unique updates and locations within servers and some use these builds to generate income, selling access to certain models or blocking them behind a paywall. That creates a customer base for CyberLeek, as some mappers might want to leverage any games or map leaks.

The Operation and CyberLeek Manifesto

CyberLeek operates differently than conventional extortion groups; it has not sought financial payment from the victim organization to prevent further leaks. There is also no evidence of the use of any encryptors or ransom demands in the group’s operations. No initial access vector, execution chain, persistence mechanism, privilege escalation path, lateral movement method, or command and control infrastructure have been documented either.

However, we do know CyberLeek maintains a community called Leek Road on their dedicated site. The high demand for GTA VI makes it essential for them to maintain this community (and a presence elsewhere) to keep others interested in their activities. Nearly a week after the GTA VI leak, CyberLeek 2.0 was launched.

leek-road-image1

Image: CyberLeek's online community called Leek Road.

CyberLeek’s manifesto, featured on Leek Road, calls for an ‘open road’ to share games with the masses, along with an anti-licensing, player-first belief system. This type of dogma appeals to a wide audience of sympathizers and consumers across the gaming community.

Throughout 2026, some gamers have expressed discontent with the gaming experience and industry, voicing concerns over the rising cost of video games (like the $999.99 cost for GTA VI’s ultimate edition), the move from the possession of physical media to digital, and widespread delays from the development to the production and distribution of finished games. Here’s a small portion of the group’s manifesto:

leek-road-image2

Image: A final message from CyberLeek's manifesto.

CyberLeek also promotes the use of cryptocurrency tokens to its audience through polls; tokens are sent to wallet addresses, and addresses for topics that generate the most tokens are prioritized for future leaks. While documentation of the revenue CyberLeek has collected so far through this polling process is absent, it is a creative way to monetize leaks and ensure audiences engage with the content.

CyberLeek’s Presence Online

Excluding the dedicated data leak site, CyberLeek also maintains a Telegram channel named CyberLeek Official. While the channel dates back to late 2024, its first victim publication referencing a specific leak did not emerge until August 2026, which is highly unusual. However, at the time of this release, there are more than 28,0000 members.

Numerous Telegram channels have also emerged, making it difficult to uncover CyberLeek’s other platforms despite ongoing reports of violations of Telegram’s terms of service. While multiple X accounts have popped up with handles and derivations of the CyberLeek name, none have been validated as official media outlets connected to the group.

The Opportunity

CyberLeek positions itself as a financially motivated extortionist group, laying the groundwork for a monetization operation. A phased leak of GTA VI content has allowed CyberLeek to build up their brand name, stay relevant, and potentially profit from future leaks containing greater volumes of sensitive information. Consider this: CyberLeek possesses not only video content, but also a developer build. Why stop there?

Members and interested sympathizers can serve as the channel to receive modified game add-ons, trade platform currencies and other services, and promote memecoins—all avenues that can lead to profit without needing a negotiation plan or process to haggle with the affected organization.

What the group monetizes is attention. The source material supports several revenue streams running in parallel: the leaked content itself, derivative and modified versions of that content, opportunities to trade in platform and adjacent services connected to the property, group-promoted cryptocurrency tokens, and paid advertising placement alongside the leaks themselves. CyberLeek has already promoted opportunities for buyers to acquire advertising space for upcoming projects where additional leaks are published,  with one sponsorship priced at $165,000.

If we contrast this type of approach with traditional ransomware or data exfiltration, we see the economic model does not decay when a victim refuses to engage or pay. For CyberLeek, refusal is content: it extends the story, gives the group something to post about, and keeps the audience present for the next release. This rang true even amid the official extended look at GTA VI released at the end of August.

Considerations for Organizations

Organizations whose incident response assumes that refusing to negotiate ends an intellectual property matter are positioned to fail when combating an operational model like the one CyberLeek uses.

Large, consumer-facing organizations with intellectual property have audiences waiting to get their hands on it before a breach becomes news. Entertainment and gaming properties sit at this juncture of desirable targets, with unreleased product designs, pre-launch assets, and other scripted content being the crown jewels.

This has consequences for organizations and defenders.

Most organizations are poor targets for CyberLeek’s model. Desirable targets should recognize that the material most likely to be exposed is not necessarily the material their data classification scheme rates as most critical. Classification schemes rank data by the damage its disclosure does to the organization. A threat actor like CyberLeek takes a different approach, as they may instead rank intellectual property based on projections of how many people want to see it, regardless of whether the design is finished or on the market.

A pre-release build also carries far less regulatory and contractual risk than distributing a customer database (and far more audience value), so it is often protected by the controls applied to ordinary internal files rather than controls applied to regulated data.

Two operational consequences follow, and both are worth understanding.

1. Distribution cost. Material an audience chooses to spread does not need infrastructure the group has to run, pay for, or defend against. Sympathetic framing converts followers into a distribution layer. Platform disruptions due to terms-of-service violations remove a node; they do not remove an audience.

2. The target’s response. A denial issued into a neutral information environment is received as a factual claim to be assessed. A denial issued into an audience that arrived with a prior grievance about the industry is received as a corporate statement to be discounted. This means an organization's communications teams may be tasked with competing against a framing established long before it spoke, putting them at a disadvantage despite their best efforts. A petition filed for subpoenas against entities distributing copyrighted material may also provoke sympathizers to side with the leaker regardless of whether all leaks have been verified.

For CyberLeek, authentic material and fabricated but convincing material produce the same outcome. Both draw the audience to the channel, both drive attention to the revenue surfaces, and both damage the claimed victim's position while the claim is being assessed.

Organizations preparing to defend against similar data breaches should assume that content can be fabricated, partially fabricated, or recycled. The distribution of recycled content amongst new updates is a plausible outcome, as unreleased development material connected to the same title was published without authorization in September 2022 by Arion Kurtaj, an individual associated with the Lapsus$ group. The 2022 material has circulated publicly and remains available, and no official authorization for its release has been documented.

Recommendations for Organizations

It is advised that organizations do the following if they identify suspicious behavior that follows the CyberLeek pattern:

  • Verify claims and evidence of stolen data. If the origin of any stolen material is unverified, keep in mind that audiences may be manipulated into accepting that material as authentic. As a result, containment should not be the next step if there is no evidence of an observed intrusion.

  • Build a capability to maintain an inventory of sources (for original and leaked data), a file control history, asset pipeline networks, and artifacts to understand when files may have been exposed and to separate new material from old. Hash material related to known exposures and keep catalogs of this material to date.

  • Ensure that planning to address media correspondence and legal action are sound before a suspicious event occurs. Hash and catalog material known to have been exposed. Deploy a capability to monitor BOTH the clearnet and closed communities for leaked material.

  • Do not implement a takedown strategy that is solely dependent on platform response. This should only be a last resort as it does not serve as a proactive action in a response plan. Ensure that any evidence is preserved before requesting the removal of material or channels. Prepare the request as a repeatable process against successor infrastructure rather than a single filing and decide in advance who monitors for reconstitution and how quickly the next request goes out.

Conclusion

Whether CyberLeek’s model is successful and can be reproduced by other threat actors remains to be seen. Three aspects are worth watching closely.

First, watch whether phased releases

continue on the schedule the group has implied, since staged disclosure is the mechanism the entire model depends on. An abandoned schedule suggests the inventory may have been thinner than claimed.

Second

, tracking whether an unrelated victim emerges could result in additional insights. An audience built over twenty-one months has grown, but nothing yet shows it transfers to the material of a different property. An efficient operational model would require that it does so to prevent CyberLeek from becoming stagnant. Third, let's see whether the audience survives repeated takedowns, despite CyberLeek’s portability, as pressure mounts to dismantle them. Duplicate or copycat accounts may also challenge the group’s operations going forward.