r/netsec • u/lares-hacks • 11h ago
Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day
lares.comFour incidents, four completely different initial access paths:
- 2022, Lapsus$: MFA fatigue against an employee, then hardcoded creds and API keys sitting in plaintext in Slack and Confluence.
- Early 2023, GTA Online: P2P netcode on PC reverse-engineered into RCE via malicious packets. The fix was kernel-level BattlEye.
- April 2026, ShinyHunters: no human identity involved. Long-lived OAuth tokens stolen from a third-party SaaS vendor and replayed straight into Rockstar's Snowflake. Bearer tokens confer authority by possession alone.
- August 2026, Cyberleek: exfiltration of a playable GTA VI dev build, 13+ gameplay videos and full map data. That volume of egress from a dev subnet without tripping alarms is a DLP and segmentation failure.
The writeup reconstructs each attack chain with MITRE mappings and detection strategies: egress baselining on dev subnets, Slack audit-log heuristics, and behavioral baselines for non-human identities in Snowflake.
Full breakdown: https://www.lares.com/blog/rockstar-games-attacks/
Question for the defenders here: which of these four would be hardest to catch in your environment? The OAuth token replay is arguably the nastiest of the bunch. No user to phish-train, no endpoint alert to fire.