❌

Reading view

Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day

Four incidents, four completely different initial access paths:

  • 2022, Lapsus$: MFA fatigue against an employee, then hardcoded creds and API keys sitting in plaintext in Slack and Confluence.
  • Early 2023, GTA Online: P2P netcode on PC reverse-engineered into RCE via malicious packets. The fix was kernel-level BattlEye.
  • April 2026, ShinyHunters: no human identity involved. Long-lived OAuth tokens stolen from a third-party SaaS vendor and replayed straight into Rockstar's Snowflake. Bearer tokens confer authority by possession alone.
  • August 2026, Cyberleek: exfiltration of a playable GTA VI dev build, 13+ gameplay videos and full map data. That volume of egress from a dev subnet without tripping alarms is a DLP and segmentation failure.

The writeup reconstructs each attack chain with MITRE mappings and detection strategies: egress baselining on dev subnets, Slack audit-log heuristics, and behavioral baselines for non-human identities in Snowflake.

Full breakdown: https://www.lares.com/blog/rockstar-games-attacks/

Question for the defenders here: which of these four would be hardest to catch in your environment? The OAuth token replay is arguably the nastiest of the bunch. No user to phish-train, no endpoint alert to fire.

submitted by /u/lares-hacks
[link] [comments]
  •  
❌