Back to Blog
Cybersecurity April 14, 2026 5 min read

ShinyHunters Breaches Rockstar Games Through Third-Party SaaS, Releases Data After Ransom Refusal

Attackers stole credentials from cloud analytics vendor Anodot to access Rockstar's Snowflake account. The company refused to pay — ShinyHunters dumped the data on April 13.

ShinyHunters Breaches Rockstar Games Through Third-Party SaaS, Releases Data After Ransom Refusal

ShinyHunters breached Rockstar Games by compromising Anodot, a third-party cloud cost analytics platform the studio uses internally. Stolen authentication tokens from Anodot gave the attackers access to a connected Snowflake account containing internal company data. Rockstar refused to pay the ransom. ShinyHunters released the data on April 13 — the day before the stated deadline.

Rockstar confirmed the incident in a brief statement: “a limited amount of non-material company information was accessed.” No player account data, no source code, no GTA 6 assets in the leaked material, according to the company. The investigation is ongoing.

How the breach happened

The entry vector is becoming a pattern. ShinyHunters did not break into Rockstar directly. They compromised Anodot, a SaaS platform Rockstar used for cloud cost monitoring. Valid Anodot authentication tokens let the attackers move laterally into a connected Snowflake data warehouse — not through any Snowflake-side vulnerability, but through credential reuse and insufficient access controls between the two platforms.

This is the same technique ShinyHunters used in the 2024 Snowflake campaign that hit Ticketmaster, Santander, and AT&T. The attack surface is not the big-name target — it’s the smaller vendor with privileged access that no one audits as closely.

Why the timing matters

GTA 6 is heading toward its launch window. Any breach of Rockstar carries outsized industry attention because of what might be in play — code, release plans, internal communications. Rockstar’s statement that no material company data was accessed is measured, not emphatic. The company has strong reasons to keep the scope narrow publicly regardless of what was actually exfiltrated.

The 2022 GTA 6 leak, also via a third-party access path (Slack credentials), was one of the largest gaming leaks ever. ShinyHunters would know Rockstar’s threat surface attracts premium ransom expectations.

What organizations should take from this

Third-party SaaS vendors with access to your data warehouse are part of your attack surface. A Snowflake account connected to a cloud analytics tool inherits the security posture of that tool. The fix isn’t to avoid cloud analytics — it’s to treat every vendor integration as a potential breach vector:

  • Audit which third-party services have Snowflake, Databricks, or BigQuery access.
  • Use service accounts with minimal permissions and session timeouts.
  • Enable network policies on Snowflake accounts to restrict which IPs can initiate sessions.
  • Rotate credentials when a vendor has a security incident — assume your tokens were in scope.
  • Push vendors for SOC 2 Type II reports and ask about their incident detection capabilities.

Rockstar says no player data was exposed. Whether the internal documents ShinyHunters released include anything that matters ahead of GTA 6’s launch is a question the next few days will answer.

cybersecurity data-breach rockstar supply-chain