Rockstar Games Snowflake Breach: Inside the ShinyHunters’ Anodot Hack Threatening a 165-Victim Supply Chain

On On **April 11, 2026**, the ShinyHunters hacking collective posted a chilling ultimatum on its dark web leak site claiming: “**Rockstar Games! Your Snowflake instances were compromised thanks to Anodot.** Pay or leak by **April 14, 2026**.”com. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak… Make the right decision, don’t be the next headline.” The message marked the latest high-profile strike by one of the most prolific data extortion groups in cybersecurity history, and it landed squarely on the publisher behind the most anticipated game release of the decade: Grand Theft Auto VI.

The Rockstar Games Snowflake breach is not an isolated incident. It represents the latest evolution of a supply chain attack pattern that has already compromised 165 organizations through Snowflake credential theft since 2024, exposing hundreds of millions of records from companies including Ticketmaster, AT&T, and Santander. This time, the attack vector was Anodot, a cloud analytics provider acquired by Glassbox in 2025, whose compromised connectors gave attackers a backdoor into Rockstar’s data warehouse.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What Happened: The Rockstar Games Snowflake Breach Timeline

The attack unfolded over a 10-day window that exposed fundamental weaknesses in third-party cloud security. On April 4, 2026, Anodot reported service outages affecting its connectors for Snowflake, Amazon S3, and Amazon Kinesis. At the time, the disruption appeared routine. Data collectors went offline, and Anodot’s status page noted intermittent connectivity issues across multiple cloud integrations.

What Anodot did not disclose at the time was that the outages coincided with unauthorized access to authentication tokens stored within its platform. ShinyHunters exploited these tokens to gain what appeared to be legitimate access to Rockstar Games’ Snowflake data warehouse instances. Once inside, the attackers used standard database query operations to exfiltrate data, a technique specifically designed to evade detection by blending with normal analytical workloads.

By April 11, ShinyHunters published its extortion demand on its dark web leak site. The group gave Rockstar a three-day deadline to make contact and negotiate payment. On April 13, Rockstar Games confirmed the incident to Kotaku, stating: “We can confirm that a limited amount of non-material company information was accessed in connection with a third-party data breach. This incident has no impact on our organization or our players.”

The April 14 deadline passed without a confirmed leak, though cybersecurity researchers continue to monitor ShinyHunters’ channels for any data dumps. The scope of the stolen data remains unclear, though Rockstar’s characterization of it as “non-material” suggests the breach may not have reached player databases or source code repositories.

Who Are ShinyHunters: From 200 Million Stolen Records to a Global Extortion Empire

ShinyHunters is not a newcomer to the cybersecurity threat landscape. The financially motivated hacking collective formed in 2019 and gained notoriety in 2020 after stealing over 200 million records from 13 companies in rapid succession. Early targets included Indonesian e-commerce giant Tokopedia (91 million records), Indian education platform Unacademy (10 million accounts), and photo editing service Pixlr (1.9 million records).

Who Are ShinyHunters: From 200 Million Stolen Records to a Global Extortion Empire

The group’s tactics have evolved significantly since those early days. According to Google Cloud’s Mandiant threat intelligence unit, ShinyHunters has shifted from simple database exfiltration to sophisticated social engineering campaigns that combine AI-enabled voice phishing (vishing) with targeted exploitation of SaaS platforms. A January 2026 report from Google Cloud documented how ShinyHunters-branded operations were using victim-branded phishing sites to steal credentials from cloud-based SaaS applications.

The group’s most devastating campaign came in 2024, when it orchestrated the Snowflake credential theft wave that Mandiant identified as affecting up to 165 organizations. High-profile victims included Ticketmaster (over 560 million records with personal and payment data), AT&T (110 million wireless customer records), and Santander (30 million customers across Chile, Spain, and Uruguay). The attacks exploited stolen credentials from infostealer malware targeting accounts that lacked multi-factor authentication.

Security researcher Brian Krebs reported in February 2026 that ShinyHunters has effectively merged operations with Scattered Spider and Lapsus$, forming a consolidated threat group known as Scattered Lapsus ShinyHunters (SLSH). This merged entity employs increasingly aggressive extortion tactics, including threats of physical violence against corporate executives, distributed denial-of-service attacks, and swatting.

The Anodot Attack Vector: How a Cloud Analytics Tool Became a Backdoor

The breach’s most significant technical detail is the attack vector: Anodot, an AI-driven cloud analytics and business monitoring platform. Founded in 2014, Anodot specializes in real-time anomaly detection and cloud cost management, serving enterprise customers including Atlassian, T-Mobile, UPS, Vimeo, Nordstrom, Amdocs, NICE, and CyberArk. The company raised $62.5 million in total funding, including a $35 million Series C round in 2021 led by Intel Capital with participation from SoftBank Ventures Asia and Samsung NEXT.

In late 2025, Glassbox, a digital experience analytics provider, acquired Anodot to bolster its monitoring capabilities. The acquisition appears to have created a transitional period in which security oversight may have lapsed. According to HackRead’s analysis, ShinyHunters exploited Anodot’s connectors, specifically the integrations that link Anodot’s monitoring tools to customer cloud environments including Snowflake, Amazon S3, and Amazon Kinesis.

“The Anodot vector is particularly concerning because it represents a class of third-party SaaS integrations that most security teams do not adequately monitor,” said Jake Williams, a former NSA hacker and cybersecurity consultant. “These analytics platforms require broad read access to function, and that access becomes a liability when the platform itself is compromised.”

The attack methodology was designed for stealth. Rather than deploying malware or exploiting zero-day vulnerabilities, ShinyHunters used the stolen authentication tokens to execute standard database operations. This approach made the unauthorized access virtually indistinguishable from legitimate analytical queries, delaying detection until the group revealed itself through its extortion demand.

The Snowflake Breach Pattern: 165 Organizations and Counting

The Rockstar Games breach follows a well-established pattern of attacks targeting Snowflake customer environments. In June 2024, Mandiant reported that up to 165 Snowflake customers were potentially exposed in a coordinated data exfiltration campaign conducted by UNC5537, the threat actor designation that overlaps with ShinyHunters. Snowflake itself was not breached; rather, attackers exploited individual customer accounts that lacked multi-factor authentication, using credentials harvested by infostealer malware.

Snowflake Breach VictimYearRecords ExposedData TypeAttack Vector
Ticketmaster (Live Nation)2024560 millionPersonal and payment dataStolen credentials
AT&T Wireless2024110 millionCall records and phone numbersStolen credentials
Santander202430 millionCustomer and employee dataStolen credentials
Advance Auto Parts20242.3 millionNames, SSNs, driver’s licensesStolen credentials
LendingTree2024UndisclosedFinancial customer dataStolen credentials
Rockstar Games2026Undisclosed“Non-material company info”Anodot compromise

The Cloud Security Alliance published an analysis noting that companies affected by the 2024 Snowflake breaches reported up to $3 million in non-material financial consequences, though material impacts on equity and stock prices were also documented. Following the 2024 wave, Snowflake implemented mandatory multi-factor authentication for all accounts and enhanced its credential monitoring systems, but the Rockstar breach demonstrates that the threat has shifted from direct credential theft to compromising third-party integration partners.

Rockstar Games’ Cybersecurity Track Record: A Pattern of Breaches

The April 2026 breach is not Rockstar Games’ first encounter with sophisticated hackers. In September 2022, a 17-year-old hacker affiliated with the Lapsus$ group, which has documented ties to ShinyHunters, gained access to Rockstar’s internal Slack channels and Confluence pages. The attacker leaked over 90 videos of early Grand Theft Auto VI development footage, forcing Rockstar to publicly confirm the game’s existence ahead of schedule. The breach was one of the most significant leaks in gaming history and led to criminal charges against the attacker.

Rockstar Games' Cybersecurity Track Record: A Pattern of Breaches

Rockstar’s parent company, Take-Two Interactive, has invested heavily in cybersecurity since the 2022 incident. However, the Anodot-vectored attack highlights a persistent blind spot: no amount of internal security hardening can fully protect against compromised third-party vendors with legitimate access to cloud environments.

“The gaming industry has become one of the top targets for data extortion groups because these companies hold enormously valuable intellectual property and have massive user bases,” said Charles Carmakal, Mandiant’s Chief Technology Officer. “The Rockstar breach through Anodot shows that even companies with sophisticated security programs remain vulnerable to supply chain compromises.”

The GTA VI Factor: Why This Breach Carries Billion-Dollar Stakes

The timing of the breach is particularly significant given that Grand Theft Auto VI remains on track for its anticipated 2026 release. GTA V generated over $8 billion in lifetime revenue, making it one of the most commercially successful entertainment products in history. Industry analysts have projected that GTA VI could generate between $1 billion and $3 billion in first-year sales alone, based on the franchise’s trajectory and the extended development cycle.

Any breach that threatens to expose source code, development assets, or internal communications carries outsized risk for Rockstar. The 2022 Lapsus$ leak, which included early GTA VI footage, prompted widespread speculation about the game’s features and quality that the studio was forced to manage publicly. A second major breach, even one Rockstar characterizes as involving “non-material” information, raises questions about whether the company’s security posture is adequate to protect what may be the most valuable unreleased entertainment product in the world.

“Rockstar calling this ‘non-material’ is a carefully chosen legal term,” said Katie Moussouris, founder and CEO of Luta Security and a pioneer in bug bounty programs. “It signals they don’t believe the stolen data will trigger SEC disclosure requirements for Take-Two. But for a company sitting on GTA VI, any breach creates reputational risk that can affect pre-orders, investor confidence, and partnership negotiations.”

Gaming Industry Under Siege: A Wave of Cyberattacks Since 2023

The Rockstar breach fits into a broader pattern of cyberattacks targeting the gaming industry. Since 2023, major studios have faced an escalating series of breaches that have exposed source code, player data, and internal development plans.

CompanyYearAttack TypeImpactThreat Actor
Insomniac Games (Sony)2023Ransomware1.67 TB stolen; Wolverine assets leakedRhysida
Rockstar Games2022Social engineering90+ GTA VI dev videos leakedLapsus$
Riot Games2023Social engineeringLeague of Legends source code stolenUnknown
Activision2023PhishingEmployee data and game plans exposedUnknown
Roblox2023Data breachInternal documents leakedUnknown
Rockstar Games2026Supply chain (Anodot)“Non-material” company data accessedShinyHunters

The pattern is clear: gaming companies are high-value targets because they combine massive user databases, valuable intellectual property, and complex supply chains of third-party tools and services. The industry’s rapid adoption of cloud-based development pipelines and SaaS analytics platforms has expanded the attack surface significantly.

The Supply Chain Problem: Why Third-Party SaaS Is the New Attack Surface

The Rockstar breach through Anodot exemplifies a growing cybersecurity challenge: the exploitation of third-party SaaS integrations as attack vectors. Modern enterprises typically connect dozens or hundreds of SaaS platforms to their core infrastructure, each with its own authentication tokens, API keys, and data access permissions. When any single vendor in this chain is compromised, the attacker inherits that vendor’s access privileges.

The Supply Chain Problem: Why Third-Party SaaS Is the New Attack Surface

EclecticIQ analysts assessed with high confidence in a September 2025 report that ShinyHunters was expanding its operations by combining AI-enabled voice phishing with targeted exploitation of SaaS integrations. The group’s playbook has evolved from stealing individual user credentials to compromising entire service providers, effectively turning legitimate business tools into attack infrastructure.

“We are seeing a fundamental shift in how data extortion groups operate,” said Sandra Joyce, Vice President of Mandiant Intelligence at Google Cloud. “Instead of targeting companies directly, they target the SaaS tools those companies depend on. One compromised vendor can give you access to hundreds of downstream customers. It is a force multiplier that makes traditional perimeter security irrelevant.”

This pattern mirrors broader trends in cybersecurity threats in 2026, where supply chain attacks have become one of the most effective and difficult-to-defend vectors. The North Korea-linked Axios npm supply chain attack that affected 100 million downloads demonstrated that even widely trusted open-source tools can be weaponized, while the Stryker cyberattack showed how compromised device management platforms can cause widespread damage.

Expert Analysis: What the Breach Reveals About Cloud Security in 2026

Cybersecurity experts are divided on the long-term implications of the Rockstar breach, but there is broad consensus that third-party cloud integrations represent a systemic vulnerability that the industry has not adequately addressed.

“The Snowflake breach wave of 2024 should have been the wake-up call,” said Troy Hunt, security researcher and creator of Have I Been Pwned. “The fact that we are still seeing breaches through third-party cloud connectors two years later tells you that most companies have not fundamentally changed how they manage vendor access. They patch the immediate vulnerability, add MFA, and move on without addressing the architectural problem.”

The architectural problem Hunt references is the proliferation of SaaS integrations with persistent access to sensitive data stores. A typical enterprise Snowflake deployment may have connections to dozens of analytics, monitoring, and ETL tools, each with service account credentials that are rarely rotated and inconsistently monitored. The Anodot compromise demonstrated that a single breached connector can expose an organization’s entire data warehouse.

Following the 2024 breach wave, Snowflake implemented mandatory multi-factor authentication and enhanced its Trust Center with new credential monitoring capabilities. However, these measures primarily protect against direct credential theft. The Anodot vector represents a different threat model: the compromise of a trusted third-party application that already has authenticated access.

Take-Two Interactive: Financial Implications and Investor Response

As Rockstar Games’ parent company, Take-Two Interactive faces the most immediate financial scrutiny from the breach. The company’s characterization of the stolen data as “non-material” appears designed to avoid triggering SEC disclosure obligations under the updated cybersecurity incident reporting rules that took effect in December 2023, which require public companies to disclose material cybersecurity incidents within four business days.

The timing is sensitive for Take-Two. The company has been preparing for what analysts expect to be its most significant product launch ever with GTA VI. Any security incident that raises questions about Rockstar’s ability to protect its intellectual property or player data could affect investor sentiment during a critical pre-launch period.

The broader market context matters as well. The $96 billion cybersecurity M&A consolidation wave reflects how seriously the industry is taking data protection, while companies across the tech sector are being forced to reassess their security postures in the wake of increasingly sophisticated attacks.

How ShinyHunters Evolved: The AI-Powered Extortion Playbook

The ShinyHunters operation in 2026 bears little resemblance to the group that emerged in 2020 by scraping unsecured cloud storage buckets. Today’s ShinyHunters is a sophisticated, multi-capability threat actor that uses artificial intelligence, social engineering, and deep knowledge of enterprise cloud architectures.

How ShinyHunters Evolved: The AI-Powered Extortion Playbook

According to Google Cloud’s January 2026 threat intelligence report, ShinyHunters-branded operations now deploy AI-generated voice calls to impersonate IT support staff, creating victim-branded phishing sites that are nearly indistinguishable from legitimate corporate portals. The group targets identity systems, API keys, and third-party integrations, preferring data exfiltration and extortion over encryption-based ransomware.

The merger with Scattered Spider and Lapsus$ has further enhanced the group’s capabilities. Krebs on Security documented how the combined Scattered Lapsus ShinyHunters (SLSH) entity employs a broader range of coercive tactics, including physical threats against corporate executives and their families. This escalation reflects the increasing professionalization of cybercrime, where groups compete for territory, share tools and techniques, and consolidate operations for greater impact.

The Rockstar breach also highlights how the group has moved up the value chain from targeting individual companies to targeting the SaaS platforms those companies depend on. By compromising Anodot, ShinyHunters potentially gained access not just to Rockstar but to every organization that used Anodot’s cloud monitoring integrations with Snowflake.

Defensive Lessons: What Organizations Should Do Now

The Rockstar breach offers several actionable lessons for organizations that depend on third-party SaaS integrations for cloud analytics and monitoring.

First, organizations must audit and minimize the access privileges granted to third-party analytics platforms. Tools like Anodot require broad read access to function, but that access should be scoped to specific data sets rather than entire warehouse environments. Implementing the principle of least privilege for SaaS integrations is no longer optional.

Second, authentication token management for third-party integrations needs to match the rigor applied to human user accounts. Service account credentials for SaaS connectors should be rotated on regular schedules, monitored for anomalous usage patterns, and immediately revoked if a vendor reports a security incident.

Third, organizations need to treat vendor security incidents as potential breaches of their own environments. When Anodot reported its April 4 outages, customers should have immediately reviewed their Snowflake access logs for any unusual query patterns. The 7-day gap between the initial Anodot outage and ShinyHunters’ public extortion demand represents a missed detection window.

Security researchers studying similar supply chain compromise patterns, including the Claude Code source leak and the GPUHammer GPU vulnerability, have noted that detection capabilities for third-party integration abuse remain significantly underdeveloped across the industry.

5 Predictions: What Comes Next After the Rockstar Breach

Based on the trajectory of ShinyHunters’ operations, the Snowflake breach pattern, and the broader cybersecurity landscape, several predictions emerge from this incident.

1. More Anodot-connected organizations will be disclosed as victims. ShinyHunters’ attack on Anodot likely exposed multiple customers beyond Rockstar. Expect additional breach disclosures in the coming weeks as affected organizations complete their forensic investigations. Anodot’s customer list includes enterprise brands across telecommunications, retail, and financial services.

2. Snowflake will face renewed regulatory scrutiny. Despite implementing mandatory MFA after the 2024 breach wave, the Rockstar incident demonstrates that Snowflake’s ecosystem remains vulnerable to third-party integration compromises. Expect regulators and enterprise customers to push for stricter controls on how third-party applications authenticate to Snowflake environments.

3. Cloud security vendors will launch SaaS integration monitoring products. The gap between how organizations monitor human user access and how they monitor third-party application access represents a significant market opportunity. Expect companies like CrowdStrike, Palo Alto Networks, and Wiz to accelerate product development in this area.

4. ShinyHunters will escalate its targeting of gaming companies. The group has now successfully targeted Rockstar twice (through Lapsus$ in 2022 and directly in 2026). Gaming companies hold both valuable IP and large user databases, making them ideal extortion targets. Expect other major studios to face similar campaigns.

5. Take-Two will disclose additional security investments ahead of GTA VI launch. The pre-release period for GTA VI is too commercially critical for Take-Two to leave security questions unanswered. Expect the company to publicly detail enhanced security measures in its next earnings call to reassure investors and pre-order customers.

The Bigger Picture: Supply Chain Attacks Are Redefining Cybersecurity

The Rockstar Games Snowflake breach is not just a gaming industry story. It is the latest data point in a trend that is fundamentally reshaping how organizations think about cybersecurity. Traditional security models assume that threats come from outside the perimeter, from attackers trying to break in. Supply chain attacks invert this model by compromising trusted tools that already have legitimate access inside the perimeter.

The Bigger Picture: Supply Chain Attacks Are Redefining Cybersecurity

The 165-organization Snowflake breach wave of 2024 demonstrated the scale of the problem. The North Korea-linked Axios npm attack showed that open-source software supply chains are equally vulnerable. And now the Rockstar breach through Anodot proves that even proprietary SaaS monitoring tools can become attack vectors.

For CISOs and security teams, the implication is clear: every third-party integration is a potential entry point. Every SaaS connector, every API key, every service account credential represents a link in a supply chain that attackers are increasingly skilled at exploiting. The organizations that avoid becoming the next headline will be the ones that apply the same zero-trust principles to their vendor integrations that they already apply to their human users.

Related Coverage

Frequently Asked Questions

What data was stolen in the Rockstar Games breach?

Rockstar Games described the stolen data as “a limited amount of non-material company information.” The company stated that the breach has “no impact on our organization or our players,” suggesting that player databases, financial data, and source code were not compromised. However, the full scope of the breach has not been independently verified.

How did ShinyHunters breach Rockstar Games?

ShinyHunters exploited Anodot, a third-party cloud analytics platform used by Rockstar Games. The attackers compromised Anodot’s authentication tokens, which provided access to Rockstar’s Snowflake data warehouse instances. They used standard database query operations to exfiltrate data, making the unauthorized access difficult to distinguish from legitimate analytical workloads.

Is player data from GTA Online or Red Dead Online at risk?

Based on Rockstar’s public statement, player data was not affected by the breach. The company explicitly stated that the incident has “no impact on our players.” However, players should monitor their accounts for any unusual activity and enable two-factor authentication as a precaution.

What is Anodot and why was it a target?

Anodot is an AI-driven cloud analytics and business monitoring platform that specializes in real-time anomaly detection and cloud cost management. It was acquired by Glassbox in 2025. Anodot was a target because its connectors have authenticated access to customer cloud environments including Snowflake, Amazon S3, and Amazon Kinesis, making it a high-value supply chain target.

Will the breach affect GTA VI’s release?

There is no indication that the April 2026 breach will affect GTA VI’s anticipated 2026 release schedule. Rockstar characterized the stolen data as non-material and unrelated to game development. However, any security incident adds complexity to the pre-launch period and may prompt additional security reviews.

How many companies has ShinyHunters breached?

ShinyHunters has been linked to breaches affecting hundreds of organizations since its formation in 2019. The group’s most significant campaign targeted 165 Snowflake customers in 2024, including Ticketmaster (560 million records), AT&T (110 million records), and Santander (30 million customers). The group has stolen over 200 million records from at least 13 companies in its early operations alone.

Nadia Dubois

Nadia Dubois

AI & Innovation Editor

Nadia Dubois is the AI & Innovation Editor at Tech Insider, where she tracks the rapid evolution of artificial intelligence, from foundation models to real-world enterprise deployment. She previously covered AI and startups for La Tribune and contributed to MIT Technology Review's European coverage. Nadia specializes in generative AI, AI regulation, and the intersection of technology and European industrial policy. She holds a dual degree in Computational Linguistics and Journalism from Sciences Po Paris.

View all articles