1. Executive summary
Malwarebytes reports that Take-Two Interactive subpoenaed Microsoft and Discord for identifying data associated with members of three Discord servers after an account calling itself CyberLeek published GTA 6 footage and map material. Requested data reportedly includes IP addresses, phone numbers, linked Google and Xbox accounts, OneDrive contents, Windows MachineGuid values and Microsoft account device IDs; compliance could expose hundreds or thousands of users with no known involvement in the leak. Separately, Malwarebytes identified fake “GTA 6 Extended Look” and demo sites leading visitors to password-stealing malware, creating a credible credential-theft lure for staff using corporate or personal devices. CyberLeek attribution is unconfirmed and the actor has no MITRE ATT&CK profile in the verified data; no CVE, CVSS severity or CISA KEV exploitation state applies to this item.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The supplied facts also do not establish an item-specific trigger under UK NIS 2018: UK Network and Information Systems Regulations — OES/RDSP duties: no client compromise or disruption to an OES/RDSP service is reported.
3. Technical analysis & attack chain
Source-reported sequence
On 17 August 2026, an account calling itself CyberLeek began publishing GTA 6 footage and disclosed part of the game map. The account claimed ideological motives centred on game preservation, digital-only releases and additional charges for single-player content. Its real identity, access method and relationship to the leaked material have not been established. CyberLeek has no MITRE ATT&CK profile in the verified reference data; attribution remains unconfirmed.
CyberLeek also promoted a $CYBERLEEK token on the Solana network, presented as a mechanism for holders to vote on future leaks. Malwarebytes reports that online commentators alleged a token-promotion motive, but that the operator subsequently burned its large holding while retaining the ability to collect trading fees reportedly reaching $60,000. No contract address, wallet address or transaction identifier is supplied, preventing independent blockchain validation from the available material.
On 20 August, Take-Two reportedly issued subpoenas to Microsoft and Discord covering data associated with three Discord servers from 1 June onward. One identified server belongs to GTA streamer DarkViperAU; the other two are not named. The requested records reportedly include:
- IP addresses and phone numbers.
- Linked Google and Xbox accounts.
- OneDrive contents for certain members.
- Windows
MachineGuidvalues, described by the source as identifiers for individual Windows installations. - Microsoft account device IDs identifying devices accessing Microsoft services.
Microsoft and Discord reportedly have until 4 September to respond. Disclosure has not been confirmed. The potential impact is therefore prospective legal-process disclosure rather than an established breach of Microsoft, Discord or affected users.
Malwarebytes separately reports finding fake “GTA 6 Extended Look” and demo sites leading visitors to password-stealing malware. Related lure themes include free early access, free in-game currency and unofficial mods. Genuine leaked footage could increase the credibility of those lures. The source does not identify the malware family, download mechanism, exploited product, payload filename, command line, persistence method, privilege-escalation path, command-and-control infrastructure or exfiltration protocol. It also provides no evidence connecting CyberLeek to these sites.
Historical context
Malwarebytes attributes a separate April incident involving 78.6 million Rockstar records to ShinyHunters, which has MITRE ATT&CK profile G1057. According to the report, ShinyHunters targeted cloud analytics provider Anodot, which held persistent authentication tokens for customer Snowflake environments, rather than directly compromising Rockstar’s internal systems. Possession of such tokens can permit account impersonation without re-entering a password. The source supplies no technical evidence linking that historical incident to CyberLeek or the August GTA 6 leak.
No vulnerability or CVE is identified in the current activity. CVSS: not applicable. CISA KEV: not applicable.
Confidence caveat
The subpoena scope, CyberLeek activity, token claims, malware-site discovery and historical Rockstar account are all derived from one supplied Malwarebytes report. These claims are single-sourced; verify before enforcement.
4. Mitigation & containment
P1 — within 24 hours
- Alert SOC, service-desk and web-security teams to the exact lure themes: “GTA 6 Extended Look”, downloadable GTA 6 demos, free early access, free in-game money and unofficial mods. Use these as investigation leads, not standalone blocking indicators.
- Prevent downloads from unofficial GTA-themed sites through existing secure-web-gateway and untrusted-download controls. Do not block domains or URLs without validation; none are supplied.
- If a user accessed a suspected site or received a malware alert, isolate the endpoint and preserve browser, proxy, DNS, download and EDR telemetry.
- From a known-clean device, reset credentials and revoke active sessions or persistent tokens for accounts used on the affected endpoint. Prioritise corporate identity, Microsoft, Google, Xbox and Discord accounts.
- Establish a confidential reporting route for personnel who belong to relevant GTA/Discord communities or receive notice that their data is within the subpoena scope. Server membership alone is not evidence of wrongdoing.
P2 — within 72 hours
- Correlate web and endpoint telemetry from the reported discovery period with subsequent credential-access alerts, unexpected authentication sessions or newly observed devices. Manually validate every match because the available lure terms are broad.
- For confirmed interaction, scope all credentials and browser sessions accessible from the endpoint, complete antimalware examination and rebuild the device if integrity cannot be established.
- Have legal and privacy teams validate the subpoena and affected-server scope through primary records if personnel report potential inclusion. Do not rely solely on the secondary report.
- Record whether exposed identifiers could connect personal Discord activity to corporate Microsoft, Google or Xbox identities.
P3 — within 7 days
- Reinforce policy prohibiting unofficial game demos, early-access downloads and mods on managed endpoints.
- Confirm browser protection, download inspection and application-control policies cover software obtained from unapproved sites.
- Where relevant, review third parties holding persistent authentication tokens for client Snowflake environments. Remove unnecessary tokens, restrict their scope and rotate retained credentials. This is hardening derived from the separate historical ShinyHunters account, not evidence of current Snowflake exposure.
- No product patch, version pin or vendor remediation is available because the source identifies no exploited vulnerability or affected software version.
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Visit to a site advertising a fake “GTA 6 Extended Look”, downloadable GTA 6 demo or free early access, followed by a malware-control alert | Secure web gateway, browser telemetry, DNS/proxy logs and EDR timeline | Medium; reported by one source, with no domain or payload artefact. Single-sourced; verify before enforcement |
| GTA-themed lure involving free in-game money or unofficial mods | Email security, browser history, web filtering and user reports | Low; broad scam theme rather than a campaign-specific indicator. Single-sourced; verify before enforcement |
6. Detection
Insufficient indicators to author detection rules.
Threat actor context
ShinyHunters · G1057 · aka UNC6240, Bling Libra
ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. ShinyHunters has targeted multiple industries and geographic regions gathering legitimate credentials and personally identifiable information (PII) for resale or extortion of victims. …
No MITRE ATT&CK profile for: CyberLeek.
7. Sources
- Malwarebytes, “GTA 6 leak hunt could expose data belonging to thousands of Discord users”, 25 August 2026.
- MITRE ATT&CK, ShinyHunters (G1057), accessed 25 August 2026.
8. Adverse Trace position
Adverse Trace assesses the current severity for EMEA financial-services clients as Low: no financial institution targeting, enterprise compromise or service disruption is established, and no CVE, CVSS severity or CISA KEV exploitation state applies. Risk increases for individuals included in the subpoena scope and for users who interact with GTA-themed malware lures; suspected execution should be handled as a credential-compromise event. CyberLeek attribution remains unconfirmed and the actor has no MITRE ATT&CK profile. The material is single-sourced; verify before enforcement. Adverse Trace will monitor for confirmed disclosure, corroborating reporting and validated malicious infrastructure or payload artefacts.
Published via PulseTrace — Adverse Trace threat intelligence.