Rockstar Games confirms data breach via Anodot-linked Snowflake access (ShinyHunters extortion)
Rockstar Games confirmed that a limited amount of non-material company information was accessed in a third-party data breach after ShinyHunters claimed it had reached the studio's Snowflake instances through stolen tokens from analytics provider Anodot and issued a pay-or-leak demand.
- Victim
- Rockstar Games
On 13 April 2026, Rockstar Games, the studio behind the Grand Theft Auto series, confirmed a data breach after the extortion group ShinyHunters claimed to have stolen its data. "We can confirm that a limited amount of non-material company information was accessed in connection with a third-party data breach," the company said, adding that the incident had no impact on the organisation or its players.
A third-party route in
The intrusion did not target Rockstar's own network. On 11 April, ShinyHunters posted a message on its leak site saying Rockstar's Snowflake cloud data warehouse instances had been compromised "thanks to Anodot.com," an AI-driven analytics and cloud monitoring company. The attackers are reported to have used authentication tokens stolen from Anodot to reach the Snowflake environments of Anodot's customers. Anodot had reported connector outages across regions on 4 April.
ShinyHunters gave Rockstar until 14 April to pay or see the data leaked. The group claimed more than 78 million records from analytics environments connected to Rockstar. Rockstar did not confirm that figure and declined to say whether a ransom had been demanded or paid; reporting indicated the exposed material was internal analytics, such as service monitoring, support metrics and business intelligence for GTA Online and Red Dead Online, rather than player account data. Snowflake said it had detected unusual activity in customer accounts connected to the Anodot integration.
Why it matters
The Rockstar case was one of several April 2026 incidents in which ShinyHunters used access tied to a single SaaS integration provider to reach multiple downstream companies' cloud data, a pattern that also affected other Anodot customers such as Vimeo. It echoes the 2024 Snowflake customer breaches: the cloud platform itself is not compromised, but trusted tokens and connectors held by third parties become a shortcut into many organisations at once. Rockstar had previously suffered a major intrusion in 2022, when a teenage Lapsus$ member leaked early footage of Grand Theft Auto VI.
Timeline
Analytics provider Anodot reports connector outages across regions.
ShinyHunters lists Rockstar Games on its leak site, claiming its Snowflake instances were compromised through Anodot, and sets a 14 April payment deadline.
Rockstar confirms that a limited amount of non-material company information was accessed in a third-party data breach and says players are not affected.
Sources
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/04/13/rockstar-games-data-breach-shinyhunters/
- bitdefender.comhttps://www.bitdefender.com/en-us/blog/hotforsecurity/rockstar-games-data-breach