INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Discord Users' Data Exposed in GTA 6 Leak Investigation
| 2026-08-25 10:01 CRITICAL MEDIUM DATA BREACH
Executive Summary
AI-generated
Someone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game's publisher badly wants to know who. Take-Two Interactive, the publisher behind the GTA series, hit Microsoft and Discord with a subpoena on August 20, demanding IP addresses, phone numbers, linked Google and Xbox accounts, and OneDrive contents of certain server members from three affected servers going back to June 1 this year. The attack is believed to be carried out by an individual or group known as CyberLeek, who claims ideological motives and has been publishing game footage on the Solana network since August 17. This leak hunt could expose data belonging to thousands of Discord users, including Australian GTA 5 streamer Matthew Judge, with potentially hundreds or thousands of people having identifying information handed over to Take-Two as part of its investigation.
Technical Mitigations AI-generated
• Block or hunt for cryptocurrency tokens with suspicious activity, such as $CYBERLEEK on the Solana network.
• Use a VPN to mask IP addresses when accessing Discord servers and OneDrive contents.
• Monitor accounts for MachineGuid values and Microsoft account device IDs that may have been compromised by ShinyHunters cybercrime crew.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope
cryptocurrencycryptocurrency
mediamedia
Incident Timeline
2026/08/25
The ShinyHunters gang targeted Anodot, a cloud analytics vendor holding persistent authentication tokens for its customers' Microsoft accounts and Windows installations.
Click on any entity below to view its context and source!
infrastructure
Windows
It’s also after their MachineGuid values and Microsoft account device IDs, which identify individual Windows installations and devices that access Microsoft services, respectively.
financial
$60,000 toke
However, they can still collect trading fees from the toke , which reportedly reached up to $60,000 last week.
threat_actor
ShinyHunters
In April, the ShinyHunters cybercrime crew
stole
78.6 million Rockstar records without directly compromising any of the company’s internal systems.
Rather than compromising Rockstar, ShinyHunters targeted Anodot, a cloud analytics vendor that held persistent authentication tokens for its customers’
Gaining access to victims’ data by compromising third-party service providers holding that data is the ShinyHunters gang’s
modus operandi
.
data_breach
78.6 Rockstar records
In April, the ShinyHunters cybercrime crew
stole
78.6 million Rockstar records without directly compromising any of the company’s internal systems.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
It’s also after their MachineGuid values and Microsoft account device IDs, which identify individual Windows installations and devices that access Microsoft services, respectively.
Metrics
financial
60,000
Toke
However, they can still collect trading fees from the toke , which reportedly reached up to $60,000 last week.
Metrics
data_breach
78,600,000
Rockstar Records
In April, the ShinyHunters cybercrime crew
stole
78.6 million Rockstar records without directly compromising any of the company’s internal systems.
Intelligence Sources
Malware Bytes
2026-08-25
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T12:13
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
Malwarebytes Browser Guard
entity
8x
timeline
Temporal Reference
2026/08/18
date
2x
tactic
Cyber Operation Type
Impersonate
tactic
Contextual Telemetry
Context Block
7 METRICS
infrastructure
Affected Product
Windows
software
financial
Toke
60,000
toke
general metric
Extended Look
6
extended look
source region
Origin Country
Australia
country
general metric
Streamer
5
streamer
threat actor
APT Group
ShinyHunters
actor
data breach
Rockstar Records
78,600,000
rockstar records
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.