Explosive New GTA 6 Leak and The 2022 Breach Lesson

Prior to the release of Netflix’s Extended Look of the highly-awaited Grand Theft Auto 6 game, a group called “CyberLeek” caused a massive uproar across social media sites by releasing multiple game play leaks. The data breach revealed the massive map of the game, vehicle functionalities and multiple mini-games. Along with the clips, CyberLeek have released the manifesto, “Every year anti-consumerism tightens its grip, and every year gamer get less for what they pay”. This commentary was in response to the game’s lack of release in physical disks, and a multitude of single-player DLCs.

While Obbe Vermeji, ex-Rockstar technical lead, doesn’t think too much of the leak as an issue, Rockstar has been on a desperate manhunt for CyberLeek. Particularly, they have issued several subpoenas to some enterprises such as DMCA, Github and Microsoft to clinch the attacks. Gaming giants are not isolated in this cybersecurity breach. As CyberLeek threatened, “If CyberLeek can reach Rockstar, no one is safe. This is a message to all big corpo: behave, or be the next target.” As of date, the CyberLeek group still remains at large with plans to release another footage before the Netflix launch.

The 2022 Rockstar Breach

Rockstar is no stranger to data breaches. In September 2022, Rockstar Games suffered a major breach. Hackers leaked roughly 90 videos of unreleased GTA 6 development footage online. Investigators later linked the attacker to Lapsus$, a hacking group that also targeted Microsoft, Nvidia, Samsung, Uber, and Okta. The attacker was later linked to the Lapsus$ hacking group. The group had also targeted major organizations, including Microsoft, Nvidia, Samsung, Uber, and Okta. Rockstar described the incident as a “network intrusion.”

Unlike the usual phishing and malware attacks, Lapsus$ is notorious for using social engineering as a vector of enterprise invasion.They targeted employees, using their credentials to infiltrate the Rockstar’s enterprise software and communication systems. While PIIs (Personally Identifying Information) are the common target of data breaches, it is a different issue for Rockstar. As the hackers stole the source code, development assets and unreleased product information, Intellectual Property has become the primary target of the 2022 data breach.

Rockstar wasn’t the only victim of Lapsus$’ attack in 2021-2022. As mentioned, Lapsus$ has attacked several big names such as Microsoft, Nvidia, Samsung, Uber, and Okta. For other companies, the attack wasn’t a simple game play leak. In fact, the group also sent out threatening messages to phone company BT/EE’s customers, stating that “if EE pays 4 millions USD in XMR before the 20th august, we will delete [all userdata] from our servers.”

Lapsus$ message to EE's customers demanding ransom from the company.

Eventually, hackers from the group were caught, revealing that most of the attackers were teenagers. This shocked the world as attacks from these “Digital Bandits” have revealed just how vulnerable even big enterprise systems are. As the court concluded, these attacks “made clear just how easy it was for its members (juveniles, in some instances) to infiltrate well-defended organizations”.

What Did We Learn? 

Reports around Lapsus$ attacks consistently showed attackers gaining access through compromised accounts and internal collaboration tools. In the Rockstar data breach, the attacker reportedly accessed internal communications and development resources. While this is a case of small groups attacking big business, small-to-medium businesses should take notes of these attacks.

To bar the entry and tighten the defense against infiltration, enterprises must implement MFA everywhere. They should also use conditional access policies to evaluate factors such as user location, device status, and risk level before granting access. In addition, applying the principle of least privilege ensures that employees and contractors have access only to the resources necessary for their roles, limiting the potential damage if an account is compromised. Finally, organizations should continuously monitor privileged accounts and administrative activities to quickly detect suspicious behavior, unauthorized access attempts, or signs of account misuse before they escalate into a major security incident

References:

Leave a Comment

Your email address will not be published. Required fields are marked *