❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity/Privacy

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

25 August 2026 at 16:51

Grand Theft Auto VI, widely heralded as the game event of the decade, took a significant hit last week after a cybercriminal sent much of the internet into pandemonium after publishing gameplay footage a week before the game’s publisher planned to reveal core portions of the game to the public.  

The files posted by the online persona “CyberLeek” indicate either a hacker had direct access to Rockstar Games’ most sensitive systems or was given proprietary data by an insider, eventually becoming one of the highest-profile data extortion attacks of the year — a vexing, almost-daily occurrence hitting industries of all types.

While most data extortion attacks rattle companies due to regulatory or privacy concerns, this particular incident has caused an outsized response from Rockstar’s parent company, Take-Two Interactive Software, because it has an audience. While no lives are at risk, as they would be in an attack on critical infrastructure, the financial and reputational stakes are magnified precisely because people are watching every drip of stolen footage become a news story or a trending topic. 

“IP theft — whether it’s conducted by a cybercriminal, an insider, or even potentially [an artificial intelligence] model — rips away the hard work, passion, and livelihood among employees and companies that created the product in the first place,” Cynthia Kaiser, senior vice president of Halycon’s ransomware research center, told CyberScoop.

The game’s prior release, GTA V, along with its online component, has sold over 230 million copies and earned Take-Two over $11 billion since its release in 2013. Industry analysts say GTA VI is on pace to make between $3.3 billion to $5.2 billion in cumulative global sales by the end of its launch week in November. 

“The crown jewels of a company are whatever makes it differentiated and special,” said Kaiser, the former deputy assistant director of the FBI’s cyber division. “For some, that means customer data or source. For a studio in the final stretch before launch, the crown jewel is the surprise.”

While Take-Two hasn’t said anything publicly about the leaks, it has responded feverishly via its legal team. The company petitioned a federal court for subpoenas under the Digital Millennium Copyright Act against Discord, Google, Microsoft and X, seeking the identity of CyberLeeks and other user accounts it accuses of copyright infringement.

Federal judges granted the subpoenas against Discord, Microsoft and X, but the petition against Google remained unapproved as of Monday. Take-Two’s legal representatives also sent copyright notices to the four companies, informing them of the copyrighted material published on their platforms, but it’s unclear if any of the tech companies have been formally served with the signed subpoenas. 

Take-Two and Rockstar did not respond to a request for comment.

The subpoenas may have been enough to spook those responsible for the leaked footage. As of Monday, the websites where those behind CyberLeek were posting leaked information and links to a memecoin were offline.

Zach Edwards, staff threat researcher at Infoblox and a self-proclaimed fan of the series, initially thought the leaks were part of a Rockstar guerrilla marketing campaign. But the company’s response “confirms that this is a real investigation, and the content being shared is likely real to some degree,” he said. 

Take-Two’s actions thus far indicate the company is approaching the breach and leaks like an insider threat investigation, Edwards said. Whoever leaked the footage may have had access to an actual build of the game, he added. That could point to an insider, someone who could have saved a copy to a cloud service, uploaded it to a file-hosting site, or walked out with it on an external drive.

CyberLeek’s conflicting motivations

The hacker or group behind CyberLeek claim they are releasing the gameplay videos to protest Rockstar’s decision to not release physical copies of the game. Yet, watermarks on the leaked videos include addresses to crypto wallets, which indicate CyberLeek is also, and perhaps primarily, seeking a payout. 

“The persona behind the leaks, CyberLeek, published an anti-corporate manifesto targeting digital pre-orders and disc-less releases to frame the breach as hacktivism,” Ben Bernstein, manager of Huntress’ cybersecurity advisors team, told CyberScoop. “Yet behind the political posturing, there’s clear financial monetization and clout-chasing.”

Kaiser draws the same conclusion. “Let’s separate stated motive from observed behavior,” she said. “Threat actors who talk about principle while running a monetization channel are usually only telling you what they think will land with an audience, not actually what is driving them.”

Katie Moussouris said “this is what the alternative vulnerability economy looks like.” The founder and CEO at Luta Security has spent decades building legitimate channels for people who find security problems to get paid without turning to crime.

“The leaker launched a cryptocurrency token, watermarked stolen footage with a buy link, and offered to sell ad space on future leaks. Each of those pays out in proportion to how many people are watching. The manifesto is what keeps them watching,” Moussouris said. 

“That is a genuinely new monetization model for stolen pre-release content, and it means the usual playbook of negotiating a ransom payment quietly or paying to make it stop won’t work,” she added.

Different flavor, same crime

Despite its unique characteristics, the rhythm of the attack and its fallout is familiar territory for cybersecurity experts. 

“Steal, publish a sample, promise more, deliver, repeat. Just like ransomware attacks, in cases like these criminals use every lever of pressure they can against a company — including the fear of what is coming next — to profit from their actions,” Kaiser said. 

“The attackers are crowdsourcing their pressure tactics. A meaningful share of the player base is treating the leaks as free content and amplifying them,” she added.

Kaiser also sees some clear parallels with previous attacks targeting major entertainment companies, including the 2014 attack on Sony Pictures and the HBO hack in 2017. 

“The Sony comparison is useful for how these things escalate, but this incident reminds me more of the Iranian hackers’ leak of ‘Game of Thrones’ episodes a few years back,” she said. “North Korea attacked Sony for political purposes, destroying its data along the way; Iranian threat actors compromised HBO, along with hundreds of universities and over forty other companies, in a hacking-for-hire scheme stealing American intellectual property.”

Federal authorities earlier this month unsealed a second wave of indictments against 17 Iranians affiliated with the tech firm Mabna Institute who allegedly stole troves of data from government agencies and dozens of companies, including HBO.

This isn’t the first time Rockstar has been hit with a security incident. In 2022, an 18-year old British man who was a member of the Lapsus$ cybercriminal gang was sentenced to an indefinite hospital order after leaking gameplay footage. According to the BBC, the incident cost Rockstar, along with ridehauling company Uber and chipmaker Nvidia, over $10 million. 

The subpoena that worries security experts

Security professionals expect the situation to escalate on all sides. Leaks have hit the internet daily for the past eight days, including a series of leaks Tuesday morning. Meanwhile, Take-Two has not relented on its subpoenas. Its broadest move was a subpoena against Discord, seeking identifying data on CyberLeek, two other users and every member of three Discord servers where the copyrighted material was posted.  

Moussouris said the scope of that inquiry should worry people well beyond this case. 

“Take-Two asked for Windows device identifiers, login records, and cloud storage contents for every person who spoke in three Discord servers going back to June,” she said. “The people with the best chance of uncovering the culprits are those doing the unglamorous investigation forensics work of figuring out how the build may have leaked.”

Discord would not say whether it had been formally served or what it has done in response. A company spokesperson said it reviews and complies with valid subpoenas when they are received. 

While the breach and leak of ‘GTA VI’ material is a serious matter, Edwards noted that Take-Two is also benefiting from greater interest in the unreleased game on a daily basis. 

“The threat actor leaking these videos has failed by essentially creating a successful underground marketing campaign for the game while also putting themselves at serious risk of being eventually caught,” he said. 

“This incident is playing out like a classic insider threat exploitation scheme. Someone got access to sensitive data, they had a political agenda which clashed with the owner of the sensitive data, and they decided to do something stupid to try and force a change,” Edwards added. “This attack has done nothing but spread ‘GTA VI’ content further than it would have otherwise, and it’s creating ripples across other industries like cybersecurity who would have never covered ‘GTA 6’ issues previously.”

The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

A California county wants to hire Tina Peters to help run its elections

By: djohnson
19 August 2026 at 11:57

Clint Curtis, the registrar for voters in Shasta County, Calif. said he plans to hire convicted felon and election denialist Tina Peters as one of his top deputies.

Curtis said he plans to hire Peters next month as an assistant registrar, according to local news outlets, which cited text exchanges with Curtis.

CyberScoop has reached out to Shasta County’s elections office for comment.

If Peters is hired, it would represent a marriage between a conspiracy-minded election official from another state and an equally distrusting electorate.

Donald Trump won Shasta County approximately two-thirds of voters in the county in all three presidential elections dating back to 2016. Its conservative residents have adopted Trump’s rhetoric that election fraud, voting machine hacks, noncitizen voting and other problems plagued the system, and have turned their anger at local officials.

Cathy Darling Allen, Shasta County’s former registrar of voters, told CyberScoop in 2024 that she retired after decades of administering elections in the county due to persistent attacks and harassment from voters who embraced baseless election fraud conspiracy theories. 

Peters, a former Mesa County, Colo. election official, had been serving a 9-year sentence for seven felonies, including identity theft, breaking into an election office, disabling surveillance cameras, and stealing voting system software.

Peters’ prosecutor, Colorado’s state clemency advisory board, and Mesa County officials have all defended her sentence and described her as entirely unrepentant for her crimes.

Election experts have called Peters’ theft of voting system software one of the most serious breaches of election systems in history. She shared the stolen code with conservative activists, and the code eventually surfaced online.

Governor Jared Polis, a Democrat, commuted Peters’ sentence earlier this year, citing pressure from the Trump administration and arguing that her punishment violated her First Amendment rights. In doing so, Polis intervened before an appeals court could decide whether Peters deserved a reduced sentence.

“She may continue making claims about elections that I believe are false,” Polis wrote in a May Substack post defending the decision. “She may continue promoting ideas that I strongly disagree with. I hope she doesn’t. But in America, people are not sent to prison for expressing political views, however misguided those views may be.”

In response to questions about Peters, Polis’ press office referred CyberScoop to the Colorado Department of Corrections.

Department of Corrections spokesperson Alondra Gonzalez told CyberScoop in an email that as part of her parole conditions, Peters is required to get a job or participate in a full time educational or vocational program and reside in Colorado. Parolees can request to transfer to another state, but those requests would be subject to rules and procedures under the Interstate Compact for Adult Offender Supervision and require approval from both states.
Gonzalez told CyberScoop that the department has not received a request for an interstate transfer from Peters at this time.

The Shasta County board of supervisors formally censured Curtis earlier this month following investigations by the county and outside consultant firm The Oppenheimer Group found he was verbally abusive or physically threatening toward staff.

At an Aug. 11 public meeting, Shasta County Supervisor Matt Plummer cited more than 700 pages of evidence and more than half a dozen eyewitnesses.

The investigations included claims that Curtis at times threatened to “punch,” “slap in the face,” “kill” or “execute” his subordinates. Another claim alleges Curtis once threatened to remove a door where an employee was allegedly hiding from him and have the person pulled out by their hair.

Plummer prefaced his comments by saying the board’s action is “not about election integrity” and that Curtis retains all of his authority to carry out budgeted election administration for the county.

“This is about determining when a department head allegedly and through two investigations, has substantiated allegations of violating personnel codes, the codes that guide how we as a county intend to interact with our employees, what do we do about it?” Plummer said.

Senators Alex Padilla, D-Calif., and Adam Schiff, D-Calif., wrote to California Secretary of State Shirley Weber to express their “grave concern” over the possibility that Peters would have access to state election systems.

“If Shasta County puts Ms. Peters in a position to again violate election laws following her convictions, county taxpayers could be burdened with unwelcomed and potentially hefty expenses,” Padilla and Schiff wrote. “If county officials proceed with this misguided plan, we request that you provide the maximum oversight possible to ensure that Ms. Peters does not improperly access ballots, voting systems, or sensitive information that could impact the rights and privacy of the over 100,000 registered voters in Shasta County in violation of…state or federal election law.”

The post A California county wants to hire Tina Peters to help run its elections appeared first on CyberScoop.

Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack

13 August 2026 at 17:59

A tech worker who hatched an elaborate insider attack in late 2023 and attempted to extort Brightly Software for about $2.5 million was sentenced to two years in prison, the Justice Department said Thursday.

Cameron Nicholas Curry, also known as “Loot,” committed a series of crimes while working as a data analyst contractor for the Siemens-owned company. The 27-year-old North Carolina man stole a trove of corporate data, including sensitive employee and compensation information, which he used to threaten various employees and executives over a six-week period in late 2023 and early 2024. 

Curry ultimately extorted the company for $7,540.92 in late January 2024. He was found guilty of six counts of extortion in March.

Brightly Software was named as the victim in court records filed in the U.S. District Court for the Western District of North Carolina earlier this month. The asset and maintenance management software provider, which Siemens acquired in 2022, did not immediately respond to a request for comment.

The insider attack illustrates risks companies accept when employees, or contractors placed in roles by a third-party recruitment company, are allowed to access sensitive data on a company-owned laptop. 

Prosecutors said Curry used his access to the company’s network to remove corporate data for extortion while he worked for the company between August and December 2023. Curry started sending threatening emails to Brightly Software employees immediately following his last day of employment, and demanded a ransom to not leak and destroy the data. 

Curry sent more than 60 emails, threatening to disclose the company’s payroll data, claiming it showed significant pay inequity across the workforce. In those emails, Curry framed the data theft extortion attack as an effort to implement salary transparency.

Officials said Curry included attachments with the emails containing screenshots of spreadsheets listing the personally identifiable information of company employees. He also warned the company he would provide employees instructions on how to address pay discrimination through mediation, the Equal Employment Opportunity Commission or a class-action lawsuit.

Some of the extortion emails got personal, including a claim that one person on the legal team wasn’t getting a bonus while most employees in high-level positions did receive bonuses. Curry also threatened to report the breach to the Securities and Exchange Commission, citing rules that require public companies to disclose cyberattacks quickly. 

The publicly traded company notified the FBI of the breach on Dec. 14, 2023 and paid less than 1% of Curry’s ransom demand almost a month later.

Authorities identified and built a case against Curry rather quickly due to multiple operational security mistakes. He used personal and verifiable data to establish a Coinbase account for the ransom, linking  two debit cards belonging to his mother and sister to the account.

The FBI searched Curry’s apartment, digital devices and vehicle in Charlotte, North Carolina, weeks after the ransom was paid. 

Curry faced up to 12 years in prison, but was ultimately sentenced to two years followed by one year of supervised release.

Curry’s lawyers argued that the case against him was prolonged due to prosecutors’ errors, including affidavits that falsely said Brightly Software was headquartered in Washington, D.C. The company is based in Cary, North Carolina, but Siemens U.S. corporate headquarters is based in Washington, and prosecutors identified the previously unnamed victim company as the subsidiary of an international parent company. 

The location discrepancy resulted in a change in venue for the trial and, Curry’s lawyers argued, imposed an unnecessarily lengthy pretrial restraint of almost 31 months on Curry, including 17 months of full home confinement.

The post Tech contractor for Brightly Software sentenced to 2 years in prison for insider attack appeared first on CyberScoop.

❌
❌