In the layered architecture of modern digital infrastructure, even the most fortified institutions find their vulnerabilities not within their own walls, but in the corridors of those they trust. Rockstar Games, the studio behind some of the most commercially dominant titles in entertainment history, confirmed this weekend that a limited set of internal data was accessed by the hacking collective ShinyHunters — not through any flaw in Rockstar's own systems, but through a compromised analytics partner. The breach, part of a sweeping campaign that has touched over 160 organizations, reminds us
ShinyHunters Claims 78.6M Rockstar Records Stolen via Snowflake Breach
A limited amount of non-material company information was accessed
So the hackers didn't actually break into Snowflake itself—they went through a side door?
Exactly. They compromised Anodot, which is an analytics platform that Rockstar was using. Once they had Anodot's credentials, they could access Rockstar's data sitting in Snowflake.
But we should be clear: we only have ShinyHunters' word on this. Reuters couldn't verify the data. We don't know if all 78.6 million records are actually intact or what condition they're in.
What was in those records, then? Games data?
According to Bleeping Computer, yes—revenue numbers, player behavior data, game economy information from GTA Online and Red Dead Online. But Rockstar called it "non-material company information."
There's a tension there. If it's just internal metrics, why does Rockstar care? And if it's sensitive enough to care about, why downplay it?
Did the hackers ask for money?
ShinyHunters wouldn't say. They refused to comment on whether there was any ransom demand or contact with Rockstar.
Which is interesting. Usually these groups brag about the extortion angle. The silence could mean negotiations are happening, or it could mean they're still deciding what to do with the data.
Is this a one-off, or part of something bigger?
Part of something much bigger. Over 160 Snowflake customers were hit in 2024 alone—Ticketmaster, Santander, Advance Auto Parts. Same pattern every time: weak credentials or compromised third parties, not Snowflake's fault directly.
Though that's cold comfort to the companies affected. The vulnerability is real even if it's not Snowflake's code that's broken.
Il Polso
- ShinyHunters claims to have extracted 78.6 million Rockstar records, including revenue metrics and player behavior data from GTA Online and Red Dead Online — one of the largest alleged gaming industry breaches in recent memory.
- The attack did not penetrate Snowflake or Rockstar directly; instead, hackers slipped in through Anodot, a third-party AI analytics tool, exposing how vendor relationships can become invisible backdoors.
- Snowflake's security team detected the intrusion and swiftly revoked all Anodot-linked accounts, containing the breach before further extraction could occur.
- Rockstar and parent company Take-Two offered only a minimal public response, confirming 'non-material' data was accessed while declining to specify contents or address ransom demands.
- The incident lands within a pattern of over 160 Snowflake-adjacent breaches in 2024 — including Ticketmaster and Santander — signaling a systemic vulnerability in how enterprises manage third-party cloud integrations.
In the layered architecture of modern digital infrastructure, even the most fortified institutions find their vulnerabilities not within their own walls, but in the corridors of those they trust. Rockstar Games, the studio behind some of the most commercially dominant titles in entertainment history, confirmed this weekend that a limited set of internal data was accessed by the hacking collective ShinyHunters — not through any flaw in Rockstar's own systems, but through a compromised analytics partner. The breach, part of a sweeping campaign that has touched over 160 organizations, reminds us that in an interconnected world, security is only as strong as its most overlooked dependency.
Over the weekend, the hacking collective ShinyHunters announced it had obtained nearly 80 million records from Rockstar Games, the studio behind Grand Theft Auto and Red Dead Redemption. The claim was flagged by cybercrime researchers at eCrime.ch on Saturday, and by Monday a group representative had confirmed to Reuters that the haul totaled 78.6 million records.
The breach did not originate from Snowflake's platform. Attackers gained entry through Anodot, an AI-powered analytics tool Rockstar used to monitor business metrics. From there, they pivoted into Rockstar's Snowflake environment. Once the suspicious activity was detected, Snowflake's security team revoked all accounts connected to Anodot to prevent further access.
Rockstar issued a brief statement acknowledging that 'a limited amount of non-material company information was accessed,' while stressing there was no impact on players or operations. Parent company Take-Two declined to comment further, and Anodot did not respond to requests for comment. ShinyHunters declined to say whether any ransom demand had been made.
Reporting from Bleaching Computer suggests the stolen files include revenue and purchase data from GTA Online and Red Dead Online, as well as player behavior tracking and internal economy details — though the full scope remains independently unverified. The incident fits a broader pattern: more than 160 Snowflake customers were targeted in similar campaigns throughout 2024, among them Ticketmaster and Santander Group. In each case, attackers exploited third-party integrations rather than Snowflake itself, underscoring how vendor relationships have become one of the most consequential frontiers in enterprise security.
A hacking collective known as ShinyHunters announced over the weekend that it had obtained nearly 80 million records belonging to Rockstar Games, the studio behind Grand Theft Auto and Red Dead Redemption. The claim surfaced on a website associated with the group on Saturday, flagged by cybercrime researchers at eCrime.ch. By Monday, a representative of ShinyHunters had confirmed to Reuters that the haul consisted of 78.6 million records from Rockstar's account with Snowflake, the cloud data platform used by thousands of corporations worldwide.
The breach did not originate from Snowflake itself. Instead, the hackers gained access through a compromised account belonging to Anodot, an artificial intelligence-powered analytics tool that Rockstar used to track business metrics. Once inside Anodot's systems, the attackers were able to pivot into Rockstar's Snowflake environment and extract the data. Snowflake's security team discovered the suspicious activity and immediately revoked all user accounts connected to Anodot, preventing further unauthorized access.
Rockstar Games responded with a brief statement, confirming that "a limited amount of non-material company information was accessed" but emphasizing that the breach had no bearing on the company's operations or its players. The studio did not elaborate on what constituted "non-material," nor did it address the specific contents of the stolen files. Take-Two Interactive, Rockstar's New York-based parent company, declined to comment beyond the studio's statement. Anodot, based in Israel, could not be reached for immediate response.
According to reporting from Bleaching Computer, the stolen data includes revenue figures and purchase metrics from Grand Theft Auto Online and Red Dead Online—two of the most profitable titles in the gaming industry. The breach also captured player behavior tracking information and details about the games' internal economies. The exact scope of what was taken remains difficult to verify independently; Reuters noted it could not immediately confirm the contents or the full scale of the compromise.
ShinyHunters declined to say whether it had demanded ransom from Rockstar or Take-Two, or whether any negotiations had taken place. The group's silence on these points is notable, as extortion typically accompanies data theft operations of this magnitude. The incident is part of a broader pattern of compromise affecting Snowflake customers. Over the course of 2024, more than 160 organizations using Snowflake fell victim to data theft and extortion campaigns, including Ticketmaster, Santander Group, and Advance Auto Parts. In each case, attackers exploited weak credentials or compromised third-party integrations rather than vulnerabilities in Snowflake's core platform. The Rockstar breach underscores how even large, well-resourced companies remain exposed when their vendors and partners become entry points for sophisticated attackers.
Citazioni salienti
A limited amount of non-material company information was accessed in connection with a third-party data breach. This incident has no impact on our organization or our players.— Rockstar Games spokesperson
Not a compromise of Snowflake's platform or environment, but rather a result of a compromise of Anodot.— Snowflake spokesperson