Server room with rows of network equipment and blinking lights in blue tones
Photo via Unsplash

TL;DR: ShinyHunters breached Rockstar Games by compromising Anodot, a third-party cloud cost monitoring platform. Anodot held OAuth tokens that connected to Rockstar's Snowflake data warehouse. The attackers extracted those tokens, walked into Snowflake, and pulled 7.54 GB of internal analytics across 25 files. Rockstar refused to pay. ShinyHunters dumped everything on April 15. This is the same SaaS-vendor-to-data-warehouse playbook ShinyHunters has used against Hims & Hers, Crunchyroll, Figure, Adidas, and CarGurus. Your company probably has a dozen tools like Anodot with stored credentials you've forgotten about.

A Cloud Cost Tool Was the Front Door

On April 4, 2026, Anodot (a company that monitors cloud spending and performance) reported that its connectors were down across multiple regions, including its Snowflake integrations.[1] That "outage" was ShinyHunters ripping authentication tokens out of Anodot's infrastructure.

By April 11, ShinyHunters posted a breach notice on their leak site: "Rockstar Games! Your Snowflake instances were compromised thanks to Anodot.com. Pay or leak."[2]

Rockstar didn't pay. On April 14, the deadline passed. By April 15, ShinyHunters dumped 7.54 GB across 25 compressed CSV files.[3]

On April 13, Rockstar confirmed "a limited amount of non-material company information was accessed in connection with a third-party data breach" and claimed the incident had "no impact on our organization or our players."[4]

What's in the 7.54 GB

The leaked files are business intelligence exports from Rockstar's Snowflake instance. According to HackRead, which reviewed the dump, the contents include:[3]

  • GTA Online and Red Dead Online performance metrics
  • Virtual currency redemption tracking data
  • Regional performance reports and daily KPIs
  • Revenue breakdowns
  • Cheat detection model datasets
  • Zendesk customer support analytics

No player credentials, no account data, and no GTA VI assets. That's the one piece of good news. But internal revenue figures, anti-cheat models, and KPI data are still valuable to competitors, short-sellers, and other threat actors mapping Rockstar's operations.

There's another wrinkle. Rockstar said "non-material." ShinyHunters said they have more. The group hasn't disclosed the full scope, and their track record suggests they hold back data for later leverage.[2]

The OAuth-Through-SaaS Playbook

Here's how this attack actually works, and why it keeps working:

Modern companies connect dozens of SaaS tools to their core data infrastructure. A cloud cost monitoring tool like Anodot needs read access to your Snowflake instance to track query costs, compute usage, and storage trends. To get that access, you grant it an OAuth token, essentially a permanent key.

That token lives in Anodot's infrastructure, not yours. You have zero visibility into how Anodot stores it, who can access it internally, or whether their security matches yours.

ShinyHunters figured this out. Instead of attacking Rockstar directly (a company that rebuilt its security posture after the 2022 Lapsus$ attack that leaked GTA VI footage), they attacked the weakest vendor in Rockstar's supply chain.[5]

The attack chain:

  1. Compromise the SaaS vendor. Breach Anodot's infrastructure
  2. Extract stored OAuth tokens. These tokens grant access to customer data warehouses
  3. Pivot to the real target. Use stolen tokens to authenticate directly to Rockstar's Snowflake instance
  4. Exfiltrate. Pull data through legitimate API calls that look like normal Anodot activity

Snowflake wasn't breached. Anodot was. But Anodot held the keys to Rockstar's data.

ShinyHunters Has Done This Before. Repeatedly.

The Rockstar breach isn't an isolated incident. ShinyHunters has been systematically exploiting the SaaS-vendor-to-data-warehouse path for months:

  • Hims & Hers: Telehealth giant breached through Zendesk and Okta SSO credentials. Millions of health-related support tickets stolen.[6]
  • Crunchyroll: 6.8 million records stolen through the same Okta SSO campaign.[7]
  • Figure Technology: 967,000 customer records from the fintech company, again via Okta.[8]
  • McGraw-Hill: 13.5 million records through a Salesforce misconfiguration. 100 GB+ dumped on April 15.[9]
  • Adidas, CarGurus, Betterment: Various SaaS vendor entry points, same exfiltration pattern.

The common thread: ShinyHunters doesn't break down the front door. They find a vendor that already has a key, steal the key, and walk in.

Security researcher Zach Edwards at Silent Push identified over 100 organizations targeted in ShinyHunters' broader campaign, which uses voice phishing, SSO credential theft, and SaaS vendor compromise as parallel attack vectors.[10]

Your Company Has 50 Anodots

Most companies don't know how many third-party tools hold OAuth tokens to their core infrastructure. A quick audit usually turns up a few dozen (cloud cost monitors, BI tools, marketing platforms, support ticket systems, DevOps dashboards), each with stored credentials granting some level of access to production databases or data warehouses.

Each one of those tokens is a potential entry point. And unlike an employee credential you can revoke when someone leaves, OAuth grants from vendor-to-vendor integrations tend to live forever. Nobody remembers who set them up. Nobody reviews whether the vendor still needs that access. Nobody checks whether the vendor has been breached.

The Snowflake breach wave of 2024 proved this model works at scale. ShinyHunters and related groups stole credentials from third-party tools to access Snowflake instances at Ticketmaster, AT&T, Neiman Marcus, and 165 other companies. Two years later, the pattern hasn't changed. Only the entry points have.

What You Can Do

If you're a Rockstar Games player: Your login credentials and personal data don't appear to be in this dump. But keep an eye on Rockstar's official communications in case the scope expands.

If you run a company:

  1. Audit your OAuth grants right now. Go to your Snowflake, BigQuery, Databricks, or Redshift admin panel. List every third-party integration with stored credentials. Ask: does this vendor still need this access? When was the token last rotated?
  2. Rotate tokens regularly. OAuth tokens to data warehouses should have expiration dates. If they don't, set them.
  3. Scope access tightly. A cloud cost monitoring tool needs read access to usage metadata. It does not need read access to your entire data warehouse. Use the principle of least privilege.
  4. Monitor for anomalous queries. If Anodot's service account suddenly starts pulling full table dumps at 3 AM, that's not cost monitoring.
  5. Vet vendor security. Before connecting a SaaS tool to your data infrastructure, ask how they store OAuth tokens, whether they encrypt them at rest, and what their breach notification timeline is.

Second Breach, Same Company

This is Rockstar's second major breach in four years. In September 2022, a member of the Lapsus$ group (an 18-year-old later sentenced to indefinite hospitalization) leaked 90 videos of GTA VI gameplay footage. That breach came through a compromised Slack channel.[4]

Rockstar rebuilt its security after Lapsus$. But the Anodot compromise shows that hardening your own perimeter doesn't matter when your vendors' perimeters are wide open. You can't firewall your way out of a supply chain attack.

The Real Story

ShinyHunters isn't breaking into companies. They're walking through doors that companies left open by giving third-party vendors permanent keys to their data. The group has been doing this for months, across dozens of companies, using the same basic playbook each time.

Rockstar will recover from a 7.54 GB analytics dump. The real damage is to every company that just read this story, glanced at its own vendor integrations, and realized it has no idea how many OAuth tokens are sitting in third-party infrastructure right now.

If you haven't audited your SaaS vendor credentials in the last 90 days, the answer is: too many.

Sources

  1. Help Net Security - "Rockstar Games confirms data breach after ShinyHunters extortion attempt" (April 13, 2026)
  2. Security Affairs - "ShinyHunters claim the hack of Rockstar Games and started leaking data" (April 2026)
  3. HackRead - "ShinyHunters Leak Rockstar Games Internal Data" (April 2026)
  4. Engadget - "Rockstar Games has confirmed it was hit by a third-party data breach" (April 2026)
  5. BreachSense - "Rockstar Games Data Breach" (April 2026)
  6. State of Surveillance - "ShinyHunters Hit a Telehealth Giant" (April 5, 2026)
  7. State of Surveillance - "Crunchyroll ShinyHunters Breach" (2026)
  8. State of Surveillance - "Figure Technology ShinyHunters Breach" (2026)
  9. State of Surveillance - "McGraw-Hill Salesforce Breach - 13 Million Records" (2026)
  10. State of Surveillance - "ShinyHunters Hit 100 Companies Through Okta" (January 27, 2026)