{"id":45325,"date":"2026-04-11T18:12:53","date_gmt":"2026-04-11T10:12:53","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/11\/shinyhunters-claims-rockstar-games-snowflake-breach-via-anodot\/"},"modified":"2026-04-11T18:12:53","modified_gmt":"2026-04-11T10:12:53","slug":"shinyhunters-claims-rockstar-games-snowflake-breach-via-anodot","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/11\/shinyhunters-claims-rockstar-games-snowflake-breach-via-anodot\/","title":{"rendered":"ShinyHunters Claims Rockstar Games Snowflake Breach via Anodot"},"content":{"rendered":"\n<p>Rockstar Games is back in the news, not over Grand Theft Auto VI delays, but because the <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/tag\/ShinyHunters\/\" data-type=\"post_tag\" data-id=\"26126\">ShinyHunters<\/a> hacking group claims it accessed the company\u2019s Snowflake environment and may be holding a large volume of data at risk of being leaked.<\/p>\n<p>The message, published on the group\u2019s dark web leak site on April 11 (UK time), sets a deadline of April 14 and follows a familiar pattern of pay or face public exposure.<\/p>\n<p>This case differs from a typical direct breach because the attackers pointed to Anodot, a SaaS platform used for cloud cost monitoring and analytics, as the entry point. In their post, they claimed, \u201cRockstar Games! Your <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/canada-arrests-hacker-linked-snowflake-data-breaches\/\" data-type=\"post\" data-id=\"122245\">Snowflake<\/a> instances were compromised thanks to  <code>Anodot.com<\/code>. Pay or leak.\u201d<\/p>\n<blockquote>\n<p style=\"font-style:normal;font-weight:100\"><em>&#8220;Rockstar Games, your Snowflake instances were compromised thanks to Anodot.com. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak, along with several annoying (digital) problems that&#8217;ll come your way. Make the right decision, don&#8217;t be the next headline.&#8221;<\/em><\/p>\n<p> <cite>ShinyHunters<\/cite><\/p><\/blockquote>\n<div>\n<figure><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-2.png\"><img loading=\"lazy\" decoding=\"async\" width=\"715\" height=\"644\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-2.png\" style=\"aspect-ratio:1.1102805823618007;width:480px;height:auto\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-2.png 715w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-2-300x270.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-2-380x342.png 380w\" sizes=\"auto, (max-width: 715px) 100vw, 715px\" alt=\"ShinyHunters Claims Rockstar Games Snowflake Breach via Anodot\" \/><\/a><figcaption>ShinyHunters claiming Rockstar Games as its new victim (Image credit: Hackread.com)<\/figcaption><\/figure>\n<\/p><\/div>\n<p>Recent <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/snowflake-customers-hit-in-data-theft-attacks-after-saas-integrator-breach\/\">reporting<\/a> confirmed that Anodot suffered a security breach, which attackers then used as a way to access customer environments connected through integrations. Reportedly, attackers were able to extract authentication tokens from Anodot, which function as trusted credentials between services. With those tokens, they could access connected Snowflake accounts without needing to exploit vulnerabilities in Snowflake itself.<\/p>\n<p>Once inside Snowflake environments, attackers exfiltrated data using normal database operations. Worse, because the access appeared legitimate, detection was not immediate in many cases. Several organizations were impacted before the activity was flagged and contained. <\/p>\n<div>\n<figure><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"673\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3-1024x673.png\" style=\"width:723px;height:auto\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3-1024x673.png 1024w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3-300x197.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3-768x505.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3-380x250.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3-800x526.png 800w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3-1160x763.png 1160w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/04\/shinyhunters-rockstar-games-snowflake-breach-anodot-3.png 1300w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" alt=\"ShinyHunters Claims Rockstar Games Snowflake Breach via Anodot\" \/><\/a><figcaption>Anodot&#8217;s <a target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/status.anodot.com\/\">Status page<\/a><\/figcaption><\/figure>\n<\/p><\/div>\n<p>For your information, ShinyHunters has built a track record of <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-target-firms-bypass-sso-security\/\">targeting identity systems<\/a>, API keys, and third-party integrations instead of relying on traditional exploits. Their focus is to gain valid access, extract large databases, and then apply pressure through public leak threats.<\/p>\n<p>Earlier this March, ShinyHunters <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-hackers-threat-stolen-salesforce-data\/\">said it had obtained<\/a> Salesforce-linked data tied to more than 400 companies. Since then, the group has published data from 26 of those organizations, giving weight to at least part of its claims. Some of the claimed and confirmed cases linked to ShinyHunters include the following organizations:<\/p>\n<ul>\n<li><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-hackers-cisco-records-data-leak\/\"><span style=\"text-decoration: underline;\">Cisco<\/span><\/a><\/li>\n<li><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-odido-nl-ben-nl-breach-confirm-cyberattack\/\"><span style=\"text-decoration: underline;\">Ben.nl<\/span><\/a><\/li>\n<li><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-leak-dutch-telecom-odido-data\/\"><span style=\"text-decoration: underline;\">Odido NL<\/span><\/a><\/li>\n<li><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-1-petabyte-data-breach-telus-digital\/\"><span style=\"text-decoration: underline;\">Telecom Giant Telus<\/span><\/a><\/li>\n<li><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-leak-dutch-telecom-odido-data\/\"><span style=\"text-decoration: underline;\">Dutch Telecom Odido<\/span><\/a><\/li>\n<li><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-350gb-data-breach-european-commission\/\"><span style=\"text-decoration: underline;\">European Commission<\/span><\/a><\/li>\n<li><a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/shinyhunters-leak-soundcloud-crunchbase-betterment-data\/\"><span style=\"text-decoration: underline;\">SoundCloud, Crunchbase, Betterment<\/span>,<\/a><em> and several others.<\/em><\/li>\n<\/ul>\n<p>As for Rockstar Games, the company has not issued a statement addressing the claim. What the Anodot incident shows is that while automation and cloud integrations improve efficiency, they can also introduce serious <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/top-3-data-security-risks-facing-businesses\/\" data-type=\"post\" data-id=\"107687\">data security risks<\/a> when access controls or tokens are exposed.<\/p>\n<div style='margin: 8px auto; text-align: center; display: block; clear: both;'> <script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-3675825324474978\"      crossorigin=\"anonymous\"><\/script>  <ins      style=\"display:inline-block;width:300px;height:250px\"      data-ad-client=\"ca-pub-3675825324474978\"      data-ad-slot=\"3421156210\"><\/ins> <script>      (adsbygoogle = window.adsbygoogle || []).push({}); <\/script><\/div>\n<p>Nevertheless, Hackread.com has reached out to <a target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/uber-hacker-rockstar-games-hacked-gta-6-data\/\">Rockstar Games<\/a> for comment. Until then, the claim reflects a real and active attack campaign, but one that has yet to be confirmed for this specific target.<\/p>\n<div >\n<div>\n<div>\n<div>\n<h5> \t\t\t\t\t\t<a target=\"_blank\" rel=\"author\" href=\"https:\/\/hackread.com\/author\/hackread\/\"> \t\t\t\t\t\t\tWaqas\t\t\t\t\t\t<\/a> \t\t\t\t\t<\/h5>\n<div> \t\t\t\t\t\t\t<a target=\"_blank\" rel=\"author\" href=\"https:\/\/hackread.com\/author\/hackread\/\"> \t\t\t\t\t\t\t\t<img src='https:\/\/secure.gravatar.com\/avatar\/3c971597535b97dcf1c986f945aa98a632225995095afc68c2a7c0dff262d639?s=80&#038;d=mm&#038;r=g' srcset='https:\/\/secure.gravatar.com\/avatar\/3c971597535b97dcf1c986f945aa98a632225995095afc68c2a7c0dff262d639?s=160&#038;d=mm&#038;r=g 2x' height='80' width='80' alt=\"ShinyHunters Claims Rockstar Games Snowflake Breach via Anodot\" \/>\t\t\t\t\t\t\t<\/a> \t\t\t\t\t\t<\/div>\n<div>\n<div> \t\t\t\t\t\t\t\tI am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.\t\t\t\t\t\t\t<\/div>\n<div>\n<div> \t\t<a href=\"https:\/\/hackread.com\/author\/hackread\/\" target=\"\"> \t\t\tView Posts\t\t<\/a> \t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Rockstar Games is back in the news, not over Grand Thef [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-45325","post","type-post","status-publish","format-standard","hentry","category-hackread"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45325","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45325"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45325\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45325"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45325"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45325"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}