Skip to content
Daily gaming industry news.
Follow on social
Gaming Trends, One Bite at a Time
Gaming Trends, One Bite at a Time
BusinessAugust 21, 2026

๐Ÿช Take-Two Goes to Federal Court as GTA VI Leaks Keep Coming

Hello there, cookie munchers, leak chasers, Vice City tourists, and everyone who just discovered that copyright law has a detective mode. Take-Two Interactive has…

Leo12 min read
Kiki follows a glowing digital evidence trail through a late-night courthouse records corridor while Chip braces an evidence cart beside two secured server cabinets.

Hello there, cookie munchers, leak chasers, Vice City tourists, and everyone who just discovered that copyright law has a detective mode.

Take-Two Interactive has moved beyond chasing individual reposts of leaked Grand Theft Auto VI footage. On August 20, the company filed multiple DMCA subpoena petitions in the U.S. District Court for the Southern District of New York seeking records from Microsoft and Discord that could help identify the person or people behind the CyberLeek persona and trace how the leaked material moved online. Kotaku reported the filings on August 21, including requests for account identifiers, IP addresses, linked accounts, device information, OneDrive content, and Microsoft investigative records tied to the leak.

The legal move arrives while CyberLeek continues releasing material that appears to come from GTA VI. One clip is especially important: Jason exits a plane and deliberately shoots the word “LEEK” into a wall. PC Gamer says that strongly suggests the leaker had access to a playable build, or at least access to someone who could perform bespoke actions inside one. Fresh footage was still surfacing on August 21 even after the court filings became public.

That gives us a serious story without upgrading every rumor into a fact. The available evidence supports probable playable-build access and an escalating copyright investigation. It does not publicly prove that CyberLeek possesses the complete retail game, current GTA VI source code, or that Rockstar India was the route into the project. Social media has already filled those blanks anyway.

Take-Two wants identities, not just takedowns

The filings matter because they change the purpose of the response. Copyright takedowns remove copies. A Section 512 subpoena is designed to identify an alleged infringer. The U.S. Copyright Office explains that a rightsholder can ask a federal district court to issue a subpoena directing an online service provider to disclose information sufficient to identify the poster of infringing material.

That is also why the phrase “the federal government is investigating CyberLeek” would be sloppy. Take-Two is using a federal-court mechanism available under the DMCA; the public filings do not establish an FBI investigation, a criminal charge, or an arrest warrant. Microsoft and Discord are being asked for records because they may possess information relevant to identification. They are not accused of causing the leak.

According to the filing details reproduced by Kotaku, Take-Two asked Microsoft for internal business and investigative records associated with Microsoft’s own investigation of the CyberLeek persona, plus identifiers including registration emails, registration and last-login IP addresses, phone numbers, linked connections, device identifiers, telemetry, and relevant OneDrive content. Discord was asked for records associated with accounts communicating in named servers and communities. Both requests specify September 4 as the requested production deadline.

The scope is broad enough that it may collect information about people who discussed or redistributed the leaks without establishing that they were the original source. Being named in a records request is not the same as being accused of hacking Rockstar. The useful conclusion is narrower: Take-Two is trying to reconstruct a digital trail rather than simply delete the next clip.

๐ŸฆŠ Kiki: Rockstar legal did not press the “call the FBI” button. Take-Two opened the copyright toolbox and found the setting labeled WHO OWNS THIS ACCOUNT? That is still a nasty upgrade for anyone behind the leaks. If your anonymous crusade touches cloud storage, account logins, linked services, devices, or communities that keep records, the final boss may not be a lawyer in a black SUV. It may be metadata quietly remembering where you were.

๐Ÿช Chip hides behind a tiny evidence box, then notices the box has already logged his last three IP addresses.

The “LEEK” wall changes the risk

The first CyberLeek posts on August 18 looked authentic enough that copyright claims quickly started removing reuploads. The strongest evidence came later. PC Gamer highlighted the moment when Jason deliberately uses rifle fire to spell “LEEK” on a wall. Previous footage could theoretically have been pre-recorded material passed to the leaker. A bespoke action performed for the identity behind the leak makes direct or cooperative access to a playable build much more plausible.

Plausible is not the same as complete. The clip does not reveal how much of the game is accessible, how old the build is, whether every mission or story chapter is present, or whether CyberLeek personally controls it. Another person with access could be recording footage on request. A limited test build could contain enough systems to produce convincing free-roam clips without containing the finished game.

There are signs that at least some material is relatively recent. Kotaku noted that one leaked radio sequence includes Tate McRae’s “Sports Car,” released in January 2025. That does not timestamp the build precisely – licensed music can circulate before commercial release – but it makes claims that every clip is ancient harder to accept at face value.

The leaks also did not stop when the subpoenas became public. On August 21, Kotaku reported another clip centered on a hypercar and detailed city streets. We are deliberately not linking to or reproducing the leaked gameplay itself. Official Rockstar imagery is more than enough to identify the game while we discuss what the reporting establishes.

๐ŸฆŠ Kiki: Shooting LEEK into a wall is a pretty convincing receipt for “someone can touch the game.” It is not a magical certificate that says COMPLETE RETAIL BUILD, ALL MISSIONS UNLOCKED, SOURCE CODE INCLUDED. The internet saw one bespoke action and immediately speedran the forensic ladder. Playable became complete. Complete became source code. Source code became “they can spoil everything.” Calm down. The evidence is already bad enough for Rockstar without adding fan-fiction features to the breach.

๐Ÿช Chip prints a certificate labeled FULL GAME CONFIRMED, realizes nobody signed it, and feeds it into the shredder.

Official GTA VI promotional image. Image: Rockstar Games.
Official GTA VI promotional image. Image: Rockstar Games.

Source code, Rockstar India, and the rumor pile

The current CyberLeek story is already absorbing details from Rockstar’s previous breaches. That is how a real leak becomes a fictional super-breach.

In 2022, Lapsus$ member Arion Kurtaj stole and leaked around 90 early GTA VI clips. Court reporting later documented that he threatened Rockstar with releasing source code unless the company contacted him. The Guardian reported that history when Kurtaj received an indefinite hospital order in 2023. That source-code threat belongs to the 2022 case. It is not evidence that CyberLeek has current GTA VI source code in 2026.

We found no credible current reporting that independently establishes possession of GTA VI source code by CyberLeek. Reports do document threats to keep leaking gameplay and to target publishers that violate the group’s self-declared consumer-rights rules. Until source code is demonstrated or confirmed by a credible source, Game Cookies should not write it as fact.

The India claim deserves the same discipline. Rumors circulating online have blamed Rockstar India or an employee there, but Indiatimes could not substantiate the allegation and noted the absence of confirmation from Rockstar. More importantly, Rockstar India is a Rockstar development studio. Calling the rumor proof that an external Indian outsourcing studio was hacked changes the claim before the underlying claim has even been verified.

Predicting that publishers will pull work out of India or Asia from this rumor therefore requires two unsupported jumps: first deciding the leak originated there, then turning an internal Rockstar studio into a generic outsourcing vendor. The industry can have a serious conversation about distributed development security. It should start with access architecture, not a map.

๐ŸฆŠ Kiki: The 2022 hacker threatened source code, so apparently the internet has decided “source code” is a reusable GTA leak accessory. Sorry, no. Old evidence does not become new evidence because both folders say GTA VI. And if the breach route eventually involves Rockstar India, investigate the route. Rockstar India is not a magic synonym for “outsourcing to Asia.” Blaming an entire region before anyone has shown how the material was accessed is not cybersecurity analysis. It is geography wearing a lanyard.

๐Ÿช Chip pins a giant map to the wall, realizes it contains zero breach logs, and slowly rolls it back up.

The consumer-rights manifesto comes with a memecoin

CyberLeek has tried to frame the campaign as punishment for anti-consumer behavior. PC Gamer documented a manifesto demanding an end to digital preorders, what the group calls fake single-player DLC, and the loss of single-player content when online infrastructure disappears. CyberLeek has also demanded apologies and “concrete” commitments from publishers while threatening more leaks.

One complaint lands on a real Rockstar decision. Rockstar’s own support page says the physical version of GTA VI contains a digital download code and no disc. Buyers can receive the box from November 12 to begin preloading before the November 19 launch. People who dislike code-in-box physical editions do not need a hacker to tell them why that feels like ownership cosplay.

But consumer-rights language does not launder the method. CyberLeek has promoted a Solana memecoin alongside the leaks and said the money would support a secret project. The token makes the campaign financially self-interested whether or not the manifesto contains complaints people genuinely share. A cause can have valid grievances and still choose destructive tactics.

The preservation campaign Stop Killing Games publicly rejected CyberLeek’s methods, urged people not to send money, and warned that illegal leaks can damage legitimate advocacy with lawmakers. That reaction matters because some of CyberLeek’s language overlaps with preservation arguments. The people doing the legal advocacy do not want the hack wearing their jersey.

๐ŸฆŠ Kiki: I can think a sixty-to-eighty-dollar box containing a download code is stupid and still not buy the hacker coin. These positions can coexist. My brain has multithreading. Consumer rights do not become more consumer-rightsy when the protest comes with a QR code asking consumers to speculate on a memecoin. If your pitch is “publishers exploit players, so fund my mysterious token while I threaten developers’ unreleased work,” the moral high ground has already fallen through the map.

๐Ÿช Chip puts one coin into a machine labeled DIGITAL RIGHTS and gets back a receipt reading SECRET PROJECT. He requests a refund.

The security lesson is about access paths, not geography

Rockstar had another confirmed security incident only four months ago. In April, the company said a third-party provider breach exposed a limited amount of company information. The Verge reported that ShinyHunters claimed access through Rockstar’s Snowflake environment via compromised systems at analytics provider Anodot. Rockstar said the incident had no impact on operations or players.

There is no public evidence tying that April incident to CyberLeek. Putting the two events next to each other is useful for risk context, not causation. A third-party cloud breach in April does not explain how August gameplay was acquired unless investigators establish a connection.

The broader security principle is much less glamorous than blaming a country. NIST’s Zero Trust guidance emphasizes protecting resources through granular identity and access controls rather than assuming trust from network location or organizational affiliation. For large distributed game productions, the important questions are which identities can reach which builds, how privileges are segmented, how vendors and employees are authenticated, how unusual access is detected, and how quickly credentials can be revoked.

That applies whether the eventual route is an internal employee, a contractor, a partner, a compromised cloud account, stolen credentials, or something nobody has reported yet. Geography can influence operations and legal jurisdiction. It does not tell you which permission was too broad.

Calling the incident “industrial espionage” is also premature as a legal label. U.S. economic-espionage law under 18 U.S.C. ยง1831 specifically concerns trade-secret theft intended to benefit a foreign government, instrumentality, or agent. We do not publicly know CyberLeek’s identity, acquisition method, beneficiary, or whether a state actor is involved. “Cybersecurity breach” and “unauthorized leak of proprietary development material” describe the present evidence without inventing the missing motive.

โญ Byte: Confirmed timeline and limits:

  • August 18: CyberLeek begins posting apparent GTA VI gameplay and a manifesto.

  • August 20: footage showing Jason deliberately spelling “LEEK” with bullet impacts makes direct or cooperative playable-build access much more plausible.

  • August 20: Take-Two files DMCA subpoena petitions in federal court seeking records from Microsoft and Discord.

  • September 4: the filings request production of the specified records by this date.

  • August 27: Rockstar’s official GTA VI Extended Look is scheduled.

  • November 19: Rockstar’s official release date for GTA VI. Still unconfirmed publicly: a complete retail build, current GTA VI source code, a Rockstar India breach route, an outsourcing-vendor origin, or a connection between CyberLeek and the April third-party breach. The timeline measures public events and reporting, not the hidden path used to obtain the material.

What happens next

The next obvious date is September 4, when Microsoft and Discord are asked to produce the requested records. Compliance could give Take-Two useful identifiers, or it could lead into proxies, burner accounts, incomplete logs, unrelated users, or another service entirely. The filings show where Take-Two is looking; they do not guarantee that the original leaker is sitting behind one clean account waiting to be named.

The second date is August 27. Rockstar’s official GTA VI page still advertises an Extended Look at 3 PM ET. That creates an unusual marketing collision: the most anticipated game in the industry is supposed to reveal itself on Rockstar’s schedule while an anonymous leaker keeps trying to rewrite the calendar in public.

For players, the safest approach is boring but useful: avoid executable files and fake “GTA VI build” downloads, do not assume every AI-generated clip or recycled 2022 video belongs to the current breach, and treat spoilers as increasingly plausible without treating every rumor as confirmed. For industry teams, the useful questions are access, segmentation, vendor paths, logging, and how much one compromised identity can touch before somebody notices.

๐ŸฆŠ Kiki: The leak is already serious. That is exactly why it does not need fan-made upgrades. Take-Two wants identities. Rockstar wants its reveal calendar back. Players want to avoid spoilers. CyberLeek wants to be a consumer-rights vigilante with a memecoin shop attached. Everybody has enough problems without us adding “India did it,” “the source code is gone,” and “the feds are hunting him” because those phrases perform better on a feed. Evidence first. Panic can wait its turn.

๐Ÿช Chip sets three rumor folders on fire, accidentally saves the one labeled COURT FILING, and receives a promotion to senior fact-checker.

In the end…

Take-Two has escalated the GTA VI leak response from copyright whack-a-mole to identity discovery. The company is using federal-court DMCA subpoenas to seek records from Microsoft and Discord, while fresh leaked material continues appearing and the playable-build evidence makes the situation harder to dismiss as a batch of stolen videos.

The leak is dangerous enough without pretending we know its origin or full scope. There is strong reason to think someone had interactive access to GTA VI. There is not public proof of a complete final build, current source code, an India-based breach route, or a connection to April’s third-party incident. Those blanks belong to the investigation, not the algorithm.

The larger industry warning is about access architecture. Huge games are built across studios, partners, cloud systems, remote endpoints, external services, and thousands of people. The security question is how far one compromised identity can travel through that production chain. If the answer is “far enough to reach the most valuable unreleased game in the world,” the fix will be more complicated than changing the country on a vendor spreadsheet.

โš™๏ธ Stay source-aware like the person who checks the court filing before forwarding the screenshot.

โš™๏ธ Keep confirmed access, reported claims, and rumor in separate folders like Chip protecting the only evidence box he did not set on fire.

โš™๏ธ And remember: a leak can be catastrophic without giving every rumor a six-star wanted level.

๐ŸฆŠ Kiki ยท ๐Ÿช Chip ยท โญ Byte ยท ๐Ÿฆ Leo

Tips, leaks, and suspicious download codes: contact us here!

Stay in the loop

Follow Game Cookies on social.

Daily bites on the platforms you already scroll. Pick your poison.

Share this story