ShinyHunters Claims Rockstar Games Cloud Breach via Snowflake; Ransom Deadline Expired
ShinyHunters has claimed responsibility for breaching Rockstar Games' cloud infrastructure via Snowflake, with Rockstar confirming unauthorized data access to Kotaku. The group's April 14 extortion deadline has passed, making data publication likely if ransom was not paid. The attack vector reprises ShinyHunters' 2024 Snowflake credential-stuffing campaign that compromised ~165 organizations including Ticketmaster and Santander Bank. The playbook is well-established: harvest credentials from infostealers or credential dumps, target Snowflake tenants lacking enforced MFA, exfiltrate in bulk, then run staged extortion. Financial institutions with Snowflake deployments share the same threat profile if MFA enforcement, network policy restrictions, and session token auditing have gaps. Note: the enrichment pipeline misattributed this to Scattered Spider. ShinyHunters and Scattered Spider are distinct actors with different TTPs and membership — the 2022 Rockstar breach (via corporate Slack) was Scattered Spider/LAPSUS$; this is a different group exploiting a different vector.
ShinyHunters keeps operating despite arrests across multiple jurisdictions — unusual resilience for a financially-motivated group. The more important pattern: Snowflake as shared cloud data infrastructure remains a single-point-of-failure across hundreds of enterprises. One compromised tenant credential, no MFA, mass exfil. The 2024 campaign proved this at scale, and they're running the same play again. If you're on Snowflake, this is your quarterly reminder that credential hygiene on cloud data platforms is existential.