• joshmn 2 days ago

    I was in federal prison with Sebastien Raoult, one of the ShinyHunters guys. We were in the same unit and talked regularly.

    I was about mid-way through my bid when another inmate told me "new guy in B3 is a another hacker." I got really excited—I'd have someone to talk shop with, at the very least.

    My takeaway from him was that they're a bunch of contemporary "script kiddies" with a lot of time on their hands.

    This tracks.

    • iknowstuff 2 days ago

      And they gave this guy life in prison! Unlucky/stupid to do it after turning 18.

      https://kotaku.com/gta-6-hacker-sentenced-prison-life-185111...

      def curious to hear your story if you’re willing to share

    • thi2 2 days ago

      And then they handed out free beer in the Paulaner Garten

      • DANmode 2 days ago

        If you’re going to make a point, could you?

        • raymond_goo 17 hours ago

          It's a German expression for "you are lying"

    • cbg0 2 days ago

      Update: 4/11/26, 11:45 a.m. ET: Rockstar Games confirmed that a data breach has happened. A spokesperson sent over this statement to Kotaku:

      “We can confirm that a limited amount of non-material company information was accessed in connection with a third-party data breach. This incident has no impact on our organization or our players.”

      • plmpsu 2 days ago

        That's what I would say regardless of if I was considering paying or not.

      • embedding-shape 2 days ago

        > “Rockstar Games, your Snowflake instances were compromised thanks to Anodot.com. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak, along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline.”

        Anyone familiar with "Snowflake" enough to say what sort of data was typically hosted there? Judging by the website and the lack of specifics about the data, I'm guessing it's less about assets, artifacts and stuff like that, and more about financial data and general/generic "business" stuff?

        • Maxion 2 days ago

          In my experienced Snowflake is often used as a data warehouse.

          • hilariously 2 days ago

            It's a database, but you could store basically any OLAP type things there, all your stuff for aggregate customer data for instance.

            • embedding-shape 2 days ago

              Sure, but some databases are sold/bought more by brand recognition and for the type of data rather than actual technical capabilities. Don't ask me why, just very familiar with people making those sort of choices.

              • hilariously 2 hours ago

                Most I would say, but with snowflake it can be anything from some exec's fever dream to them actually paying 10x what they should and accomplishing said fever dream; I've worked on the entire spectrum when it comes to Snowflake.

            • tempaccount5050 2 days ago

              I've seen companies literally mirror every piece of data they have in snowflake to do AI/analytics stuff. There's probably a lot of of shit in there.

              • OoooooooO 21 hours ago

                Snowflake is an MPP OLAP DB usually used for a data warehouse.

                • ziml77 2 days ago

                  Snowflake is typically used for data analytics in my experience. It's going to have financial stuff very likely, but not like raw documents. Definitely not source code.

                  I mean technically you can stuff documents into a column with the BINARY datatype provided they are under 67 MB each, but it's not really meant to be used as a document store.

                • Bender 2 days ago

                  Rockstar Games Hacked, Hackers Threaten a Massive Data Leak If Not Paid Ransom

                  This is just my opinion but that is not much of a threat and I think they should ignore it. Rockstars social platform has always had abhorrent security and players have always been able to easily doxx one another, know where other players live, boot each other out of games to the point of requiring multiple mod-menus just to be in a multi-player lobby in my experience thus extortion of money for player data from snowflake is just redundant.

                  • JCattheATM 2 days ago

                    > players have always been able to easily doxx one another, know where other players live,

                    That sounds unlikely.

                    • undefined 2 days ago
                      [deleted]
                    • seydor 2 days ago

                      How fitting with their games. They should include the hackers in GTA7

                      • rundigen12 2 days ago

                        I honestly expected the demand to be "Release GTA 6 soon or else we will". ...The fact that they're just demanding money is a little disappointing. ;-)

                        • gloxkiqcza 2 days ago

                          Many ransomware groups of today operate in the same way a legal tech startup would. It’s a large organization with clear goals, not just some guys fooling around. It’s a funny thought tho.

                          • specialist 2 days ago

                            How do laypersons (noobs) like me learn about this stuff? Like Wired magazine technical level.

                            I've just started Darknet Diaries podcast. So great.

                            When I worked on electronic medical records, I assumed it was just a matter of time until we were hacked (too). All the most banal reasons: many vendors, shared passwords, root/admin access, etc.

                            I imagine things haven't improved much since.

                            • cyberpunk 2 days ago

                              Darknet Drinking Game: a shot every time something is “unbelievable to me”

                            • robotburrito 2 days ago

                              Yeah but large tech companies don’t just operate by breaking laws like this.

                              • EA-3167 2 days ago

                                Sure they do, Uber is probably the most famous in that regard, but plenty break things and pay a fine later.

                                In fact I’d say that sort of law breaking is downright routine. The key difference is the ability to afford a really good legal and lobbying team.

                                • luqtas 2 days ago

                                  laws that allow big players hurt minorities are any good? Rockstar recently had a strike from their workers by their abuse and layoffs

                                  • potsandpans 2 days ago

                                    You sure about that?

                                    • undefined 2 days ago
                                      [deleted]
                                  • chistev 2 days ago

                                    I know you're joking, but the game will be released eventually anyway.

                                  • chistev 2 days ago

                                    Coincidentally and Interestingly, again, I was reading an old thread from 2015 titled - ProtonMail pays $6k ransom, gets taken out by DDoS anyway

                                    The top comment says -

                                    "NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others."

                                    The top response to that comment says -

                                    "From their blog: https://protonmaildotcom.wordpress.com/ At around 2PM, the attackers began directly attacking the infrastructure of our upstream providers and the datacenter itself. The coordinated assault on our ISP exceeded 100Gbps and attacked not only the datacenter, but also routers in Zurich, Frankfurt, and other locations where our ISP has nodes. This coordinated assault on key infrastructure eventually managed to bring down both the datacenter and the ISP, which impacted hundreds of other companies, not just ProtonMail.

                                    At this point, we were placed under a lot of pressure by third parties to just pay the ransom, which we grudgingly agreed to do at 3:30PM Geneva time to the bitcoin address 1FxHcZzW3z9NRSUnQ9Pcp58ddYaSuN1T2y. This was a collective decision taken by all impacted companies, and while we disagree with it, we nevertheless respected it taking into the consideration the hundreds of thousands of Swiss Francs in damages suffered by other companies caught up in the attack against us. We hoped that by paying, we could spare the other companies impacted by the attack against us, but the attacks continued nevertheless. This was clearly a wrong decision so let us be clear to all future attackers – ProtonMail will NEVER pay another ransom. "

                                    Full thread here -

                                    https://news.ycombinator.com/item?id=10523583

                                    • ronsor 2 days ago

                                      Most hackers actually keep their promises if paid the ransom, nowadays.

                                      It sounds perverse but the incentives require it: if payment didn't bring resolution, no one would pay. As a result, all of the big gangs avoid scamming.

                                      • mh- 2 days ago

                                        That was the state of play in 2015 as well. In the absence of a claim from the group otherwise, I wouldn't be surprised if they simply couldn't get it to stop (on a technical level.)

                                        Way back when, it was a pretty common screwup to accidentally saturate the nodes you were packeting from. So then your C&C couldn't get them to respond, either. Oops.

                                        • nubg 2 days ago

                                          Seems like there is an achilles heel for this business model: A "good guy" could start hacking companies, demand ransom while pretending to be one of the gangs, and then deliberately continuing the attack after the ransom is paid. Precisely to destroy this business model. The gangs would be fuming but there would be nothing they could do? Apart from trying to track down the "good guy" or introducing some sort of (cryptography based or whatever) proof-system that a hack was made by them?

                                          • chistev 2 days ago

                                            This is an interesting thought. I'm waiting to see responses to it.

                                          • 2OEH8eoCRo0 2 days ago

                                            The point is that by paying you incentivize it and make it worthwhile not that the hackers keep promises.

                                            • xoa 2 days ago

                                              >Most hackers actually keep their promises if paid the ransom, nowadays.

                                              I don't think that's actually true, or at least is certainly cannot be taken for granted. Instead, it appears ransom has followed more of the path of Silicon Valley VCs:

                                              .It sounds perverse but the incentives require it: if payment didn't bring resolution, no one would pay. As a result, all of the big gangs avoid scamming.

                                              What you're describing is the expected Game Theory outcome over long periods in an iterated game. This works as long as the payment amount is towards the <salary> side of the potential payment spectrum, where each payment may well be decent money for the work the ransomers put in but not so much that they don't need new ransoms. The problem comes if/when the absolute amount of payment moves from "salary" to the "Exit"/"Retirement" side of the spectrum, ie, heads into what VC would call "Unicorn" status. At some level of money it reaches the point where the ransomers need never work again in their lives, it's enough money to get out of the risky business and live off of it indefinitely. It's now no longer an iterated game but a single game, and in single games defection can be rewarded. It no longer matters if reputation is burned, on the contrary it might be the moment to cash all accumulated rep in.

                                              I think in general, both on the bright and dark sides, this sort of "phase change" in a given market space is worth trying to keep an eye out for because it can result in significantly changed behavior "out of nowhere" that can head in ugly directions very fast.

                                              • nicce 2 days ago

                                                Yeah, this business is based on actually delivering the promise.

                                                • DANmode 2 days ago

                                                  That’s WHY people pay.

                                                  The point being made is: it also flags you as a known-payer,

                                                  for a repeat hit.

                                                  • chistev 2 days ago

                                                    That makes sense. They should pay, then.

                                                  • ndiddy 2 days ago

                                                    > "NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others."

                                                    These days, companies try to mitigate the reputational harm associated with paying the ransom by instead paying security firms that "specialize in ransomware recovery" and claim to have "proprietary trade secret means of decrypting their clients' files". These firms always just happen to charge more than the cost of the ransom for their services. They then provide a non-itemized receipt, and both parties walk away happy and without having to admit to anything. Here's a good article on this practice if you're interested. https://features.propublica.org/ransomware/ransomware-attack...

                                                  • apt-apt-apt-apt 2 days ago

                                                    Honestly, it's gotta feel like Christmas to e-criminals right now.

                                                    So many new toys and ways to scam or extort people. And so many potential innovations to explore as well lol.

                                                    • cindyllm 2 days ago

                                                      [dead]

                                                    • mschuster91 2 days ago

                                                      Please, please let that leak be the source code of GTA SA :D

                                                      • DANmode 2 days ago

                                                        What are you trying to do that you can’t?

                                                        • mschuster91 a day ago

                                                          well GTA3 and Vice City got fully decompiled by some geniuses, 5 got leaked, the missing ones are San Andreas and 4.

                                                          • DANmode a day ago

                                                            I know. So, are you collecting, reading? Or trying to do something?

                                                            • mschuster91 10 hours ago

                                                              The former. Having actual code to look at how people used to do things in the past, especially under the constraints that console games used to have before everything got boiled down to either a mobile phone SoC (Nintendo Switch) or a PC in shrinkwrap (Xbox, Playstation), is worth to have available in some public form.

                                                      • TrailingArbutus 2 days ago

                                                        didn't this already happen like, exactly this way already?? haha/? (bro i NOT gonna survive)

                                                        • bsimpson 2 days ago

                                                          Holy shit - according to the same article, an autistic teen last hacked them and was sentenced to life in an asylum!

                                                          • eugenekolo 2 days ago

                                                            ..again?

                                                            • c420 2 days ago

                                                              [dead]

                                                              • gaythread 2 days ago

                                                                Do we not have GTA5 source already?

                                                                • bakugo 2 days ago

                                                                  Yes, but GTA5 leaked a decade after its release. Rockstar didn't really suffer any significant damage from it.

                                                                  If 6 leaks before release, though, that's a completely different story. I can imagine them actually paying a ransom if that happened.

                                                                  • dvratil 2 days ago

                                                                    Maybe I'm missing something, but how would GTA6 source leak really harm Rockstar? I mean it's unlikely it would be possible to compile a full working game from the leak, and even if so, it's such a non-trivial task, that I don't believe it would hurt sales /that/ much.

                                                                    The only thing I can imagine is the story would get spoiled on the internet, but that's about it.

                                                                    • mh- 2 days ago

                                                                      I feel the need to say it shouldn't be this way, to avoid an onslaught of replies, but:

                                                                      It would be dramatically easier to discover and exploit vulnerabilities/glitches in their multiplayer experience, which is their cash cow.

                                                                      • 3eb7988a1663 2 days ago

                                                                        On the other hand, maybe the community could submit bug fixes for loading times.

                                                                        https://news.ycombinator.com/item?id=26296339

                                                                        • leapingdog a day ago

                                                                          I may be misremembering a drunken conversation with a developer but IIRC the root cause was choice of cross-platform APIs available in early 2010s & the JSON file was tiny when introduced.

                                                                          • 3eb7988a1663 a day ago

                                                                            The problem was not in delivering JSON. There were better ways, but it was good enough.

                                                                            The failure is that loading times had been a complaint for years, and nobody involved lifted a finger. It would be impossible to use the platform without feeling the pain.

                                                                            • leapingdog a day ago

                                                                              I don't really disagree.

                                                                              The software was released on 7 platforms, not counting multiple Windows versions. I don't know the risks or what platforms changes impact today or the test effort involved. I expect "it's still functioning as expected" was the default.

                                                                      • Cpoll a day ago

                                                                        > non-trivial task

                                                                        This is the sort of challenge hackers love, and the prestige is enormous. If it's possible with the leak, I have to imagine some group will do it.

                                                                        • JCattheATM 2 days ago

                                                                          People would compile it and unofficial community servers would quickly pop up.

                                                                          • leapingdog a day ago

                                                                            If GTA6 leaks they will not release this year & layoffs will follow.

                                                                            Different era, but shades of the Half Life 2 leak.

                                                                            • mgol94 2 days ago

                                                                              I would speculate that it’s not about individuals compiling and playing without paying, but that with access to the codebase, creating cracks and online cheats would be trivial, which might actually hurt their bottom line

                                                                              • esskay 2 days ago

                                                                                It'd make it a pain to stop abuse of their online platform when it launches, which is financially problematic given gta 5 online made rockstar billions.

                                                                            • undefined 2 days ago
                                                                              [deleted]
                                                                            • raks619 2 days ago

                                                                              they should just leak the game, rockstar should take the opportunity to create gta7 by training AI using gta6 and then making lifelike visuals. would be better.