Business Insights Cybersecurity Blog by Bitdefender

CyberLeek: Extortion Built for an Audience, Not a Victim

Written by Jade Brown | Sep 01, 2026

CyberLeek positions itself as a financially motivated extortionist group, taking part in the theft of data and intellectual property to intrigue an audience and grow potential revenue streams in the process.

The recent CyberLeek operation, backed by a message ofNo Disc, No Peace puts on the appearance that the threat actor advocates for gamers everywhere, despite self-serving motives. 

For Grand Theft Auto (GTA) fans, 2026 is big. Fans have been waiting for more than four years for the new release, GTA VI, to become available in November. Months ahead of that timeline, in mid-August, CyberLeek published leaked scenes and gameplay consisting of Grand Theft Auto (GTA) VI material spanning twelve gameplay subjects, including a mix of old and new content.

Leaked videos and images featured a hypercar, plane, taser scene, junkie, nudist town, a basketball video, and map sneak peeks. A video tied to the group was also distributed online which established that they apparently have a GTA VI build in their possession and could potentially spoil the ending of the game.

On the group’s leak site, it claims this is CberLeek’s effort to push back against corporate profits in the gaming industry.

The Gaming Leaks Precedent

This GTA VI leak may come as a surprise, however this is not the first leak of its kind. GTA VI has been in development since early 2022, making it a highly anticipated installment. In 2022, LAPSUS$ targeted several video game developers and also orchestrated a leak that consisted of 90 GTA VI video clips in addition to segments of the game source code. No connection has been drawn between LAPSUS$ and CyberLeek to date, but there is a precedent for this type of gaming leak.

Grand Theft Auto is known for having an open, heavily involved mapping community. These are groups spread across Discord communities, gaming marketplaces, and gaming related sites. that develop and share custom maps and game modifications. Mappers share unique updates and locations within servers and some use these builds to generate income, selling access to certain models or blocking them behind a paywall. That creates a customer base for CyberLeek, as some mappers might want to leverage any games or map leaks.

The Operation and CyberLeek Manifesto

CyberLeek operates differently than conventional extortion groups; it has not sought financial payment from the victim organization to prevent further leaks. There is also no evidence of the use of any encryptors or ransom demands in the group’s operations. No initial access vector, execution chain, persistence mechanism, privilege escalation path, lateral movement method, or command and control infrastructure have been documented either.

However, we do know CyberLeek maintains a community called Leek Road on their dedicated site. The high demand for GTA VI makes it essential for them to maintain this community (and a presence elsewhere) to keep others interested in their activities. Nearly a week after the GTA VI leak, CyberLeek 2.0 was launched.

Image: CyberLeek's online community called Leek Road.

CyberLeek’s manifesto, featured on Leek Road, calls for an ‘open road’ to share games with the masses, along with an anti-licensing, player-first belief system. This type of dogma appeals to a wide audience of sympathizers and consumers across the gaming community.

Throughout 2026, some gamers have expressed discontent with the gaming experience and industry, voicing concerns over the rising cost of video games (like the $999.99 cost for GTA VI’s ultimate edition), the move from the possession of physical media to digital, and widespread delays from the development to the production and distribution of finished games. Here’s a small portion of the group’s manifesto:

Image: A final message from CyberLeek's manifesto.

CyberLeek also promotes the use of cryptocurrency tokens to its audience through polls; tokens are sent to wallet addresses, and addresses for topics that generate the most tokens are prioritized for future leaks. While documentation of the revenue CyberLeek has collected so far through this polling process is absent, it is a creative way to monetize leaks and ensure audiences engage with the content.

CyberLeek’s Presence Online

Excluding the dedicated data leak site, CyberLeek also maintains a Telegram channel named CyberLeek Official. While the channel dates back to late 2024, its first victim publication referencing a specific leak did not emerge until August 2026, which is highly unusual. However, at the time of this release, there are more than 28,0000 members.

Numerous Telegram channels have also emerged, making it difficult to uncover CyberLeek’s other platforms despite ongoing reports of violations of Telegram’s terms of service. While multiple X accounts have popped up with handles and derivations of the CyberLeek name, none have been validated as official media outlets connected to the group.

The Opportunity

CyberLeek positions itself as a financially motivated extortionist group, laying the groundwork for a monetization operation. A phased leak of GTA VI content has allowed CyberLeek to build up their brand name, stay relevant, and potentially profit from future leaks containing greater volumes of sensitive information. Consider this: CyberLeek possesses not only video content, but also a developer build. Why stop there?

Members and interested sympathizers can serve as the channel to receive modified game add-ons, trade platform currencies and other services, and promote memecoins—all avenues that can lead to profit without needing a negotiation plan or process to haggle with the affected organization.

What the group monetizes is attention. The source material supports several revenue streams running in parallel: the leaked content itself, derivative and modified versions of that content, opportunities to trade in platform and adjacent services connected to the property, group-promoted cryptocurrency tokens, and paid advertising placement alongside the leaks themselves. CyberLeek has already promoted opportunities for buyers to acquire advertising space for upcoming projects where additional leaks are published,  with one sponsorship priced at $165,000.

If we contrast this type of approach with traditional ransomware or data exfiltration, we see the economic model does not decay when a victim refuses to engage or pay. For CyberLeek, refusal is content: it extends the story, gives the group something to post about, and keeps the audience present for the next release. This rang true even amid the official extended look at GTA VI released at the end of August.

Considerations for Organizations

Organizations whose incident response assumes that refusing to negotiate ends an intellectual property matter are positioned to fail when combating an operational model like the one CyberLeek uses.

Large, consumer-facing organizations with intellectual property have audiences waiting to get their hands on it before a breach becomes news. Entertainment and gaming properties sit at this juncture of desirable targets, with unreleased product designs, pre-launch assets, and other scripted content being the crown jewels.

This has consequences for organizations and defenders.

Most organizations are poor targets for CyberLeek’s model. Desirable targets should recognize that the material most likely to be exposed is not necessarily the material their data classification scheme rates as most critical. Classification schemes rank data by the damage its disclosure does to the organization. A threat actor like CyberLeek takes a different approach, as they may instead rank intellectual property based on projections of how many people want to see it, regardless of whether the design is finished or on the market.

A pre-release build also carries far less regulatory and contractual risk than distributing a customer database (and far more audience value), so it is often protected by the controls applied to ordinary internal files rather than controls applied to regulated data.

Two operational consequences follow, and both are worth understanding.

1. Distribution cost. Material an audience chooses to spread does not need infrastructure the group has to run, pay for, or defend against. Sympathetic framing converts followers into a distribution layer. Platform disruptions due to terms-of-service violations remove a node; they do not remove an audience.

2. The target’s response. A denial issued into a neutral information environment is received as a factual claim to be assessed. A denial issued into an audience that arrived with a prior grievance about the industry is received as a corporate statement to be discounted. This means an organization's communications teams may be tasked with competing against a framing established long before it spoke, putting them at a disadvantage despite their best efforts. A petition filed for subpoenas against entities distributing copyrighted material may also provoke sympathizers to side with the leaker regardless of whether all leaks have been verified.

For CyberLeek, authentic material and fabricated but convincing material produce the same outcome. Both draw the audience to the channel, both drive attention to the revenue surfaces, and both damage the claimed victim's position while the claim is being assessed.

Organizations preparing to defend against similar data breaches should assume that content can be fabricated, partially fabricated, or recycled. The distribution of recycled content amongst new updates is a plausible outcome, as unreleased development material connected to the same title was published without authorization in September 2022 by Arion Kurtaj, an individual associated with the Lapsus$ group. The 2022 material has circulated publicly and remains available, and no official authorization for its release has been documented.

Recommendations for Organizations

It is advised that organizations do the following if they identify suspicious behavior that follows the CyberLeek pattern:

  • Verify claims and evidence of stolen data. If the origin of any stolen material is unverified, keep in mind that audiences may be manipulated into accepting that material as authentic. As a result, containment should not be the next step if there is no evidence of an observed intrusion.

  • Build a capability to maintain an inventory of sources (for original and leaked data), a file control history, asset pipeline networks, and artifacts to understand when files may have been exposed and to separate new material from old. Hash material related to known exposures and keep catalogs of this material to date.

  • Ensure that planning to address media correspondence and legal action are sound before a suspicious event occurs. Hash and catalog material known to have been exposed. Deploy a capability to monitor BOTH the clearnet and closed communities for leaked material.

  • Do not implement a takedown strategy that is solely dependent on platform response. This should only be a last resort as it does not serve as a proactive action in a response plan. Ensure that any evidence is preserved before requesting the removal of material or channels. Prepare the request as a repeatable process against successor infrastructure rather than a single filing and decide in advance who monitors for reconstitution and how quickly the next request goes out.

Conclusion

Whether CyberLeek’s model is successful and can be reproduced by other threat actors remains to be seen. Three aspects are worth watching closely.

First, watch whether phased releases
continue on the schedule the group has implied, since staged disclosure is the mechanism the entire model depends on. An abandoned schedule suggests the inventory may have been thinner than claimed.

Second
, tracking whether an unrelated victim emerges could result in additional insights. An audience built over twenty-one months has grown, but nothing yet shows it transfers to the material of a different property. An efficient operational model would require that it does so to prevent CyberLeek from becoming stagnant.

Third, let's see whether the audience survives repeated takedowns, despite CyberLeek’s portability, as pressure mounts to dismantle them. Duplicate or copycat accounts may also challenge the group’s operations going forward.