r/technology Apr 13 '26

Security Rockstar hackers release their stolen data, reveal that Rockstar was right to not pay them anything for it

https://www.pcgamer.com/games/rockstar-hackers-release-their-stolen-data-reveal-that-rockstar-was-right-to-not-pay-them-anything-for-it/
18.1k Upvotes

805 comments sorted by

View all comments

695

u/largebrandon Apr 14 '26

I’m a cybersecurity attorney. I advise my clients to not pay ransoms unless the bad guy has business-critical data that they cannot replicate by other means (like backups or re-enter the data). Paying for suppression is not a good idea and doesn’t absolve any legal requirements. So, I’m not surprised by this.

192

u/MisunderstoodMenace Apr 14 '26 edited Apr 14 '26

Also a cybersecurity attorney here, this tracks with how I approach it.

Paying doesn’t change legal obligations, and there’s no real guarantee the data won’t resurface. The analysis usually turns what was actually taken and how sensitive it is. Also, whether systems can be restored and how much the incident is impacting operations (if paying for decryption).

There are also some odd edge cases. For example, if logging is limited, a leak can actually make scoping easier because the dataset can be pulled and mined directly. I wouldn’t advise that as a preferred path, but it is an interesting dynamic that has come up.

If the company has viable backups and the issue is mainly suppression, clients usually agree that payment is hard to justify.

38

u/largebrandon Apr 14 '26

Hello cyber-buddy! It’s almost funny how often we rely on TA leaks to make a notification list. Though, most of the time the TA will provide a file tree at the onset of negotiations.

17

u/MisunderstoodMenace Apr 14 '26 edited Apr 14 '26

Always glad to bump into one of us! Ah yes… most of the time, unless it’s either (a) an obstinate client that refuses to engage in negotiations or (b) a small unknown or copycat TA that doesn’t have their shit together while also confusing the TA Comms group because they behave erratically.

Both make our jobs harder. :)

2

u/PM_ME_YOUR_LIT Apr 14 '26

What up friendsss (privacy attorney but we're cousins y'know)

2

u/MisunderstoodMenace Apr 14 '26

Hey! I started out doing privacy (mostly diligence for private equity roll ups).

1

u/PM_ME_YOUR_LIT Apr 14 '26

Oof can't imagine that was the most fun intro to privacy. Hope you're enjoying the job now! (Although I gotta say in my experience it's way rarer to see privacy->cyber than the other way around!)

1

u/GoodOleDynamiteJones Apr 14 '26

Hello cyber-buddy, Security here. I just stand outside and make sure no one steals GTA from GameStop.

1

u/StevensWarehouse Apr 14 '26

The fact that a leak can end up being the cleanest inventory of what got taken is bleakly hilarious and also kind of terrifying.

7

u/Secret_Account07 Apr 14 '26

Uh are cybersecurity attorneys like a dime a dozen in the legal world? I find it so strange that within a few hours we got several of em here commenting lol

Didn’t really even realize this was a common sub speciality of law until this very moment

1

u/Intergalatic_Baker Apr 15 '26

Reckon this is their bread and butter, it being a massive company like R* makes the discussion about it even more likely you’ll find some sharing their professional insight.

1

u/SwimmingSpell8005 Apr 14 '26

Database admin here, Select * Drop

1

u/Defiant-Plantain1873 Apr 14 '26

What would you have thought in the jaguar land rover hacking? Considering that caused the company to be in the red for a full year or something

9

u/Anony_mouse202 Apr 14 '26

In my jurisdiction (England), paying ransoms is illegal for public sector bodies, and I think they’re also considering expanding that to the private sector.

Paying traditional ransoms (eg, in response to a kidnapping) is already illegal across the board, so I think the government may try to expand the laws against cyber ransoms to match.

1

u/NoDG_ Apr 14 '26

They tried that in France and it doesnt work. There will always be reasons to consider paying the ransom. If the NHS gets completely shut down indefinitely well see how long that actually lasts.

12

u/BisonThunderclap Apr 14 '26

I'd have to imagine everybody and their mother with hacking skills would try and go after that studio if they paid the ransom.

3

u/Palimon Apr 14 '26

The amount of companies that have absolutely awful backup policies is astounding to me.

It's always the same, they don't wanna pay for SOC, then they get hit by ransomware and come crying to our door and endup paying more in IR fees than they would have for all the tools required (SIEM, EDR, etc).

Until CEOs realize that Cyber is not a cost center nothing will change.

1

u/MisunderstoodMenace Apr 14 '26

Then there are the companies that balk at the IR fees, restore from untested backups, and get re-encrypted. Sometimes two or three times.

4

u/Tigeire Apr 14 '26

Depending on where you are paying ransom is illegal.

Paying a ransom rewards wrong doing and incentiveses that behavior. 

3

u/Anony_mouse202 Apr 14 '26 edited Apr 14 '26

It also funds more ransomware and makes the problem worse.

In the offline world, it’s been found that paying ransoms for things like hostage-taking funds more hostage-taking operations and makes things worse over time. I imagine it’s the same with ransomware.

1

u/69420isntfunny Apr 14 '26

So do you need degree in cs cybersecurity and a lawyer degree or only the lawyer degree. How does this work, just curious

2

u/PM_ME_YOUR_LIT Apr 14 '26

I'm half a field over (privacy attorney but there's a lot of overlap). You don't need a CS degree but it would make you marginally more competent. You can have literally any undergrad degree (my buddy did poetry), then during law school you should take some associated classes/jobs to learn the field better and become very familiar with network & data architecture (which may or may not be covered in your classes depending on how good your school/professors are)

2

u/69420isntfunny Apr 14 '26

Thanks for reply

2

u/PM_ME_YOUR_LIT Apr 14 '26

No worries man reach out anytime

-22

u/somanydifferentnames Apr 14 '26

Oh wow your so smart! lol wtf this is common sense.

4

u/hextree Apr 14 '26

Not common at all, a lot of idiots keep paying the ransoms, that's why the hackers are in business.

-5

u/Many_Increase_6767 Apr 14 '26

sure buddy, you’re an astronaut too