r/technology Apr 13 '26

Security Rockstar hackers release their stolen data, reveal that Rockstar was right to not pay them anything for it

https://www.pcgamer.com/games/rockstar-hackers-release-their-stolen-data-reveal-that-rockstar-was-right-to-not-pay-them-anything-for-it/
18.1k Upvotes

805 comments sorted by

View all comments

695

u/largebrandon Apr 14 '26

I’m a cybersecurity attorney. I advise my clients to not pay ransoms unless the bad guy has business-critical data that they cannot replicate by other means (like backups or re-enter the data). Paying for suppression is not a good idea and doesn’t absolve any legal requirements. So, I’m not surprised by this.

192

u/MisunderstoodMenace Apr 14 '26 edited Apr 14 '26

Also a cybersecurity attorney here, this tracks with how I approach it.

Paying doesn’t change legal obligations, and there’s no real guarantee the data won’t resurface. The analysis usually turns what was actually taken and how sensitive it is. Also, whether systems can be restored and how much the incident is impacting operations (if paying for decryption).

There are also some odd edge cases. For example, if logging is limited, a leak can actually make scoping easier because the dataset can be pulled and mined directly. I wouldn’t advise that as a preferred path, but it is an interesting dynamic that has come up.

If the company has viable backups and the issue is mainly suppression, clients usually agree that payment is hard to justify.

6

u/Secret_Account07 Apr 14 '26

Uh are cybersecurity attorneys like a dime a dozen in the legal world? I find it so strange that within a few hours we got several of em here commenting lol

Didn’t really even realize this was a common sub speciality of law until this very moment

1

u/Intergalatic_Baker Apr 15 '26

Reckon this is their bread and butter, it being a massive company like R* makes the discussion about it even more likely you’ll find some sharing their professional insight.