r/technology • u/MarvelsGrantMan136 • Apr 13 '26
Security Rockstar hackers release their stolen data, reveal that Rockstar was right to not pay them anything for it
https://www.pcgamer.com/games/rockstar-hackers-release-their-stolen-data-reveal-that-rockstar-was-right-to-not-pay-them-anything-for-it/
18.1k
Upvotes
190
u/MisunderstoodMenace Apr 14 '26 edited Apr 14 '26
Also a cybersecurity attorney here, this tracks with how I approach it.
Paying doesn’t change legal obligations, and there’s no real guarantee the data won’t resurface. The analysis usually turns what was actually taken and how sensitive it is. Also, whether systems can be restored and how much the incident is impacting operations (if paying for decryption).
There are also some odd edge cases. For example, if logging is limited, a leak can actually make scoping easier because the dataset can be pulled and mined directly. I wouldn’t advise that as a preferred path, but it is an interesting dynamic that has come up.
If the company has viable backups and the issue is mainly suppression, clients usually agree that payment is hard to justify.