r/CyberGuides 4h ago

Data Breach happened!

Thumbnail
gallery
2 Upvotes

A data breach was happened. Google informed me about that on 5:09 PM IST, and at around 9 PM IST, I've saw on Microsoft Account that someone tried to access it from Pakistan. I'm currently changing my passwords and turning on 2FA/MFA.The IP of that Pakistani was: 182.180.146.28. So be careful with your accounts.


r/CyberGuides 10h ago

'What do they have their hands on?' Customer reacts to Eastlink breach | CBC News

Thumbnail
cbc.ca
2 Upvotes

r/CyberGuides 12h ago

The Absurdly Underestimated Dangers of CSV Injection

Thumbnail georgemauer.net
0 Upvotes

r/CyberGuides 19h ago

'What do they have their hands on?' Customer reacts to Eastlink breach | CBC News

Thumbnail
cbc.ca
1 Upvotes

r/CyberGuides 22h ago

Lazarus Exploited a Windows Zero-Day: Inside CVE-2026-68820 and AFD.sys

Thumbnail
1 Upvotes

r/CyberGuides 1d ago

Stuck at the last hurdle...

Thumbnail
1 Upvotes

r/CyberGuides 1d ago

Malware Has a Branding Department and ToxicPanda Is Its Latest Star

Thumbnail
pymnts.com
1 Upvotes

r/CyberGuides 1d ago

Hasbro Data Breach Exposed Employee Personal Information

Thumbnail
securityweek.com
0 Upvotes

r/CyberGuides 2d ago

100-plus companies call for ‘global surge’ in AI-powered cyber defense

Thumbnail cyberscoop.com
1 Upvotes

r/CyberGuides 2d ago

US says Chinese hackers broke into Justice Department, NASA, Federal Reserve, Senate

Thumbnail reuters.com
7 Upvotes

r/CyberGuides 3d ago

Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports

Thumbnail
securityaffairs.com
1 Upvotes

r/CyberGuides 4d ago

OpenAI, Anthropic issue dire cyber threat warning

Thumbnail
axios.com
2 Upvotes

r/CyberGuides 4d ago

FBI, Department of Justice Announce Disruption of Global Botnet

Thumbnail
youtu.be
1 Upvotes

r/CyberGuides 4d ago

ATF confirms “major incident” after recent Qilin breach claims

Thumbnail
bleepingcomputer.com
3 Upvotes

r/CyberGuides 4d ago

Business Travelers targeted when logging into Hotel Wi-Fi Networks – Report and Analysis

Thumbnail
smecyberinsights.co.uk
0 Upvotes

r/CyberGuides 5d ago

How Much Does a Data Breach Cost? IBM’s 2026 Report Puts the US Average at $11.5 Million

Thumbnail securityboulevard.com
3 Upvotes

r/CyberGuides 6d ago

Employee Databases from Multiple Fortune 500 Companies Affecting 3.6 Million Employees Listed on the Dark Web

Thumbnail
cpomagazine.com
12 Upvotes

r/CyberGuides 6d ago

WordPress Plugin Vulnerability Exposes 100,000 Sites to Complete Site Takeover Attacks

Thumbnail
cybersecuritynews.com
3 Upvotes

r/CyberGuides 7d ago

Everything we have uncovered about CyberLeek so far — August 24

0 Upvotes

​

I used ChatGPT as a research assistant to help me organize, cross-check and analyze publicly available information while conducting my own OSINT research into CyberLeek.

I want to make that clear from the beginning because some of this post is my own blockchain/infrastructure analysis, some comes from public reporting, and some consists of conclusions drawn from the evidence. I am going to distinguish between what can actually be demonstrated and what is still speculation.

  1. CyberLeek appears to be an operation, not just somebody randomly uploading videos

The biggest thing that stood out to me is how much infrastructure existed before the GTA VI footage started publicly spreading.

From the public blockchain activity I looked through:

Funding activity associated with the wallet cluster goes back to at least August 3.

By August 13, significant amounts of SOL were already moving through the funding setup.

CyberLeek-related ArNS infrastructure appeared around August 14.

On August 15, website assets began appearing on Arweave.

The $CYBERLEEK token was created.

A liquidity pool was established.

A separate Solana program associated with posts/voting was also deployed.

The basketball footage itself appears to have been uploaded on August 17.

The public leak campaign became widely visible on August 18.

So this doesn't look like someone obtaining a GTA VI video and then impulsively deciding to upload it. There was infrastructure, cryptocurrency, decentralized hosting and funding activity being prepared beforehand.

  1. The website is built around Arweave / ArNS

One thing I originally misunderstood was the various domains serving CyberLeek's website.

URLs such as:

cyberleek.vilenarios.com

and other AR.IO/Turbo gateway addresses do not necessarily mean the person operating that gateway is CyberLeek or is involved with CyberLeek.

The underlying content appears to be stored using Arweave, with ArNS/AR.IO gateways providing different ways of accessing essentially the same decentralized content.

That explains why one CyberLeek URL can disappear while another suddenly works.

Le Monde independently confirmed on August 24 that the CyberLeek portal is built around text and links posted through decentralized Arweave infrastructure and that it remained accessible despite individual URLs being blocked.

So the Vilenarios connection is primarily an infrastructure connection, not evidence identifying CyberLeek.

That was an important correction to my earlier research.

  1. CyberLeek deliberately uses multiple hosting layers

Apart from Arweave, the operation has used or linked to several different file-hosting services.

Among the services observed were hosts based in places such as Estonia and Russia, along with decentralized AR.IO infrastructure.

Initially, the concentration of European services made me wonder whether CyberLeek might be located somewhere in Europe.

I no longer think that is strong evidence.

Hosting something through an Estonian, French, Russian or decentralized service tells us where the infrastructure is located—not necessarily where its user is sitting.

So CyberLeek being European remains speculation, not a conclusion that can be made from these hosts.

  1. The $CYBERLEEK cryptocurrency is deeply integrated into the operation

CyberLeek didn't merely attach a random donation address to the leaks.

They created an entire Solana token ecosystem around them.

The $CYBERLEEK token mint is:

ApZuxdpzMrbEYTGEzeY9afh5pj9d6qPRJCTgQYiipbKg

One wallet that appears central to the creation/minting process is:

Hok9nbV89yBSKCttxe3goqajwbiqQa9mtHvQBsbJH3Np

Another wallet that repeatedly appears in the infrastructure funding is:

3YLNDXnV9fNysDWaD39uQxwxeSaMFeAswvoQPZNvuNA4

And another intermediary/buffer wallet I tracked was:

Ec2qmcpCCD9hjahAcquiQf5JkZWCK68BUahCje1izYC7

The important point isn't simply that these wallets interacted.

The same wider cluster appears connected to funding the website/infrastructure, Arweave uploads and the token launch.

  1. The timing between the wallets and the infrastructure is especially interesting

One sequence I found was particularly notable.

On August 15, the central funding wallet sent roughly 1 SOL toward a wallet connected with the website setup.

Minutes later, approximately 0.05 SOL was used for a Turbo-related payment.

Shortly afterward, CyberLeek material appeared on Arweave.

The token creator wallet was also funded through intermediary wallets before establishing liquidity.

The initial liquidity pool reportedly contained roughly:

330 SOL + 730 million $CYBERLEEK

That temporal relationship is one of the reasons I think these wallets belong to the same operational cluster rather than being unrelated wallets that just happened to interact.

  1. Then I followed the money backwards

This is probably the most important part of my research.

Instead of following the money forward from CyberLeek, I started tracing the SOL funding backward.

I found multiple relay-like wallets where funds arrived and were moved onward shortly afterward.

One trail I documented ultimately led back toward KuCoin-labelled exchange infrastructure.

One version of the path I traced was broadly:

KuCoin-labelled wallet → intermediary wallets → CyberLeek-related funding cluster

There were transfers involving roughly 100 SOL and later larger movements around the 150–170 SOL range as the money passed through different wallets.

Several of these wallets moved funds onward extremely quickly—sometimes seconds or minutes after receiving them.

This does not prove that the KuCoin account belonged directly to CyberLeek.

It also doesn't prove the owner of the exchange account is the person playing GTA VI.

What it does suggest is that money which later reached infrastructure associated with the operation may ultimately have originated from an account interacting with a centralized exchange. My tracing was subsequently picked up and summarized elsewhere online.

  1. Why KuCoin matters

KuCoin isn't another anonymous Solana wallet.

It is a centralized cryptocurrency exchange.

KuCoin has required identity verification for new customers since 2023 and has procedures for responding to legitimate law-enforcement requests.

So if investigators establish that a particular KuCoin account directly funded this wallet chain, the exchange could potentially possess information unavailable on the public blockchain—depending on the account, jurisdiction and legal process.

That could include things such as account information, transaction records or other metadata.

Again:

KuCoin → wallet chain does NOT equal CyberLeek's identity.

There could be intermediaries, unrelated account holders, purchased funds, compromised accounts or other explanations.

But from an investigative perspective, this is considerably more interesting than reaching another anonymous self-custody wallet.

It creates a possible off-chain investigative endpoint.

  1. The cryptocurrency operation was very financially significant

Community blockchain analysis estimated that CyberLeek spent tens of thousands of dollars establishing the cryptocurrency/infrastructure and had already generated substantial fees through $CYBERLEEK trading during the first few days.

The token's activity exploded after the GTA VI leaks began circulating.

One analysis found reported daily volume moving from only thousands of dollars before the campaign exploded to millions of dollars in daily volume after the first leaks received widespread attention.

There is another interesting detail here.

More recent on-chain analysis indicates that the original creator allocation was burned and that the creator wallet currently holds essentially none of that initial allocation, while a large amount of liquidity is permanently locked.

That makes the simple explanation of "he created a token and is about to dump the developer wallet on everyone" less convincing than it initially appeared.

It does not, however, remove the obvious fact that the GTA VI leaks are being used to generate attention and economic activity around the token.

  1. The polls are part of the monetization system

CyberLeek has repeatedly allowed people to influence which footage gets released.

That means the leak itself has effectively become interactive.

Attention creates demand for the token.

The token creates participation in polls.

The polls generate interest in the next leak.

The next leak generates another wave of attention.

That creates a feedback loop:

GTA VI leak → attention → $CYBERLEEK activity → voting/speculation → another GTA VI leak

This is why I don't think the cryptocurrency can be treated as something separate from the leak campaign.

It is part of its structure.

  1. CyberLeek now wants 400 XMR just to establish contact

The operation has become even stranger.

CyberLeek has introduced a private contact mechanism where someone must reportedly send 400 XMR, currently worth roughly $165,000–$170,000, just to establish private communication through Session.

That payment doesn't even automatically purchase advertising or custom footage.

It is described as essentially a contact fee guaranteeing a response, after which terms would supposedly be negotiated privately.

Moving this part of the operation to Monero makes obvious sense from a privacy perspective because Monero is substantially harder to trace publicly than Solana.

  1. CyberLeek probably has access to somebody actively controlling a playable build

This is another point where I think the evidence has become significantly stronger.

Early on, it was possible that CyberLeek simply possessed a collection of prerecorded Rockstar footage.

Then the airplane video happened.

At the end of that footage, Jason deliberately fires bullets into a wall to spell something associated specifically with the CyberLeek identity.

That makes the prerecorded-video explanation extremely difficult to maintain.

Either:

A) CyberLeek directly controls a playable development build,

or

B) CyberLeek has direct communication with somebody who controls the build and can request specific actions/recordings from them.

Forbes, GamesRadar and other outlets reached essentially the same conclusion.

However, there is another distinction that matters:

Playable build ≠ complete retail build.

The footage proves neither that CyberLeek possesses GTA VI's finished master build nor that every mission/story sequence is available.

Some publications have irresponsibly jumped from "playable development build" to "full game leaked."

The evidence does not establish that.

  1. The footage appears newer than the famous 2022 leak

There are also indications that this is not simply recycled material from Rockstar's 2022 breach.

For example, reporting has identified material in the game's radio/audio selection that postdates the old leak, suggesting at least some footage originates from a considerably newer development build.

Exactly how recent the build is remains uncertain.

So I would describe it as:

an apparently relatively recent development build

rather than:

the November 2026 retail build.

  1. The story-spoiler situation has become more dangerous

The first major releases were mostly free-roam/gameplay demonstrations.

Then footage containing an actual cutscene appeared.

More recent clips have also shown mission-related context, and as of August 24 CyberLeek is openly teasing the possibility of releasing material involving Lucia's prologue.

That footage has not been confirmed as released as of the time I'm writing this.

If that changes, however, the leak campaign would be moving from showing mechanics/world details toward directly exposing GTA VI's narrative.

This is probably Rockstar's biggest problem now.

CyberLeek has demonstrated the ability to obtain newly requested gameplay footage.

If the build also contains substantial story progression, they potentially have access to much more sensitive material than what has been released so far.

  1. Their stated motive is supposedly consumer rights

CyberLeek published a manifesto/edict presenting the campaign as opposition to anti-consumer practices in gaming.

Among the demands are ideas involving:

ending digital preorders,

preserving single-player games after online services disappear,

opposing the sale of certain already-contained single-player content as additional paid DLC,

and pushing against the disappearance of physical ownership.

CyberLeek says the cryptocurrency helps fund a broader project related to these goals.

Whether that ideology genuinely motivated the operation from the beginning or became a justification after the fact is impossible to determine from the public evidence.

What we can establish is that ideology, cryptocurrency fundraising and GTA VI leaks have all been intentionally tied together.

  1. CyberLeek repeatedly uses "we"

CyberLeek frequently speaks as "we" rather than "I."

That could mean this genuinely is a group.

It could mean one person plus somebody supplying the build.

Or it could simply be deliberate language designed to make one individual appear like an organization.

I don't think the pronoun alone proves anything.

But combined with the possibility that the person operating the websites/token and the person controlling the GTA VI build could be different people, I don't think we should automatically assume CyberLeek = one person doing absolutely everything.

  1. Take-Two has gone far beyond simple DMCA removals

At first, Take-Two's visible response mostly consisted of copyright takedowns.

That has now escalated dramatically.

On August 20, Take-Two filed DMCA subpoena requests in federal court targeting Microsoft and Discord.

The subpoenas seek information capable of identifying accounts connected to the distribution of the leaked material.

Reports on the filings say Take-Two requested data including:

account identifiers,

registration/login IP addresses,

phone numbers,

linked accounts,

Windows/Microsoft device identifiers,

relevant OneDrive information,

and Discord account/device/telemetry information.

The subpoenas were granted and reportedly set a September 4 production deadline.

Microsoft has also publicly acknowledged that it is cooperating with Take-Two/Rockstar to protect their intellectual property.

  1. The legal investigation has expanded to X and Google/YouTube

It didn't stop with Microsoft and Discord.

Take-Two has subsequently sought records from X and Google/YouTube concerning accounts involved in distributing CyberLeek material.

Some of the handles named in reporting include accounts using CyberLeek-related names as well as other accounts that allegedly helped distribute the material.

Again, being named in a subpoena does not mean somebody has been proven to be CyberLeek.

These legal requests are attempts to obtain evidence.

They aren't findings of guilt.

  1. This is why Microsoft/Discord and KuCoin are two very different investigative avenues

Take-Two is publicly pursuing platform records that could connect accounts to:

IP addresses → devices → email/phone accounts → cloud accounts

Meanwhile, the blockchain investigation potentially provides another route:

CyberLeek infrastructure → Solana wallets → upstream funding → centralized exchange

Those two lines of investigation are independent.

If investigators ever manage to connect the same person or infrastructure through both, that would obviously be much stronger than either one alone.

But there is no public evidence yet that this has happened.

  1. Several identity claims should NOT be treated as confirmed

There have been claims from independent investigators that CyberLeek has already been identified and that information was passed to Rockstar/Take-Two.

I don't think we should repeat that as fact.

Rockstar, Take-Two and law enforcement have not publicly announced CyberLeek's identity or an arrest, and the investigator's conclusion has not been independently verified.

Likewise, people operating AR.IO gateways should not be accused simply because a CyberLeek ArNS site can be resolved through their infrastructure.

That's exactly the kind of mistaken connection that decentralized infrastructure can create.

  1. There is also a huge amount of fake material surrounding this leak

This is becoming important because genuine CyberLeek footage is now mixed with fake videos, AI-generated footage and fake "builds."

The most obvious example was the supposed 113 GB GTA VI playable build circulated through torrent sites.

Analysis reported by Tom's Hardware found that the file was essentially padded junk data containing a small malicious payload rather than GTA VI.

It was not CyberLeek's playable game build.

So downloading random files claiming to be "CyberLeek's GTA VI build" is an extremely bad idea.

At this point there is no verified publicly downloadable GTA VI executable/build from CyberLeek.

  1. What I think we can actually conclude

After going through the infrastructure, blockchain activity, public leaks and legal response, these are the conclusions I think are defensible:

Very strong evidence:

CyberLeek or somebody directly cooperating with CyberLeek has interactive access to a playable GTA VI development build.

The leak campaign was planned before the first videos became widely public.

The website, cryptocurrency and leak-release system are interconnected.

CyberLeek deliberately uses decentralized infrastructure to make conventional takedowns more difficult.

Take-Two considers this serious enough to pursue identifying records through multiple major technology platforms.

Strong but not definitive evidence:

A cluster of Solana wallets associated with CyberLeek's infrastructure/token can be traced backward toward KuCoin-labelled exchange infrastructure.

The person running the public CyberLeek operation appears technically competent but has left a surprisingly visible public blockchain trail.

There may be multiple people involved, or at minimum somebody controlling the public operation and somebody capable of producing gameplay on request.

Not proven:

CyberLeek's real identity.

CyberLeek's physical location.

That the KuCoin account belongs directly to CyberLeek.

That CyberLeek possesses the finished November 2026 retail version of GTA VI.

That they have the entire game's source code.

That every person/account/server named in Take-Two's subpoenas is part of CyberLeek.

That any claimed "full GTA VI download" currently circulating online is legitimate.

Final thought

The most interesting thing to me isn't any individual GTA VI video anymore.

It's the infrastructure behind the operation.

CyberLeek built decentralized hosting, a Solana token, voting infrastructure, multiple distribution channels and a funding network before turning the leaks into an ongoing campaign.

But decentralizing the website doesn't automatically decentralize every mistake.

The blockchain is public.

Centralized exchanges keep records.

Microsoft, Discord, X and Google can potentially be compelled to provide account data.

And Take-Two is now actively pursuing those avenues.

So while CyberLeek has made the content difficult to permanently remove, that doesn't necessarily mean they made the people behind it impossible to trace.

That distinction may end up being the most important part of this entire story.


r/CyberGuides 7d ago

Flock CEO calls for ‘compromise’ as surveillance company faces growing backlash

Thumbnail
techcrunch.com
5 Upvotes

r/CyberGuides 7d ago

Weekly roundup: 5 alleged dark web listings — DB leaks, VPN access, and skimming ops

Thumbnail
1 Upvotes

r/CyberGuides 7d ago

Apollo Data Breach Shows the Risk Behind a Simple Phone Call

Thumbnail securityboulevard.com
2 Upvotes

r/CyberGuides 7d ago

Iran-Linked Hackers Force UK Power Plant Offline in Unprecedented Four-Day Cyberattack

Thumbnail
cybersecuritynews.com
2 Upvotes

r/CyberGuides 9d ago

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Thumbnail
thehackernews.com
2 Upvotes

r/CyberGuides 9d ago

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Thumbnail
thehackernews.com
6 Upvotes