← Back to stories

bunpav ·

Is There a Second GTA 6 Leaker? What We Know About the Separate Internal-Files Claim

A separate group claims access to GTA 6 shader data, lighting caches, and internal build files — distinct from CyberLeek. What's been shared, and how.

8 min readbunpav crewIndustry shiftsPC gaming

Most of the headlines about the GTA VI leaks belong to CyberLeek — the leaker behind the gameplay videos, the map, and the manifesto that's dominated coverage since August 18, 2026. But buried in the same news cycle is a second, apparently unrelated claim: a different group says it has its own separate cache of internal GTA VI development files, and if true, Rockstar would be dealing with two independent security failures at the same time.

TL;DR — what's being claimed

QuestionDirect answer
Who is this second leaker?Unidentified; reporting treats them as a distinct group from CyberLeek.
What have they shared?Shader structures, lighting caches, water-rendering data, and a screenshot reportedly from an April 2026 build.
How much data?Reportedly over 6.2 billion bytes (roughly 6.2 GB) of uncompressed material.
How did they get it?Unverified claim of phishing a Rockstar India employee.
Is it confirmed real?Not conclusively — some details, like whether it's from Xbox dev hardware or a PC, are disputed.
Does this connect to CyberLeek?No confirmed link between the two leak sources as of this writing.

What exactly is different about this leak?

CyberLeek's material is made for an audience: gameplay clips of Jason driving and playing basketball, a readable map, a manifesto written to generate public sympathy and press coverage. The second leak reads more like raw studio output — the kind of files an engine programmer or technical artist would actually work with day to day, not content designed to go viral.

Reported contents include shader structures, lighting-cache data, and water-rendering material — the technical building blocks behind how Leonida's environments actually render, not footage of anyone playing the game. Also circulating is what's described as an unpublished screenshot from an April 2026 build, which — if accurate — would represent one of the most recent snapshots of GTA VI's visual state to leak publicly. Digital Trends' reporting puts the total volume of shared material at more than 6.2 billion bytes uncompressed.

How did this leaker reportedly get access?

The access story here is murkier than CyberLeek's. A Reddit post discussing the second group claims the material came from phishing a Rockstar India employee — tricking someone with legitimate internal access into handing over credentials or files, rather than a direct network intrusion. Neither Rockstar nor Take-Two has confirmed this account publicly, and it should be treated as an unverified claim rather than established fact.

There's also a live dispute over the hardware behind the leaked material: some claims tie it to Xbox Series X development hardware, while conflicting reports suggest at least part of the material may actually have been captured running on a PC. That inconsistency is one reason this leak has received more cautious coverage than CyberLeek's, which was quickly corroborated by Take-Two's own DMCA activity.

Why two leakers is worse than one for Rockstar

A single leak, however damaging, is a single incident to investigate and contain. Two apparently independent sources — one publishing viral gameplay clips, one circulating raw engine assets — means Rockstar potentially has two separate points of failure to identify and close at once, right in the run-up to its own official reveal.

Notebookcheck's coverage frames it plainly: the "leak mess" for Rockstar deepened specifically because a second, unrelated group surfaced with its own claim to an internal build, layering additional uncertainty on top of the already-chaotic CyberLeek situation. For context on how that first leak has unfolded day by day, see our full CyberLeek timeline.

Should you trust files claiming to be this leak?

Be skeptical by default. Legitimate leaked material in cases like this circulates as viewable images and video — things you can look at without running anything on your machine. Anything packaged as a downloadable file, installer, or "full build" claiming to be this leak should be treated the same way as fake CyberLeek downloads: likely malware dressed up as a leak, designed to exploit exactly this kind of news cycle.

How does a phishing-based leak differ from CyberLeek's?

If the Rockstar India phishing claim holds up, it represents a fundamentally different threat model than what CyberLeek appears to have pulled off. CyberLeek's access looks more consistent with a direct network intrusion or a compromised credential set tied to a build server — the kind of breach that gives someone hands-on, ongoing access to a running game build, which is exactly what the playable-build evidence suggests. Phishing an individual employee, by contrast, typically yields whatever that specific person had access to on their machine or in their inbox at the time — which lines up with this leak's contents skewing toward technical assets like shader files and lighting caches rather than an interactive build.

That distinction matters for how Rockstar investigates and responds. A network intrusion points toward infrastructure and access-control failures — questions about who could reach a build server and how. A phishing-based breach points toward employee security training and email/credential hygiene — a completely different remediation path, often involving a much larger set of potentially affected employees rather than a single compromised system.

Why is the hardware question still unresolved?

The dispute over whether this material originated from Xbox Series X development hardware or a PC isn't a minor technical footnote — it changes what kind of access the leaker actually had. Development kits for consoles are typically restricted, inventoried hardware distributed to a relatively small set of registered studio accounts and hardware partners; material genuinely sourced from one would suggest a breach reaching further into Rockstar's or Microsoft's controlled hardware ecosystem than a leak sourced from an ordinary studio PC.

Conflicting claims about the material's origin are common in the early days of any leak story, before independent technical analysts have had time to examine file metadata, compression artifacts, and platform-specific markers in detail. Until that analysis firms up — and until Rockstar or Take-Two comments, which they have not — treat the console-hardware claim specifically as the least-verified piece of an already unverified story.

What would confirmation actually look like?

For a claim like this to move from "unverified Reddit post" to "credible leak," you'd typically expect one or more of: a named security researcher or outlet independently verifying file authenticity against known GTA VI production markers, Take-Two issuing DMCA takedowns against this specific material (as it did rapidly for CyberLeek's footage), or Rockstar acknowledging a second, distinct security incident in a public or regulatory filing given its parent company's status as a publicly traded firm. None of those have happened yet as of this writing, which is the core reason this story remains in "claim" territory rather than confirmed fact, unlike the CyberLeek leaks covered in our main timeline.

Why does this claim matter even while unverified?

Even setting aside whether this specific claim ever gets confirmed, its emergence says something real about the environment Rockstar is operating in right now. Once a high-profile leak story is dominating headlines, it creates an incentive structure that pulls in adjacent claims — some genuine, some opportunistic, some simply mistaken — all competing for attention within the same news cycle. That's part of why treating every GTA VI leak claim with the same level of scrutiny, rather than assuming a second sensational headline must be as solid as the first, matters for anyone trying to actually track what's happening rather than just what's being said.

Watching how Rockstar's public messaging evolves is itself a useful signal — a company staying silent on a specific claim isn't confirmation it's false, but a sudden shift in tone or additional DMCA activity targeting this exact material would be a strong indicator it's real.

What should you do with this information?

  1. Don't conflate the two leak stories. CyberLeek and the second internal-files claim are, as far as current reporting shows, unrelated — don't assume one confirms the other.
  2. Treat the "Rockstar India phishing" claim as unverified until Rockstar or a named security researcher confirms it.
  3. Never download files claiming to be this leak's raw data. Shader and lighting-cache files aren't something a casual fan needs or can safely open anyway.
  4. Watch for Rockstar's security response, not just its PR response — a second breach, if real, is the kind of story that eventually surfaces in official statements or SEC filings given Take-Two's public-company status.
  5. Keep an eye on the main timeline for updates on whether this second claim gets corroborated the way CyberLeek's leaks were. Full timeline here.

Details on the second leaker are based on reporting and unverified claims available as of August 21, 2026. We'll update this post if Rockstar, Take-Two, or a named security researcher confirms or disputes the account.

Player questions

Is the second GTA 6 leaker the same as CyberLeek?

No, current reporting treats them as separate and apparently unconnected. CyberLeek has posted gameplay videos and map images; the second group is circulating technical development files instead.

What has the second leaker shared?

Development-focused material including shader structures, lighting caches, water-rendering data, and an unpublished screenshot reportedly from an April 2026 build — over 6.2 billion bytes of uncompressed data in total, according to reports.

How did the second leaker reportedly get access?

A Reddit post discussing the group claims access came through phishing a Rockstar India employee, though this has not been officially confirmed by Rockstar or Take-Two.

Is this leak confirmed as genuine?

Not conclusively. Some reports note conflicting claims about whether the material comes from Xbox development hardware or a PC, and Rockstar has not verified the files publicly.

Does having two leak sources make this worse for Rockstar?

Yes, structurally. Two independent, unrelated breaches happening around the same time is harder to contain than a single incident — Rockstar would need to investigate and respond to two separate security failures at once.

Should I trust files claiming to be this second leak?

Treat any file download claiming to be leaked GTA 6 development data with extreme caution. Legitimate leaked material circulates as images and video, not as executables or installers you're asked to run.

More to read