Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | August 2026: GTA VI Leak, Keyv & Carhartt Breaches
Sep 22, 2026
8 Mins Read
Moon
Summarize with:

August 2026: GTA VI Leak, Keyv & Carhartt Breaches

August 2026 brought a wide mix of cyber incidents, from large-scale data breaches affecting millions of people to software supply chain attacks targeting developers and enterprise environments.

Third-party exposure emerged as a recurring theme. A breach at logistics provider CEVA Logistics affected customers of multiple major brands, while compromised packages and extensions demonstrated how trusted development ecosystems can become attack vectors. Healthcare providers and technology companies also disclosed breaches involving millions of records.

Here are the major cyber attacks, breaches, and threat campaigns reported or significantly updated in August 2026.

CyberLeek Released Alleged GTA VI Material

Beginning August 18, an anonymous actor using the name CyberLeek began releasing unreleased Grand Theft Auto VI gameplay footage, screenshots, and alleged map material.

Instead of publishing the material in a single dump, CyberLeek released it incrementally while promoting a cryptocurrency token and a manifesto framed around consumer-rights demands. Rockstar and Take-Two pursued takedowns and other legal measures, while Rockstar publicly addressed the leaks on August 26.

CyberLeek website where the breach and crypto coin were promoted

CyberLeek website where the breach and crypto coin were promoted

The incident also created opportunities for secondary cybercrime. Fake GTA VI builds and websites appeared alongside the leaks, with some distributing malware or attempting to steal credentials.

Read SOCRadar’s analysis of the GTA VI CyberLeek incident.

CEVA Logistics Breach Exposed Steam and Pokémon Center Customer Data

A cyberattack against CEVA Logistics affected customer data belonging to multiple companies that rely on the logistics provider for European order fulfillment.

Valve said CEVA was compromised between July 29 and August 1. The incident exposed delivery-related information belonging to some European customers who purchased Steam hardware, including names, addresses, phone numbers, email addresses, and order information. Valve’s own systems were not breached, and CEVA did not hold Steam passwords, Steam Guard codes, or payment information for the affected orders.

The scope widened later in August when Pokémon Center notified customers in the United Kingdom and Germany that the same CEVA incident had exposed personal and order information. The potentially compromised data included names, mailing addresses, phone numbers, email addresses, and details about ordered products. Pokémon Center said payment card information was not affected.

The incident showed how a single third-party compromise can expose customer information belonging to several otherwise unrelated brands.

DOUBLECUP ClickFix Campaigns Delivered New RATs

SOCRadar’s Threat Research Unit analyzed DOUBLECUP, a Russian Loader-as-a-Service operation designed for ClickFix campaigns and active since early June 2026.

DOUBLECUP license portal login

DOUBLECUP license portal login

DOUBLECUP provided operators with infrastructure and tooling for campaigns that used social engineering to persuade victims to execute commands. SOCRadar observed campaigns impersonating CRM platforms including NetSuite, Odoo, HubSpot, and Salesforce.

The operation delivered an updated CountLoader alongside DeviceManager, a previously undocumented Python-based remote access trojan. DeviceManager established persistence and used blockchain-based EtherHiding techniques to resolve command-and-control infrastructure, with HTTP and DNS tunneling available for communications.

Read SOCRadar’s DOUBLECUP technical analysis.

LiteLLM Supply Chain Attack Exposed 2,500+ Organizations

New analysis published in August expanded the known scope of the LiteLLM supply chain attack, which originally involved malicious LiteLLM releases published to PyPI in March.

The compromised versions, 1.82.7 and 1.82.8, contained credential-stealing functionality. Later analysis showed that the broader collection activity extended beyond the roughly 40-minute malicious PyPI window.

SOCRadar’s analysis of exposure data identified more than 2,500 organizations and roughly 434,000 captured CI/CD files, with 95% of affected organizations appearing in the dataset before the malicious LiteLLM packages were published.

The incident also demonstrated the risk of transitive dependencies: organizations did not necessarily need to install LiteLLM directly to become exposed.

Read SOCRadar’s analysis of the LiteLLM supply chain attack.

RingCentral Breach Exposed 1.6 Million Email Addresses

The scale of a July breach at RingCentral became clearer in August when Have I Been Pwned added data from the incident to its breach database.

The dataset contained approximately 1.6 million unique email addresses, along with names, phone numbers, and physical addresses. RingCentral previously described the incident as a sophisticated social engineering attack affecting a limited portion of its customers.

The exposed corporate contact information could provide useful material for targeted phishing and voice-phishing attempts.

Overview of the RingCentral data breach (HIBP)

Overview of the RingCentral data breach (HIBP)

Unlimited Technology Systems Breach Affected 3.8 Million People

Healthcare software and revenue-cycle management provider Unlimited Technology Systems disclosed a breach affecting approximately 3.8 million people.

The intrusion occurred in October 2025, but its scale became clearer in August after the U.S. Department of Health and Human Services listed 3,803,750 affected individuals. Potentially exposed information included Social Security numbers (SSNs), identity documents, contact information, medical record numbers, insurance information, and diagnosis data.

No ransomware or data-extortion group had publicly claimed responsibility at the time of reporting.

CareCloud Breach Affected 3.7 Million Patients

Healthcare technology provider CareCloud confirmed that a March cyberattack affected 3,756,469 people.

Attackers accessed one of the company’s AWS environments during an incident that disrupted part of its Health division for approximately eight hours. CareCloud later confirmed that personal records were accessed, although it did not publicly detail the full range of compromised data beyond names.

The disclosure added another large healthcare technology incident to 2026’s breach totals.

Aesto Health Breach Affected 9.5 Million Patients

The scale of the Aesto Health breach became clearer around the end of August, with 9,540,683 individuals ultimately reported as affected.

The intrusion occurred between December 2 and December 18, 2025, when an unauthorized actor accessed data within Aesto’s AWS infrastructure. Exposed information varied by individual but could include names, dates of birth, medical information, Social Security numbers (SSNs), driver’s license information, financial account numbers, and health insurance information.

Aesto began sending notifications to affected individuals on August 21. The 9.54 million figure was reflected in disclosures filed around the end of August.

Carhartt Data Breach Exposed 12.9 Million Accounts

Clothing manufacturer Carhartt became another major breach victim after ShinyHunters published data allegedly stolen from the company.

Analysis of the leaked material identified information associated with approximately 12.9 million real user accounts, including names, email addresses, phone numbers, and physical addresses. Millions of synthetic records were also present but were excluded from the breach count.

Carhartt leak listing by ShinyHunters

Carhartt leak listing by ShinyHunters

ShinyHunters claimed negotiations had failed before it released the data and said it had demanded $3.3 million. It is indicated that the stolen information likely originated from Carhartt’s Databricks analytics environment.

Sakura Internet Investigated Exposure of 1.36 Million Accounts

Japanese cloud and hosting provider Sakura Internet disclosed unauthorized access affecting its infrastructure in August.

The investigation initially identified unauthorized access to 583 rental-server accounts, including malware installation on some systems. A subsequent investigation found possible unauthorized access to a separate sales-management system containing information associated with as many as 1,360,563 customer accounts.

Sakura stressed that large-scale data exfiltration from the sales system had not been confirmed. Potentially exposed information included customer contact, profile, contract, and billing details.

Keyv Compromise Spread Across the npm Ecosystem

On August 4, attackers compromised the GitHub account of a maintainer behind Keyv and used that access to inject credential-stealing malware into widely used npm packages.

The compromise spread beyond Keyv into packages including flat-cache, file-entry-cache, cacheable, and cache-manager. By August 5, researchers at Aikido reported that at least 444 packages across 1,381 versions had been compromised, collectively accounting for more than 2 billion monthly installs.

The malicious releases were particularly concerning because attackers pushed code directly to legitimate GitHub repositories before publishing new npm releases, allowing the poisoned packages to carry valid provenance from GitHub Actions.

Open VSX Removed 77 Malicious Extensions

The Open VSX extension marketplace removed 77 malicious “evil twin” extensions that impersonated legitimate developer tools.

Researchers found that the extensions had been uploaded between July 26 and August 1. Most collected basic host information, while 19 gathered more detailed information about development environments, repositories, installed extensions, CI platforms, and related metadata. All 77 transmitted data to the same attacker-controlled domain.

The campaign highlighted the value of developer environments as an attack surface, particularly when malicious packages exploit trust in familiar extension names.

How Can SOCRadar Help?

August’s incidents showed how cyber risk can emerge beyond an organization’s own network, from compromised suppliers and software dependencies to leaked data and impersonation campaigns. SOCRadar provides several modules for monitoring these external risks:

  • Dark Web Monitoring: Detects exposed data, compromised credentials, threat actor activity, and mentions across underground sources.

SOCRadar’s Dark Web Monitoring

SOCRadar’s Dark Web Monitoring

  • Supply Chain Intelligence: Monitors third-party organizations and suppliers for potential cyber risks and exposure.
  • Brand Protection: Identifies phishing, impersonation, fraudulent domains, and other threats targeting brands and digital assets.
  • Attack Surface Management: Helps discover and monitor internet-facing assets and exposures that could provide attackers with an entry point.

Together, these modules help security teams identify external exposure earlier and investigate risks affecting their organization, suppliers, and digital assets.