To find whoever is leaking GTA 6 material, Take-Two has not asked for a confession or an address: it has asked for a MachineGuid. An identifier almost nobody outside an IT department knows exists, that their computer has been carrying since the day Windows was installed, and that they have never seen.
Since mid-August 2026, someone signing as "CyberLeek" has been posting leaked material from the game. On 20 August, according to the court paperwork reported by the press, Take-Two filed two DMCA subpoenas in the Southern District of New York demanding that Microsoft and Discord identify whoever is behind that alias. The deadline they set was 4 September: today.
This post is not about the game. It is about the shopping list: what those subpoenas ask for is, item by item, the same trail any employee of any company leaves on any working day.
What those subpoenas ask for
According to the paperwork reported by the press, the request is not limited to one suspicious account. It reaches every account that took part in three specific Discord servers since 1 June, and for each one it demands:
- ›The MachineGuid and the MSA device identifiers (Microsoft account).
- ›The IP addresses of registration and last sign-in.
- ›The associated phone numbers.
- ›The linked connections to Google and Xbox.
- ›The contents of OneDrive.
Read it again without thinking about video games. Identity, device, network, linked accounts and files. That is a complete forensic inventory of a person, and no hack is needed to build it: these are the ordinary records a provider keeps because its service would not work without them.
What is MachineGuid?
The MachineGuid is a unique value that Windows generates when the system is installed and that persists throughout the life of that installation: it survives password changes, signing out, switching accounts, wiping the user profile. Short of a clean reinstall of the system, it is still there.
The distinction that explains everything: MachineGuid does not identify the account, it identifies the device. An account gets abandoned, the email gets changed, a fresh one gets created. The machine all of that was done from is still the same one, and it is what ties together several identities that looked entirely unrelated.
Which is why a request like this is not after a confession: it is after a correlation. If the same device identifier shows up behind the anonymous account doing the posting and behind the everyday personal account —the one with the real name and the verified phone number— the investigation no longer needs anyone to give themselves away.
And it is worth stating what we do not know: it has not been confirmed how the leaked material was obtained, nor whether those subpoenas produced anything. "CyberLeek" is a self-assigned public alias, not an identified person. What is interesting here is not how the case ends; it is the mechanism.
Now swap "GTA 6 leaker" for "your company"
The salesperson who leaves for a rival and, the week before, syncs the customer folder. The back-office account that starts sending odd emails at three in the morning on a Tuesday. The laptop connecting from a country where you have nobody. None of those makes the news, but all three are exactly the same technical problem as Take-Two's: someone did something from some device, and it has to be reconstructed afterwards.
If you had an incident tomorrow, could you reconstruct who did what, from which device, and with which data?
And here is the asymmetry we find to be the most useful part of the whole story. In Take-Two's case, that trail belongs to Microsoft, and getting at it takes lawyers, a court and a deadline. In your company, the equivalent trail is yours: your users' sign-ins, your laptops' telemetry, who opened which document in your SharePoint. You need no court order to read it.
With one condition, and it is the one that gets broken almost every time: you only have it if you collect it and keep it. A log nobody switched on does not exist. One that expired thirty days ago does not either, and data-leak incidents are rarely discovered in the same week they happen. By the time you need to look, it is too late to decide what you were keeping.
What this means for your company, specifically
Here is Take-Two's list translated into the five pieces we put in place when someone asks us for exactly this: being able to answer the question in the box above.
- 1Identity. The equivalent of the subpoena's IPs and phone numbers. With Entra ID and Microsoft 365 you get every user's sign-in log, MFA so that the sign-in means something, and conditional access so that not just any location or any machine will do. Without it, "Marta's account" is a claim, not a fact.
- 2Devices. The equivalent of MachineGuid. Intune gives you the inventory —which machines exist, whose they are, what state they are in— and EDR/XDR gives you the telemetry of what happens inside them. A device that is not in the inventory shows up in no investigation, simply because nobody knew it existed.
- 3Data. The equivalent of the OneDrive contents. Knowing what is in OneDrive and SharePoint, who accesses it, what gets shared outside; and having a Microsoft 365 backup with a retention period you decided, not the one that shipped as the default.
- 4Logs. The boring piece, and the one that decides whether the other four are worth anything. Centralise your logs and retain them before the incident, because afterwards you cannot: nobody has ever recovered a log that was never stored. The question we ask a client here is not "do you have logs?", it is "going back how many months?".
- 5Zero Trust. The principle that binds the other four: every access is verified by identity and by device, and only what is needed is granted. Zero Trust is not about distrusting people; it is about the system not having to take your word for who came in.
None of the five is exotic. They all fail the same way: they are taken for granted. We have already written about what a modern sign-in method leaves out and about what a Microsoft 365 feature can delete over the top of your retention policy; in both cases the problem was not the tool, it was that nobody had read the small print.
In cybersecurity we all leave a trail
The question is whether your company can see it. And seeing it is not the same as having it: most of the organisations we talk to generate that trail —they have generated it since day one, without doing anything— but they do not collect it, do not keep it long enough, and nobody looks at it until there is a problem. At that point the investigation starts by reconstructing what is no longer there.
The difference between reacting and getting ahead is not having more tools. It is having decided, calmly and before anything happens, what gets logged, how long it is kept and who looks at it. Take-Two needed a court and a fortnight to ask for its trail. You have yours at home. It would be a shame to find out it was switched off.
Sources: coverage of the two DMCA subpoenas filed by Take-Two on 20 August 2026 in the Southern District of New York and of the data demanded from Microsoft and Discord — Tom's Hardware, Malwarebytes, Variety, Kotaku, Game Developer, MuyComputer and VidaExtra. The details of the subpoenas are reported here as that press has published them; we have not had access to the original documents. The technical origin of the leak has not been confirmed, and "CyberLeek" is a self-assigned public alias, not an identified person.
Could you reconstruct the trail of an incident in your company?
At everyWAN we set up identity, devices, data and logging so the answer does not come down to luck. We review what you already have in place and tell you what is missing before you need it.