To Identify a Leaker, Take-Two Asked for Data on Every Member of Three Communities
Three subpoenas filed in New York rely on a DMCA provision that requires no lawsuit and no judge. What they ask for goes well beyond the persona that signed the GTA VI leak.

▸In this article
Between August 20 and 21, 2026, Take-Two Interactive filed at least three subpoena requests in the U.S. District Court for the Southern District of New York seeking to identify whoever is behind the leak of Grand Theft Auto VI material. The targets are Microsoft, Discord, and Google.
All three invoke the same provision: § 512(h) of the DMCA. It allows a rights holder to obtain the identity of an alleged infringer without suing anyone first — and the request goes to the clerk of the court, not to a judge. Three formal requirements suffice: a prior takedown notice, a proposed subpoena, and a sworn declaration that the purpose is to identify the infringer.
Not one of those steps involves anyone weighing whether what is being demanded is proportionate to what is being sought. That absence is what makes the case interesting well beyond the video game.
What each subpoena reaches
Discord (case 1:26-mc-422). It seeks identification of three accounts named by numeric ID — CYBERLEEK, CINEMATICROCKSTAR, and Surfer24k, the last with the alternate handles cyberleek_west and surwest. So far, nothing unexpected.
Then the exhibit keeps going. It also demands, verbatim, "all identifying information associated with all user accounts that are or were members of the servers and channels listed below, for the period from June 1, 2026 to the present." For each account returned: server metadata and telemetry, original message records, access logs with IP addresses, emails, phone numbers, connected accounts, registration date, Google and Xbox links, and device identifiers.
Three servers are listed. One is described by the petitioner itself as a cheats community and the "operator's home." Another is a public brand profile. The third is the video editors' server run by Australian creator Matthew Judge, DarkViperAU — who has publicly stated he had no knowledge of the leak, and against whom the filing makes no allegation whatsoever. That server's identifier appears in the exhibit as pending, to be resolved later.
Microsoft (case 1:26-mc-421). It comes in through a door that went almost unreported: not Windows, not Xbox, but GitHub, pointing to a specific repository that hosted the material. Beyond Microsoft's own internal investigation records on the persona, the exhibit repeats the sweep of server members and adds one item: content related to GTA, Rockstar, or Cyberleek stored in the OneDrive of those accounts.
Google (case 1:26-mc-425). The most restrained of the three. It is limited to a single YouTube video and three named personas, with no community-wide sweep.
All three subpoenas set compliance for September 4, 2026, at the office of the firm representing Take-Two.
The distance between there and here
In Brazil, obtaining connection logs or application access logs requires a court order, and the Marco Civil da Internet conditions the request on three things that must all be present at once: indications of the unlawful act, a reasoned justification of how the requested logs serve the investigation, and a defined time period.
A request drafted like the Discord one satisfies the third requirement — there is a start date. It fails the second: the request must justify what the logs are for, and the email address, phone number and device identifier of every member of three communities serve no investigative purpose at all. And it fails the first with respect to the overwhelming majority of the people swept in, against whom there is no indication of any unlawful act — strictly speaking, there is not even an allegation.
What in the United States is obtained through a clerical act here requires a reasoned decision by a judge. That is not a procedural detail: it is the difference between a filter that exists and one that does not.
What is still unknown
There is no confirmed public information on how the material got out — whether through credential compromise, social engineering, or some other route. Speculation about the vector has circulated, and none of it has come from a verifiable source.
Nor has anyone been identified. CYBERLEEK is a pseudonym, and the subpoenas exist precisely because Take-Two does not know who is behind it. A persona is not a person, and nothing in the filings supports attributing the leak to any particular individual.
What is known is that the persona tied the leak to a cryptocurrency token of the same name, which placed a financial motive alongside the manifesto it published. That is a pattern that merits its own analysis, and we will return to it.
Why this matters outside gaming
A leak of game material is an entertainment industry matter. The instrument used to respond to it is not. Section 512(h) is applied every day against platform users, and its design — no lawsuit, no judge, no proportionality test — works exactly the same for any copyright holder who wants the name behind an account.
Anyone who runs an online community has a practical lesson here: a server's exposure does not depend on what its members did. It depends on the server showing up on a list.
Sources
- In re DMCA Subpoena to Microsoft Corporation, case 1:26-mc-00421 — U.S. District Court for the Southern District of New York, filed 08/20/2026.
- In re DMCA Subpoena to Discord, Inc., case 1:26-mc-00422 — same court, filed 08/20/2026.
- In re DMCA Subpoena to Google LLC, case 1:26-mc-00425 — same court, filed 08/21/2026.
- 17 U.S.C. § 512(h).
- Law No. 12.965/2014 (Marco Civil da Internet), art. 10, § 1, and arts. 22 and 23.
Correction — 08/26/2026. The original version of this article described the second requirement of art. 22 of the Marco Civil as "specificity as to what is being sought". The sole paragraph of art. 22 in fact requires a reasoned justification of the usefulness of the requested logs for purposes of investigation or evidentiary instruction. The passage has been corrected; the conclusion about the request is unchanged.
Update, September 10, 2026. The court records show a fourth application, against X Corp (case 1:26-mc-426), granted on August 24; the Google application (case 1:26-mc-425) was withdrawn by Take-Two on August 28 after the judge asked for an explanation, and the case was closed on August 31; and Discord received a second application, with the list of targets under seal, granted on August 31. The full account, from the filings, is in Four cases, one question.
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/news/to-identify-a-leaker-take-two-asked-for-data-on-every-member-of-three-communities
Retrieved on