Security1 distinct publisher3 min readPublished
The publisher wants MachineGuid values, device IDs and OneDrive contents for members of three servers going back to June 1. Microsoft and Discord have until September 4 to answer.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
MachineGuid is the item on that list that does the work. It is the value identifying a single Windows installation, and a Microsoft account device ID identifies the devices that access Microsoft services [3]. Alone, neither names anybody. Joined against phone numbers, IP addresses, linked Google and Xbox accounts and the contents of a OneDrive [2], they turn a Discord handle into a particular machine, and that machine into the other accounts that have touched it.
The window deserves as much attention as the field list. Records are sought from June 1 [1], and the first CyberLeek footage appeared on August 17 [7]. That is 77 days of history before anything was published, and roughly 80 days by the date of the subpoena [13][12]. An August leak is being investigated through logs that predate it by about two and a half months, which is a plain statement of what a retention setting is: whatever a platform still holds is the scope of somebody else's demand.
Take-Two has been on the wrong end of the same arithmetic. In April, the ShinyHunters crew took 78.6 million Rockstar records without compromising Rockstar's own systems, by going after Anodot, a cloud analytics vendor holding persistent authentication tokens for its customers' Snowflake environments [9]. The lesson of that incident was that the aggregate held by a third party is the thing worth stealing. This subpoena asks two third parties to build a fresh aggregate of other people's identifiers and hand it to a private litigant.
Microsoft and Discord have fifteen days from the subpoena to the deadline [14], which is not much room to argue about scope, and the Malwarebytes report records no response from either company and no statement that either will contest it [15]. Meanwhile the motive question stays open: commentators read the $CYBERLEEK token on Solana as a pump, and although the holding was burned on Sunday, trading fees reportedly reached $60,000 last week [8]. None of that narrows the request by a single account.
For anyone operating a community platform, the useful read is not the celebrity of the game. It is that a device fingerprint retained for abuse prevention doubles as an identity resolver the moment a subpoena arrives, and that server membership is being used as the selector, which is why the estimate of who gets caught runs to hundreds or thousands [5]. Matthew Judge, the Australian streamer whose server is named, says he had nothing to do with it and knew nothing about it [6], and his position is the position of most people in scope: identified to a corporate investigation because of where they hung out in June. The same footage is also being used as bait, with Malwarebytes finding fake "Extended Look" and demo sites that deliver password-stealing malware [11]. One leak, two separate ways for uninvolved members to lose control of their identifiers.
Ranked by verification strength, evidence, and original report placement.
CyberLeek launched a $CYBERLEEK token on Solana promoted as a way to vote on the next footage to be leaked; commentators accused it of pumping the token, and while the large holding was burned on Sunday, trading fees can still be collected and reportedly reached up to $60,000 last week.
Take-Two Interactive served a subpoena on Microsoft and Discord on August 20, seeking a range of data about members of three Discord servers going back to June 1 of this year.
The subpoena demands IP addresses, phone numbers, linked Google and Xbox accounts, and OneDrive contents of certain server members.
The subpoena also seeks MachineGuid values and Microsoft account device IDs, which identify individual Windows installations and devices that access Microsoft services respectively.
Microsoft and Discord have until September 4 to hand over the data.
The subpoena covers servers including one belonging to Australian GTA 5 streamer Matthew Judge, known as DarkViperAU, who posted on X that he had nothing to do with the event and did not know anything about it.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific but single-sourced, with no primary document
The dates, identifier classes and deadline are stated with unusual specificity, and one item (the fake GTA 6 malware sites) is first-party vendor research. But the entire cluster rests on one publisher, no subpoena or docket document is cited, no platform confirmation exists, and the key exposure magnitude is unquantified.
Real events underway, outcome not yet realized
Observable events have occurred - footage was published August 17, the subpoena was served August 20, and malware-serving lookalike sites were found August 24 - but the consequence that defines the story, actual production of device-level records to Take-Two, has not been shown to have happened.
Framing runs ahead of the unresolved compliance question
The identifier list and deadline are accurately reported, but the headline framing treats platform logs as already converted into a device-level ID list while compliance is undecided and the 'hundreds or thousands' affected figure has no membership data behind it. Modest overstatement rather than invention.
Security vendor publishing on its own product's problem space
The publisher is an anti-malware vendor; the piece cites its own researchers, gives consumer scam-avoidance advice, and closes with a direct call to install its Browser Guard extension. That is a visible commercial interest in emphasizing privacy and scam exposure, though the subpoena facts themselves are not product-dependent.
Moderate-low: one interested source, key outcome pending
Detail level and internal consistency are good, and the derived date arithmetic checks out, but with a single vendor source, no primary filing, no platform comment, and a hedged financial figure, confidence in the story as reported stays below the halfway mark.
build
A DMCA notice over one GitHub repo now asks Microsoft for MachineGuids from three Discord servers1 distinct publisher
security
A trailer date is a campaign schedule: fake GTA 6 sites are selling stolen session cookies1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
product
GTA VI's $79.99, disc-free preorder sets the ceiling everyone else prices against1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026