The Microsoft GTA 6 Subpoena Asks for OneDrive Contents

by 6Charts Team Category: news 9 min read

We downloaded the exhibit ourselves at HTTP 200, 835,534 bytes, five pages, and quote both demands verbatim. The word "artifact" appears exactly once in the whole document, in the conditioning phrase, and no list follows it. Take-Two also asks Microsoft to resolve identifiers it did not hold, and labels its own targets as taken from the leaked video. We redact every server name, guild ID and account ID and explain why. The Google and X versions of the same demand are limited to three named personas each, with no cloud storage clause.

The DMCA subpoena provision exists for one narrow job. It lets a copyright owner ask a court clerk to compel a service provider to hand over information sufficient to identify an alleged infringer. The Microsoft subpoena in the GTA 6 leak case asks for a good deal more than that, and it conditions part of the demand on a list of technical indicators that does not appear anywhere in the document. We downloaded and read the attachment ourselves. What follows quotes it exactly, redacts every identifier in it, and separates what the document says from what anybody could argue about it. What does the Microsoft subpoena actually ask for? CONFIRMED, editor re-verified at the primary source on 25 August 2026. We pulled the exhibit at HTTP 200, 835,534 bytes, MD5 86ab8832492ea84d55ade4e691a1f91b, five pages, with 12,251 characters of extractable text. The ECF stamp across the top reads "Case 1:26-mc-00421 Document 1-1 Filed 08/20/26". Attachment A is headed "DOCUMENTS TO BE PRODUCED UNDER SUBPOENA" and has two demands. The first, verbatim: "All internal Microsoft business records and investigative records associated with Microsoft's internal investigation of the "cyberleek" persona sufficient to identify the user(s), person(s) and/or entity/ies associated with that persona." The second, verbatim and in full: "All identifying information associated with all user accounts that are/were members communicating with the Discord server(s) listed below during the time period from June 1, 2026 to present; and for those accounts, provide any associated device/telemetry records where one or more of the tool/file artifacts below were present on the system. For each returned account, provide: the account ID, registration email, registration and last-login IP addresses, phone number, linked connections (Google/Xbox/etc.), any associated device identifiers (MachineGuid/MSA), and content related to Grand Theft Auto ("GTA"), Rockstar or Cyberleek from their OneDrive account." Read the last clause again. The demand ends by asking Microsoft to produce the contents of people's OneDrive accounts, filtered by subject matter. That is stored personal files, not account registration details. Where is the list the demand depends on? This is the finding we did not expect. CONFIRMED, editor re-verified. The word "artifact" appears exactly once in the entire five-page document, inside the phrase "the tool/file artifacts below". No list of artifacts follows it. The document runs to a final page marked "Page 5 of 5" and ends with a table of Discord accounts. The thing the demand points at does not exist inside the filing. That matters because the artifact list is the limiting condition. The telemetry demand only reaches accounts where one or more of those tools or files were present on the system. Without the list, the sentence has no boundary a reader can see. We flag the innocent explanation and we cannot rule it out. The list may exist and may have been provided to Microsoft separately, outside the court filing, by counsel or by a forensic partner. We have no way to check that from the docket. What we can say is that it is not in the document the court received. Take-Two is asking Microsoft to fill in identifiers Take-Two does not have CONFIRMED, editor re-verified. The attachment lists one Discord server whose guild ID field reads "(invite; guild ID TBD by partner)", and one account whose identifier field reads "(resolve via guild [ID])". So part of the target list is incomplete on its face, with the recipient expected to resolve it. That is a normal enough thing to negotiate with a provider in practice. Inside a document that also asks for the file contents of every member of the servers concerned, it reads as a request whose edges had not been settled when it was filed. Take-Two says where it got the identifiers CONFIRMED, editor re-verified. The attachment labels its Discord targets "(guilds, from the open source video)" and "(from open source)". Those labels are an admission of provenance. The identifiers were taken from the leaked material itself. Somebody went through the footage, read off the server references visible in it, and built a target list from what the leak showed. That is a reasonable investigative step and it is also worth stating plainly, because it explains why the list looks the way it does. A server that appears on screen in a video gets swept in whether or not anybody in it did anything. Every image on this page is official Rockstar material, taken from the studio's own character video clips. Nothing on this page comes from leaked material, and we did not view any. What we are redacting, and why The attachment names three Discord servers, gives two guild IDs, and names three Discord account handles with their IDs. We are printing none of it. Our reasoning is simple. A court filing is a public record and its contents are fair to report. Republishing the identifiers inside it does something different from reporting: it hands a ready-made target list to anybody who wants to go and harass the people on it, none of whom has been accused of anything by anyone. Describing the scope by category and count tells you everything you need to judge the breadth of the demand. One point we have already reported and will repeat, because it is the part readers ask about. A well-known streamer's community server appears within the scope of this case. He is not accused of anything, he has not been sued or charged, and the demand is directed at a service provider rather than at him. What does section 512(h) allow? CONFIRMED. The statute is short and specific. 17 U.S.C. section 512(h)(3) requires the provider to "expeditiously disclose to the copyright owner or person authorized by the copyright owner information sufficient to identify the alleged infringer." And section 512(h)(2)(C) requires the applicant to file "a sworn declaration to the effect that the purpose for which the subpoena is sought is to obtain the identity of an alleged infringer." CONFIRMED. Take-Two filed exactly that declaration. Its own framing, verbatim from the parallel Google matter: "Take-Two, through its counsel of record, has submitted a sworn declaration confirming that the purpose for which the DMCA subpoena is sought is to obtain the identity of an alleged infringer or infringers, and that such information will only be used for the purpose of protecting Take-Two's rights under Title 17 U.S.C. sections 100, et. seq." So the question a court would eventually have to answer, if anybody ever put it to one, is whether the contents of a person's OneDrive and the membership roll of a server are "information sufficient to identify the alleged infringer". That is an argument a recipient or an affected user could make on a motion to quash. It is an argument and nothing more. No court has ruled on the scope of this demand, and the 21 August orders are one-page grants that do not discuss it at all. How the Google and X demands compare CONFIRMED. We pulled both sibling attachments as well, at HTTP 200, 537,926 bytes for Google and 517,995 bytes for X. They demand the same per-account data set, verbatim: "account ID, backend server metadata or telemetry records, original message logs, IP access logs, email addresses, phone numbers, connected accounts, registration timestamps, linked connections (social media, websites, etc.), and any associated device identifiers (MachineGuid/MSA)". The difference is who it applies to. Each of those two is limited to three named personas. There is no OneDrive demand in either. There is no bulk membership demand in either. DemandMicrosoft (421)Google (425)X Corp. (426) Per-account identifying datayesyesyes Scope of accountsevery member of three named servers since 1 June 2026three named personasthree named personas Device and telemetry recordsyes, conditioned on a list not in the filingserver metadata or telemetryserver metadata or telemetry Cloud storage contentsyes, OneDrive, filtered by subjectnono Internal investigation recordsyesnono Two law firms drafted these. The narrower pair came from Ruttenberg IP Law. The broader pair came from Kirkland & Ellis. Whatever else the comparison shows, it shows that a much tighter version of the same demand was drafted in the same week by the same client. Nobody has answered yet CONFIRMED NEGATIVE. No response from Microsoft, Google or X appears on any of the four dockets. We do not know whether any of them intends to comply, to object, or to negotiate the scope down. Providers frequently narrow demands like this in correspondence that never reaches a docket, and if that happens here we will probably never see it. What is and is not established Confirmed (editor re-verified at the primary source, 25 August 2026): the Microsoft Attachment A demands, quoted verbatim above, including the OneDrive clause and the demand covering all accounts that were members of the listed servers from 1 June 2026 to the present. Source exhibit HTTP 200, 835,534 bytes, MD5 86ab8832492ea84d55ade4e691a1f91b, five pages. Confirmed (editor re-verified): the word "artifact" appears exactly once in the whole document, in the conditioning phrase, and no artifact list follows. The document ends on page five with a table of Discord accounts. Not known, and flagged honestly: whether that artifact list exists elsewhere. It may have been supplied to Microsoft separately outside the court filing. We cannot check that from the docket. Confirmed (editor re-verified): one server's guild ID is given as to be determined by a partner, and one account's identifier is given as something for the recipient to resolve. Take-Two asked Microsoft to supply identifiers Take-Two did not itself hold. Confirmed (editor re-verified): the attachment labels its Discord targets as coming from the open source video and from open source, so the identifiers were derived from the leaked material itself. Confirmed: 17 U.S.C. section 512(h)(3) authorises disclosure of information sufficient to identify the alleged infringer, and section 512(h)(2)(C) requires a sworn declaration that identification is the purpose. Take-Two filed that declaration and its wording is quoted above. Confirmed: the Google and X attachments demand the same per-account data set but are limited to three named personas each, with no OneDrive demand and no bulk membership demand. Google attachment 537,926 bytes, X attachment 517,995 bytes, both HTTP 200. An argument, not a finding: that this demand exceeds what section 512(h) authorises. That is a point a recipient or an affected user could raise on a motion to quash. No court has ruled on scope, and the 21 August orders are one-page grants that do not discuss it. Confirmed negative: no response from Microsoft, Google or X appears on any docket. We do not know whether any of them will comply, object or narrow. Editorial policy: the attachment names three Discord servers with two guild IDs and three Discord account handles with IDs. We print none of them, because republishing them would hand a target list to people looking for one. We describe the scope by category and count instead. Explicitly not claimed: that any member of any named server did anything. Membership is not conduct, and a records demand contains no finding about anybody. If Microsoft responds, objects or narrows this in any way that reaches the public record, we will report it on our news page with the document shown. If you are here for something more cheerful, our servers list is where to go next.