Cybercrime tends to work best when people are excited, distracted or in a hurry. Give someone something they desperately want and there is a good chance they will spend less time wondering whether they should trust it.
The latest Grand Theft Auto VI leak saga provided an almost perfect example. After genuine leaked material attracted enormous attention online, a supposed 113GB playable GTA VI build began appearing on torrent sites. Its sheer size helped sell the illusion. A game that big must contain something substantial, right?
Apparently not.
People who reverse-engineered the file reported that roughly 99.99% of it was empty padding, with a malicious payload of only about 50KB buried inside. The code reportedly attempted to exclude the entire C:\ drive from Windows Defender scanning and shut down security software. The gigantic download was, for the most part, camouflage.
There is an important distinction here. Reporting indicates that the file was a copycat scam exploiting the attention surrounding Cyberleek, rather than evidence that Cyberleek itself distributed the malicious ISO. Keeping those stories separate matters when distinguishing an actual leak from criminals simply taking advantage of the publicity.
Cyberleek’s own attempts to monetise the attention were unusual enough. Its website advertised promotional placements and customised gameplay content, while access to private negotiations required payment in Monero. Reports valued the required 400 XMR at approximately US$165,000–US$170,000 at the time.
Calling that a confirmed US$170,000 “extortion demand”, however, would overstate what the available evidence shows. The website characterised it as a contact fee, not a ransom demand.
What the episode demonstrates rather neatly is how online traps exploit three things people regularly underestimate: curiosity, urgency and apparent legitimacy.
| Digital threat | How the trap works | Property transaction equivalent |
| Fake download | A believable file hides something malicious | A convincing email contains fraudulent instructions |
| Malware | Software weakens security or compromises a device | A compromised account exposes transaction information |
| Impersonation | Criminals borrow the credibility of something genuine | Scammers pose as agents, solicitors or conveyancers |
| Urgency | The victim acts before checking | “New bank details — settlement today” |
| Payment redirection | Money is diverted to the attacker | Deposit or settlement funds reach a criminal account |
| Independent verification | Authenticity is checked through another channel | Payment instructions are confirmed using a trusted phone number |
The property scam that arrives at exactly the right time
This is where a story about a video game becomes uncomfortably relevant to Australian property buyers.
The Australian Signals Directorate’s Australian Cyber Security Centre has specifically warned about business email compromise (BEC) affecting property transactions. Criminals may compromise a genuine email account or convincingly impersonate a property professional, then substitute fraudulent bank details into communications concerning payments.
Scamwatch describes the same basic scenario: a home buyer receives what appears to be a legitimate request for a deposit, but the bank details have been changed. The buyer follows the instructions and the money goes somewhere entirely different.
The frightening part is that the fraudulent message does not necessarily look fraudulent. If an attacker has compromised an email account, they may have enough context to make their message fit naturally into an existing conversation.
Warning signs worth treating seriously include • a sudden change to a BSB or account number • unusual pressure to transfer money quickly • a subtly altered email address • an unexpected attachment or login link • unusual requests for sensitive information • or instructions discouraging independent confirmation of payment details. Scamwatch recommends checking changed payment information by calling the business using a telephone number obtained independently.
And Australians are increasingly doing exactly that. PEXA’s 2026 consumer research found that 54% of recent property buyers called their conveyancer or agent using a known telephone number to verify sensitive information such as bank details, while another 33% used a secure tool such as PEXA Key.
The fake GTA VI file leaves us with a wonderfully simple warning: something can look impressively legitimate and still be completely wrong.
When the thing you are trusting is a settlement instruction rather than a game download, the consequences are considerably more serious.

Flash Conveyancing Advice
If bank details suddenly change during your property transaction, don’t verify them by replying to the same email. If that account has been compromised, you may simply be asking the scammer whether their own fraudulent details are correct. Stop, call your conveyancer on a number you already know or have independently verified, and read the BSB and account number back verbally before transferring significant funds. If suspicious funds have already been sent, contact your bank immediately.
A property purchase can involve years of savings changing hands in minutes. Payment verification deserves more attention than a quick glance at an email before clicking “transfer”.
Flash Conveyancing, led by Julian & Renee, specialises in property transactions throughout NSW with a deliberately personal approach. Clients deal with people who understand their transaction rather than relying entirely on automated communications when contracts, identity information and substantial amounts of money are involved.
As part of Flash Conveyancing’s stated security procedures, payment directions, BSBs and account numbers are directly voice-verified with clients before funds move. No responsible security system can promise to eliminate every possibility of cyber fraud, but independent human confirmation creates an important additional barrier against payment-redirection scams.
Flash Conveyancing also uses air-gapped local storage as one layer of its approach to protecting sensitive client information. Keeping selected information or backups offline is not an impenetrable cyber shield, but isolation from continuously connected systems can form a useful part of a broader security strategy.
Julian & Renee assist buyers and sellers throughout Sydney, Newcastle and Wollongong, including property transactions across Blacktown, Hawkesbury, Blue Mountains, The Hills, Hornsby and Parramatta.
Their NSW conveyancing service also extends to Acacia Gardens, Angus, Arndell Park, Blacktown, Colebee, Glendenning, Glenwood, Grantham Farm, Kellyville Ridge, Kings Langley, Marsden Park, Melonba, Oakhurst, Parklea, Quakers Hill, Riverstone, Schofields, Seven Hills, Stanhope Gardens, Tallawong, The Ponds, Baulkham Hills, Beaumont Hills, Bella Vista, Castle Hill, Kellyville, Kenthurst, North Rocks, Northmead, Rouse Hill, Vineyard, Windsor, Annangrove, Box Hill, Cattai, Dural, Gables, Galston, Glenhaven, Glenorie, Maraylya, Middle Dural, Nelson, North Kellyville, Norwest and Winston Hills, as well as elsewhere across NSW.
The fake GTA VI torrent needed 113GB of padding to make a tiny malicious file look convincing.
A property scammer may need nothing more than one familiar email and one changed account number. Before your property money moves, make sure the person behind the instructions really is who you think it is.

