What specific vulnerability led to this Last of Us 2 leak?
Sony and Scheier's comments were both vague in how they presented the information, but PixelButts' and
Kotaku's reports provide more specific context to about how the leak happened. They both revealed that a hacker group found a way to access Amazon servers that stored data for games like
Uncharted 3: Drake's Deception and
The Last of Us.
The group managed to take 1 TB of data from a server for
The Last of Us before the end of March, and while PixelButts made Naughty Dog aware of the vulnerability in February, access to those Amazon servers wasn't fixed until "on or before April 30." This gave the leaker more than enough time to get what they needed from the server and reveal it to the public.
PixelButts told
Kotaku that while this hacker group is definitely connected to the leak, "their circle is more just [Naughty Dog] enthusiasts that like development content from their games, rather than malicious actors." While the fan group itself wasn't responsible for the leak, someone cognizant of what they were doing most certainly was.
https://www.inverse.com/gaming/last-of-us-2-leaks-spoilers-controversy-explained