Hackers gained unauthorized access to Ubisoft's Rainbow Six Siege servers, resulting in widespread manipulation of the game's in-game economy and administrative systems. Players around the world reported receiving billions of R6 Credits, Renown, and exclusive cosmetic items, including developer-only skins, directly into their accounts. The attackers also abused internal moderation tools to ban and unban accounts, including those belonging to Ubisoft administrators and popular streamers, and used the in-game ban feed to broadcast taunting and cryptic messages to the player base.
Ubisoft responded by confirming the breach, intentionally shutting down Rainbow Six Siege and its in-game Marketplace to contain the incident, and announcing that all transactions since the attack would be rolled back. The company clarified that players would not be penalized for spending the illicitly granted credits and that the fake ban messages were not generated by Ubisoft. As of the latest updates, Ubisoft was still working to restore full service and had not disclosed the technical details of how the breach was accomplished.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
By December 29, 2025, Ubisoft had restored Rainbow Six Siege services after the shutdown. The company continued reversing unauthorized changes from the breach, while keeping the in-game marketplace closed for additional review.
On December 28, 2025, reporting surfaced that a separate recent Ubisoft source-code theft was attributed to a different threat actor and allegedly involved exploitation of the MongoBleed vulnerability, CVE-2025-14847. These claims were presented as distinct from the confirmed Rainbow Six Siege in-game abuse, and Ubisoft had not confirmed the broader allegations.
On December 28, 2025, Ubisoft publicly acknowledged the breach-related disruption, intermittently kept services offline, and indicated it would roll back player data and transactions to undo unauthorized credits, items, and account changes. Ubisoft also clarified that players would not be punished for spending illicitly granted credits.
On December 27, 2025, Ubisoft shut down Rainbow Six Siege servers in response to the breach and resulting loss of control over game systems. The outage also affected normal gameplay as the company worked to contain the incident.
By December 27, 2025, attackers had gained extensive control over Rainbow Six Siege backend or administrative systems. Reports describe mass bans and unbans, fake ban-feed messages, and unauthorized grants of huge amounts of credits, Renown, and rare or developer-only cosmetic items to players.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcetomshardware.com
Open sourcetomshardware.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.