Respawn Entertainment confirmed an active security incident in Apex Legends in which a threat actor could remotely control another player’s in-game inputs, including moving characters off the map, disconnecting clients, and forcibly changing player nicknames (commonly to RSPN Admin). Respawn stated its initial investigation found no evidence of remote code execution (RCE), injection, or malware installation on players’ systems, and the company reported the issue was resolved after several hours of ongoing player disruption.
Reporting indicates Respawn patched an exploit believed to be associated with the game’s anti-cheat component, after the behavior was observed impacting multiple players and streamers over the prior week. The incident drew comparisons to a 2024 Apex tournament disruption in which a separate exploit was used to deploy cheating software on participants’ PCs (an event previously claimed by Destroyer2009), but current statements emphasize the 2026 incident did not show signs of code execution on customer machines.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Respawn later patched the exploit that allowed attackers to remotely control players' in-game characters, reportedly deploying the fix through the game's anti-cheat component. The company reiterated that it found no evidence the exploit enabled malware installation or code execution on players' PCs.
Roughly six hours after acknowledging the issue, Respawn said the disruption had been resolved. The company provided few technical details but continued to frame the incident as cheat-related.
On Saturday, Respawn publicly confirmed it was investigating the player-hijacking incident and said its initial investigation found no evidence of remote code execution, code injection, or malware installation on players' systems. The company indicated the issue appeared related to cheating rather than compromise of player PCs.
Over the weekend, Apex Legends players reported that a malicious actor was remotely controlling character inputs, forcing abnormal movement, disconnecting clients, and changing nicknames such as "RSPN Admin." Community discussion suggested possible abuse of server-side administrative or debugging capabilities.
During a North American Apex Legends competition the previous year, hackers compromised players during matches, leading Electronic Arts to postpone the finals. The incident became a point of comparison for later concerns about game security and anti-cheat effectiveness.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcenews.risky.biz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.