Ubisoft Rainbow Six Siege Servers Breach linked to MongoBleed Vulnerability
On December 27, 2025, Ubisoft's Rainbow Six Siege servers experienced a significant security breach. A hacker group known as the First Group initiated unauthorized activities on the servers, resulting in unexpected in-game disruptions.
On December 27, 2025, Ubisoft's Rainbow Six Siege servers experienced a significant security breach. A hacker group known as the First Group initiated unauthorized activities on the servers, resulting in unexpected in-game disruptions.
Players globally have reported receiving substantial amounts of in-game currency, including R6 Credits, Renown, and Alpha Packs. Additionally, exclusive items typically locked behind paywalls were made accessible to some users. The attackers used the in-game ban feed to issue unwarranted bans, affecting high-profile accounts, including those of Ubisoft administrators and popular streamers.
Ubisoft has acknowledged the breach and is currently addressing the issue. Temporary server downtime is occurring as part of unannounced maintenance and restarts. Players are advised to refrain from accessing Ubisoft Connect or Rainbow Six Siege until server stability is confirmed, due to potential risks of data corruption or account tampering.
On December 27, 2025, Ubisoft's Rainbow Six Siege servers experienced a significant security breach.
The breach has been attributed to an API authorization failure. The First Group exploited this vulnerability to manipulate game features. An additional, unrelated breach by the Second Group has also been reported, involving the exfiltration of source code through a MongoDB vulnerability, identified as CVE-2025-14847. This flaw allows unauthorized access to server memory by using malformed compressed packets.
Security experts highlight that the Second Group's actions could lead to significant intellectual property losses for Ubisoft, potentially facilitating cheat development.
Ubisoft is implementing measures to revert the unauthorized changes made during the breach. This rollback process may affect legitimate player progress made over the weekend. The company is expected to provide further updates once the situation is fully resolved.
Based on reporting by Cyber Security News.
