Ubisoft Confirms Rainbow Six Siege Server Breach Linked to MongoBleed Vulnerability
ID: ee82cb0c-69ed-5eda-b4e6-f21d2a5ddca7
STIX ID: report--ee82cb0c-69ed-5eda-b4e6-f21d2a5ddca7
Feed Name: Cyber Press
Ubisoft experienced a critical breach via the MongoBleed vulnerability (CVE-2025-14847) allowing unauthenticated, network-based arbitrary data reads and memory disclosure; attackers tampered with millions of Rainbow Six Siege accounts (mass in-game currency fraud and unlocked cosmetics), weaponized the anti-cheat ban system for messaging, and reportedly exfiltrated ~900GB of sensitive materials including source code and SDKs. Ubisoft confirmed the incident, took servers offline for maintenance, plans a data rollback, and advised players to avoid Ubisoft Connect until integrity is verified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
