By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Massive Rainbow Six Siege breach reportedly linked to MongoBleed flaw — everything you need to know
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Massive Rainbow Six Siege breach reportedly linked to MongoBleed flaw — everything you need to know
News

Massive Rainbow Six Siege breach reportedly linked to MongoBleed flaw — everything you need to know

News Room
Last updated: 2025/12/28 at 6:25 PM
News Room Published 28 December 2025
Share
Massive Rainbow Six Siege breach reportedly linked to MongoBleed flaw — everything you need to know
SHARE

Hackers have caused absolute chaos in Ubisoft’s Rainbow Six Siege after breaching the company’s systems.

Instead of leaking stolen data from the game online, they’ve turned the company’s internal systems against it to ban and unban players, manipulate in-game message feeds and most surprisingly, give all players 2 billion in Rainbow Six Siege credits. While a 2 billion credit windfall for a single player is valued at roughly 13.3 million, reports suggest the total value of currency distributed across the entire player base has reached a staggering 339 trillion.

To make matters worse, security researchers are reporting that this breach is directly related to a recently disclosed MongoDB vulnerability. Dubbed MongoBleed, the flaw allows unauthenticated attackers to remotely leak the memory of exposed MongoDB instances. Attackers even used their access to the game’s management services to hijack a ban ticker that Ubisoft says had actually been disabled, using it to mock the company’s leadership directly.


You may like

Here’s everything you need to know about the recent Rainbow Six Siege hack along with the MongoBleed flaw and why this tactical, team-based first person shooter likely won’t be the last victim.

The Siege under siege

(Image credit: Ubisoft)

First launched back in 2015, Rainbow Six Siege is a tactical, first-person shooter and live-service game that pits two teams against each other. It had over 80,000 active monthly players at the beginning of the year thanks to the launch of a new expansion but this number has fallen to around 40,000 in the latter half of this year.

On December 27th, reports that the game was breached by hackers first began circulating online. While normally this would result in player data being stolen and then sold online, something completely different happened as a result of this breach.

The hackers behind the Rainbow Six Siege breach took the following actions after gaining access to Ubisoft’s systems:

Get instant access to breaking news, the hottest reviews, great deals and helpful tips.

  • Banned and unbanned thousands of people randomly, including high-profile streamer accounts.
  • Took over the ban feed to broadcast custom messages mocking Ubisoft leadership, even though the ban ticker feature had actually been disabled in a past update.
  • Gave everyone 2 billion in premium R6 credits and Renown. While the value of these credits for a single player is estimated at over 13 million, some reports suggest the total value of currency distributed reached a staggering 339 trillion.
  • Gave everyone every skin in the game, including ultra-rare Glaciers and even developer-only cosmetics.

According to BleepingComputer, Ubisoft confirmed that the incident took place early in the morning on December 27th and said its teams were working to resolve an issue currently affecting the game. From there, the company then shut down the game and its in-game marketplace to prevent further damage to the player-driven economy.

If you’re a Ubisoft player that spent some of those 2 billion credits that magically appeared in your Rainbow Six Siege account, there’s good news and bad news. While you won’t be punished for spending them, Ubisoft is currently rolling back all transactions that occurred after 11:00 AM UTC on December 27th.

So how did the hackers behind this breach manage to pull it off? Well, at least according to some reports, the new MongoBleed flaw is to blame.


You may like

Leaking memory without passwords

A hand typing at a computer in a dark room, lit up by the laptop's keyboard LEDs and red LED light

(Image credit: Getty Images)

Although they haven’t been verified by Ubisoft yet, the security research group VX-Underground is claiming with medium to high confidence that hackers used a recently disclosed MongoDB flaw to breach the company’s systems.

The vulnerability (tracked as CVE-2025-14847 and dubbed MongoBleed) allows unauthenticated attackers to remotely leak the memory of exposed MongoDB instances. By sending malformed, compressed network packets to the server’s zlib decompression logic, attackers can trick the database into “bleeding” fragments of its internal heap memory. This can expose sensitive data like plain-text database passwords, session tokens, and administrative authentication keys.

As reported by The Hacker News, MongoBleed has a high-severity CVSS score of 8.7 and impacts a broad range of database versions:

  • MongoDB 8.2.0 through 8.2.2
  • MongoDB 8.0.0 through 8.0.16
  • MongoDB 7.0.0 through 7.0.27
  • MongoDB 6.0.0 through 6.0.26
  • MongoDB 5.0.0 through 5.0.31
  • MongoDB 4.4.0 through 4.4.29
  • All legacy versions including MongoDB Server v4.2, v4.0, and v3.6

While the flaw has been patched in versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30, many organizations have not yet upgraded to a fixed release.

What makes the investigation so complex is that multiple unrelated groups of cybercriminals appear to have targeted Ubisoft simultaneously.

According to VX-Underground, a first group compromised live game services to manipulate inventories and bans, while a second group allegedly used MongoBleed to pivot into Ubisoft’s internal Git repositories. This second group reportedly stole source code for various projects dating from the 1990s to the present day. Meanwhile, a third group is reportedly attempting to extort Ubisoft over stolen user data, while a fourth group claims the source code was already compromised long before the current chaos began.

Rainbow Six Siege won’t be the last victim

While Rainbow Six Siege could potentially be the first public victim of MongoBleed, the sheer scale of MongoDB’s global footprint shows that it likely won’t be the last. As of this year, over 60,000 organizations across nearly every industry rely on this open-source tool for their backend infrastructure.

With 200,000 instances estimated to currently be exposed online, the potential for widespread exploitation of MongoBleed is quite high. Since this exploit isn’t too complicated and requires no authentication, other companies could suffer a similar fate to what happened with Rainbow Six Siege if they don’t patch their systems immediately.

From credential harvesting to undetected data theft, MongoBleed attacks could have wide reaching implications for organizations and their users across a wide variety of industries.

Hopefully companies take immediate steps to remedy this situation because if they don’t you’ll be reading (and I’ll be writing) about a lot more MongoBleed-powered attacks next year.


Google News

Follow Tom’s Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds.


More from Tom’s Guide

Today’s identity theft protection deals

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Missing Robot In The Antarctic Returned With Terrifying Data – BGR Missing Robot In The Antarctic Returned With Terrifying Data – BGR
Next Article Microsoft Office 2019 drops to .97 for a lifetime Windows license Microsoft Office 2019 drops to $29.97 for a lifetime Windows license
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Java News Roundup: Spring Vault, LangChain4j, Seed4J, Infinispan, Gradle
Java News Roundup: Spring Vault, LangChain4j, Seed4J, Infinispan, Gradle
News
China outlines rules to regulate human-like AI companion apps –  News
China outlines rules to regulate human-like AI companion apps – News
News
I tested dozens of gaming laptops this year — these are the 3 fastest you can buy
I tested dozens of gaming laptops this year — these are the 3 fastest you can buy
News
KDE Plasma’s Wayland Transition “Nears Completion” In Ending Out 2025
KDE Plasma’s Wayland Transition “Nears Completion” In Ending Out 2025
Computing

You Might also Like

Java News Roundup: Spring Vault, LangChain4j, Seed4J, Infinispan, Gradle
News

Java News Roundup: Spring Vault, LangChain4j, Seed4J, Infinispan, Gradle

5 Min Read
China outlines rules to regulate human-like AI companion apps –  News
News

China outlines rules to regulate human-like AI companion apps – News

6 Min Read
I tested dozens of gaming laptops this year — these are the 3 fastest you can buy
News

I tested dozens of gaming laptops this year — these are the 3 fastest you can buy

14 Min Read
Apple warns employees not to leave the U.S. amid return delays – 9to5Mac
News

Apple warns employees not to leave the U.S. amid return delays – 9to5Mac

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?