Ubisoft has taken Tom Clancy’s Rainbow Six Siege X offline after a major security breach that allowed attackers to change in-game balances and grant enormous amounts of paid currency. Players saw sudden account changes and rare items appear. Ubisoft shut down game services and the in-game marketplace while it investigated and worked to restore normal play.

What Happened
Over the weekend, many Rainbow Six Siege X players reported seeing unusual account changes. Screenshots and short videos showed accounts with massive added balances of R6 Credits and new rare items. Some players reported seeing two billion R6 Credits suddenly added to their accounts. R6 Credits are the game currency bought with real money. Ubisoft affirmed that it knew about an incident and went on to close the game and its Marketplace as it investigated.
Ubisoft reported that it returned the game to a previous state and conducted a massive test before restoring services online. The company also threatened to reverse all the transactions past a certain cutoff and that the Marketplace would be closed until a team finished the investigation. Ubisoft posted updates on its official account as events unfolded.
Ubisoft Response
Ubisoft moved quickly to contain the issue. The studio acknowledged the breach on its official channel and took the game and Marketplace offline within hours. The developer later confirmed a rollback to undo unauthorized changes and began quality control tests before a staged restart. Ubisoft said that players who spent credits granted by the breach would not be penalized, but that purchases made after the breach cutoff would be reversed as the rollback took effect. The Marketplace is still closed while the company continues its inquiry.

The company has not published a full technical breakdown of how the attackers gained access. Ubisoft indicated that it would provide additional information when the investigation permits it to do so. Incidents of breaches such as this are usually investigated by studying logs of server access logs, access tokens, and account activity to establish the point of entry and flow of malicious activity. Security teams also seek exposure of data or backdoor evidence.