encrypted passwords, full credit card numbers and expiration dates (but no CCV's), full names, billing addresses & zip codes, session tokens, transaction history, and 2FA backup codes were posted in a Discord server dedicated to cheating by the group claiming to be responsible for the hack.
Unknown Extent of Incident: Some have speculated that the hackers could also have exploited the kernel-level anti-cheat (BattlEye) which Rainbow Six Siege users in order to infect all players with malware. This claim remains unverified.
My thoughts
This is still a developing story, and at the time of writing we do not know the full scope of what was accessed or altered on Ubisoft’s side. What is clear, though, is that the attackers were able to tamper with multiple “trust” systems at once: account entitlements (R6 Credits/Renown and cosmetics), moderation state (ban flags), and player-facing messaging (the reintroduced ban ticker). When a live-service title’s backend can be manipulated at that level, it stops being a “game issue” and becomes a platform security issue, because the same services that deliver cosmetics also enforce integrity and protect purchases.
The 2B R6 Credits figure is especially useful as a scale indicator. Even if the currency cannot be converted into real money, granting the equivalent of roughly $13.33 million in premium currency per account is enough to destabilize the in-game economy and the Marketplace immediately. At that point, a rollback is essentially the only practical containment option—trying to selectively unwind purchases and trades at player scale is slow, error-prone, and invites more disputes. Unfortunately, rollbacks also create collateral damage: legitimate Marketplace transactions, time-limited purchases, and other progression made during the affected window can be lost, and players end up bearing the cost in time and uncertainty.
The other major concern is the leak of sensitive account data (emails, plaintext passwords, payment details, tokens, 2FA backup codes, etc.). The risk expands beyond Siege to classic account takeover and potential fraud. Regardless of what ultimately gets confirmed publicly, this is the kind of incident where players should assume elevated risk and act accordingly: change passwords (and do not reuse them anywhere else), enable/refresh 2FA, revoke active sessions where possible, and monitor payment methods and account activity.
Finally, there has also been speculation about whether the attackers could have leveraged kernel-level anti-cheat components (BattlEye) to push malware. That claim remains unverified, but it highlights the real anxiety players feel when a game’s “trusted” components sit deep in the OS. Ubisoft’s next steps matter here: the shutdown and rollback are the immediate containment measures, but the longer-term trust repair will depend on transparency and what was compromised, what data (if any) was exposed, what cont