Ubisoft A.I CyberSecurity Scoring
Ubisoft
Company Information
Website:https://www.ubisoftgroup.com
Employees number:21,990
Number of followers:1,486,883
NAICS:51126
Industry Type:Computer Games
Homepage:ubisoftgroup.com
Ubisoft Risk Score (AI oriented)
Between 0 and 549
UbisoftComputer Games
Updated:
07/06/2026
07/06/2026
492/1000
Critical
C
Ubisoft Global Score (TPRM)
xxxx
UbisoftComputer Games
Score locked

UbisoftCritical
Current Score
492C (CRITICAL)
01000
6 incidents
-128 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
492
MAY 2026
488
APRIL 2026
488
MARCH 2026
472
FEBRUARY 2026
472
JANUARY 2026
468
DECEMBER 2025
603
Breach
28 Dec 2025 • Ubisoft
Ubisoft: Massive Rainbow Six Siege breach gives players billions of credits
Ubisoft Rainbow Six Siege In-Game Abuse and Potential Larger Breach
462
CRITICAL-141
UBI1766901285
Ubisoft’s *Rainbow Six Siege* Hit by Major Breach, In-Game Systems Compromised
Ubisoft’s Rainbow Six Siege (R6) suffered a significant security breach, allowing attackers to manipulate in-game systems, distribute unauthorized rewards, and disrupt player accounts. The incident, confirmed by Ubisoft on Saturday at 9:10 AM via the official R6 X account, led to the game and its Marketplace being temporarily shut down for investigation.
Hackers exploited internal systems to perform several unauthorized actions, including:
- Banning and unbanning players at will.
- Displaying fake ban messages on the in-game ban ticker (later confirmed as fraudulent by Ubisoft).
- Granting players approximately 2 billion R6 Credits—a premium currency worth roughly $13.33 million based on Ubisoft’s pricing.
- Unlocking all cosmetic items, including developer-exclusive skins.
Ubisoft stated that players would not face penalties for spending the illicitly granted credits but would roll back all transactions made after 11:00 AM UTC. The company also disabled the ban ticker, confirming it did not generate the fake messages.
While Ubisoft has not disclosed how the breach occurred, unverified reports suggest a broader compromise. Security research group VX-Underground cited claims from multiple threat actors, including:
- One group allegedly exploited an R6 service to manipulate bans and inventory without accessing user data.
- A second group claimed to have used the MongoBleed vulnerability (CVE-2025-14847)—a recently disclosed flaw in MongoDB—to pivot into Ubisoft’s internal Git repositories, potentially stealing decades of source code.
- A third group reportedly stole user data via MongoBleed and attempted extortion.
- A fourth group disputed some claims, asserting that source code access was already established.
Ubisoft has not confirmed these allegations, and BleepingComputer could not independently verify the extent of the breach beyond the confirmed in-game abuse. As of now, servers remain offline, and no formal statement on the attack vector has been released. Updates will follow if new details emerge.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
600
OCTOBER 2025
597
SEPTEMBER 2025
594
AUGUST 2025
590
JULY 2025
700
Ransomware
15 Jul 2025 • Ubisoft
Ubisoft
Ubisoft Ransomware Attack by Lapsus$ Gang
585
MEDIUM-115
UBI4432044091525
Ubisoft, the renowned video game developer behind franchises like Assassin’s Creed, Far Cry, and Just Dance, fell victim to a ransomware attack orchestrated by the Lapsus$ gang, a cybercriminal group known for high-profile breaches, including Samsung and Nvidia. The attack primarily aimed to steal sensitive corporate data for extortion, threatening public release unless a ransom was paid. While the incident caused temporary disruptions to Ubisoft’s web-based services, the company confirmed that no player personal data was compromised, and all systems were swiftly restored to full operation. The attack underscores the growing threat of ransomware groups targeting major enterprises for financial gain, leveraging stolen data as leverage. Ubisoft’s proactive measures, including cybersecurity solutions like Acronis Cyber Protect, helped mitigate further damage by blocking encryption and extortion attempts. The incident highlights the critical need for robust cybersecurity defenses against evolving ransomware tactics, even when direct customer impact is minimized.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2023
737
Breach
01 Dec 2023 • Ubisoft
Ubisoft
Possible Data Breach at Ubisoft
672
CRITICAL-65
UBI056251223
The well-known video game publisher, Ubisoft, is looking into reports of a possible data breach after well-known researchers vx-underground released proof.
According to the experts, Ubisoft's infrastructure was accessible to an unidentified threat actor for approximately 48 hours. After learning of the attack, the administrators locked the invaders out.
The attackers' method of breaking into the organisation remains unknown; they made an unsuccessful effort to obtain user data from R6 Siege.
The company's SharePoint, Confluence, and Microsoft Teams installations are accessible.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2022
743
Cyber Attack
01 Mar 2022 • Ubisoft
Ubisoft
Cyberattack on Ubisoft
722
CRITICAL-21
UBI205114322
The French video game company Ubisoft was targeted in a cyberattack in the first week of March 2022.
The attack caused temporary disruptions in its games, systems, and services which were soon restored.
Although no personal information was compromised in the attack still company asked its employees for a company-wide password reset.
The Lapsus$ extortion group on their Telegram group posted information about the incident.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
NOVEMBER 2020
736
Cyber Attack
06 Nov 2020 • Ubisoft
Crytek, Capcom, Ubisoft and Nintendo: Capcom hacked in latest cyber-attack on game-makers
Cyberattacks Target Major Video Game Studios, Exposing Source Code and Internal Data
715
CRITICAL-21
NINCRYUBICAP1780793478
Cyberattacks Target Major Video Game Studios, Exposing Source Code and Internal Data
In a wave of recent cyber incidents, leading video game companies including Capcom, Ubisoft, and Crytek have fallen victim to ransomware attacks and data breaches, raising concerns over the security of intellectual property in the gaming industry.
Capcom, the Japanese developer behind franchises like Resident Evil and Street Fighter, confirmed a cyberattack on its systems earlier this week. The breach, attributed to the Ragnar Locker ransomware group, disrupted internal networks, including email and file servers. While the company stated there was no evidence of customer data being accessed, it did not disclose whether source code or other sensitive materials were stolen. The attack follows a pattern of recent breaches in the industry, though experts see no evidence of a coordinated campaign.
Meanwhile, Ubisoft is investigating claims that hackers stole source code for Watch Dogs: Legion, with reports suggesting the data was leaked online. The company acknowledged a potential security incident after internal network issues surfaced but has not confirmed the extent of the breach. Similarly, Crytek known for the Crysis series was also targeted by the same hacking group, raising fears that proprietary game code could be sold or distributed illegally.
The attacks come amid a broader trend of cyber threats against gaming companies, including previous leaks from Nintendo. While no major disruptions to gameplay or official services have been reported, the incidents highlight vulnerabilities in an industry increasingly targeted for its valuable digital assets. The long-term impact may include unauthorized game modifications, knockoff releases, or the exploitation of stolen development materials.
As investigations continue, the gaming sector remains on alert for further disclosures of compromised data.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2020
753
Cyber Attack
01 Oct 2020 • Ubisoft
Ubisoft
Ubisoft Data Leak
735
CRITICAL-18
UBI18911222
The data of Ubisoft, a french video game company was leaked by the attackers after a cyber attack on their servers.
The compromised data included technical identifiers like GamerTags, profile IDs, Device IDs, and Just Dance videos.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Ubisoft ??
What was Ubisoft's A.I Rankiteo Cyber Score in May 2026 ??
What was Ubisoft's A.I Rankiteo Cyber Score in April 2026 ??
What was Ubisoft's A.I Rankiteo Cyber Score in March 2026 ??
What was Ubisoft's A.I Rankiteo Cyber Score in February 2026 ??
What was Ubisoft's A.I Rankiteo Cyber Score in January 2026 ??
What was Ubisoft's A.I Rankiteo Cyber Score in December 2025 ??
What was Ubisoft's A.I Rankiteo Cyber Score in November 2025 ??
What was Ubisoft's A.I Rankiteo Cyber Score in October 2025 ??
What was Ubisoft's A.I Rankiteo Cyber Score in September 2025 ??
What was Ubisoft's A.I Rankiteo Cyber Score in August 2025 ??
What was Ubisoft's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Ubisoft's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Ubisoft ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Ubisoft's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?