Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Phishing

Malicious Code on Unity Website Skims Information From Hundreds of Customers

The video game software development company says the incident impacted users of its SpeedTree website.

Unity skimming

Hundreds of users had sensitive information skimmed through a compromised website belonging to video game software development company Unity Technologies.

Impacted individuals are being informed that threat actors compromised the website for Unity’s SpeedTree 3D vegetation modeling software. 

An investigation showed that the SpeedTree website, specifically its checkout page, contained malicious code between March 13 and August 26, 2025. 

The malicious code was designed to harvest the information entered by individuals who made purchases on the SpeedTree site, including name, address, email address, payment card number, and access code.

Unity told the Maine Attorney General’s Office that 428 individuals are impacted. The affected customers are now being notified and offered free credit monitoring and identity protection services.

The disclosure comes shortly after gamers have been warned about a high-severity Unity Editor vulnerability that can allow attackers to load arbitrary libraries and execute malicious code. 

Advertisement. Scroll to continue reading.

Hackers can leverage the flaw to access sensitive information on devices running applications built with Unity.

The vendor has released patches, but Microsoft and Valve have also rushed to take action to protect customers against potential attacks.

Related: SonicWall SSL VPN Accounts in Attacker Crosshairs

Related: NPM Infrastructure Abused in Phishing Campaign Aimed at Industrial and Electronics Firms

Related: Spanish Authorities Dismantle ‘GXC Team’ Crime-as-a-Service Operation

Related: Extortion Group Leaks Millions of Records From Salesforce Hacks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.