Phishing

Malicious Code on Unity Website Skims Information From Hundreds of Customers

The video game software development company says the incident impacted users of its SpeedTree website.

Unity skimming

Hundreds of users had sensitive information skimmed through a compromised website belonging to video game software development company Unity Technologies.

Impacted individuals are being informed that threat actors compromised the website for Unity’s SpeedTree 3D vegetation modeling software. 

An investigation showed that the SpeedTree website, specifically its checkout page, contained malicious code between March 13 and August 26, 2025. 

The malicious code was designed to harvest the information entered by individuals who made purchases on the SpeedTree site, including name, address, email address, payment card number, and access code.

Unity told the Maine Attorney General’s Office that 428 individuals are impacted. The affected customers are now being notified and offered free credit monitoring and identity protection services.

The disclosure comes shortly after gamers have been warned about a high-severity Unity Editor vulnerability that can allow attackers to load arbitrary libraries and execute malicious code. 

Advertisement. Scroll to continue reading.

Hackers can leverage the flaw to access sensitive information on devices running applications built with Unity.

The vendor has released patches, but Microsoft and Valve have also rushed to take action to protect customers against potential attacks.

Related: SonicWall SSL VPN Accounts in Attacker Crosshairs

Related: NPM Infrastructure Abused in Phishing Campaign Aimed at Industrial and Electronics Firms

Related: Spanish Authorities Dismantle ‘GXC Team’ Crime-as-a-Service Operation

Related: Extortion Group Leaks Millions of Records From Salesforce Hacks

Related Content

Artificial Intelligence

A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration.

Data Breaches

Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers.

Cybercrime

The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.

Data Breaches

The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. 

Data Breaches

The attackers used a compromised BigCommerce application key held by Ribon to access customer data.

Data Breaches

The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.

Data Breaches

Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.

Data Breaches

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version