Unity Technologies, a prominent video game software development company, experienced a significant data breach involving its SpeedTree 3D vegetation modeling software website. The breach was the result of malicious code injected into the checkout page, which remained undetected from March 13 to August 26, 2025. This unauthorized code was capable of skimming sensitive customer information during the purchase process. As a result, data belonging to 428 customers was compromised, including names, addresses, email addresses, access codes, and payment card details. Unity Technologies discovered the breach on August 26, 2025, and immediately took action by disabling the website and removing the malicious code. The company launched a thorough investigation to determine the scope and impact of the incident. Following the investigation, Unity notified affected customers and relevant authorities, including the Office of the Maine Attorney General. To mitigate the potential impact on victims, Unity is providing 12 months of complimentary credit monitoring and identity protection services through Equifax. The breach notification letter detailed the timeline of the compromise and the specific data elements exposed. Unity also reviewed affected files and implemented additional security measures to prevent similar incidents in the future. The company’s response included transparent communication with customers and regulatory bodies. The incident highlights the risks associated with e-commerce platforms and the importance of monitoring for unauthorized code injections. In parallel, Unity disclosed a separate high-severity vulnerability in the Unity Editor, tracked as CVE-2025-59489, which could allow arbitrary library loading and malicious code execution, though this was not directly related to the SpeedTree breach. Customers who made purchases on the SpeedTree website during the affected period are advised to monitor their financial accounts for suspicious activity. The breach underscores the need for robust web application security and timely detection of malicious activity. Unity’s swift response and offer of identity protection aim to reduce the risk of further harm to affected individuals. The incident serves as a reminder for organizations to regularly audit their web infrastructure for vulnerabilities and unauthorized changes.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
Unity Technologies disclosed that its SpeedTree website was compromised, resulting in the theft of customer payment card information. Reporting indicates the incident affected more than 400 individuals.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.