Suspicious

I received an email from, Unity Technologies (unity-technologies@unity3d.com), with the following message.


Hello,

Your invoice [the invoice] is available and attached as a PDF.

Invoice Total Amount: 0.00 USD

Thank you for using Unity!

sincerely,
The Unity Team.


This is the message, and in it is a PDF attached. But I don’t remember any invoice. Is this message real or a hacking scam?

I’m guessing you’re subscribed for some of the new multiplayer stuff? Like Relay and/or Lobby?
This is new: https://discussions.unity.com/t/884845

I also got today the notification from google workspaces that it sees it as phishing:

  • Summary: Google detected and reclassified 1 message(s) from unity-technologies@unity3d.com as phishing post-delivery. These messages were not opened and have been removed from recipients’ inboxes. There was 1 recipient(s).
  • Activity date: Freitag, 13.10.2023, 06:47:54 (UTC)
  • Actor: unity-technologies@unity3d.com
  • Total messages: 1

When I open the PDF inside the browser it looks like a legit invoice for the position:

Total Storage
CLD-BLD-STO

Its phishing, I also got it

Be careful with PDFs you don’t trust. It’s easy to embed malicious code into them.

https://www.adobe.com/acrobat/resources/can-pdfs-contain-viruses.html

Linus Tech Tips got hacked a few months back by simply opening one.

https://www.theverge.com/2023/3/24/23654996/linus-tech-tips-channel-hack-session-token-elon-musk-crypto-scam

4 Likes

Yup, use a virtual machine if you aren’t sure about the legitimacy of an email and you want to open the files linked.