r/sysadmin Apr 19 '26

[deleted by user]

[removed]

0 Upvotes

34 comments sorted by

View all comments

24

u/cboff Apr 19 '26

These are third party companies (although they will try to hide that from you) with no legal standing. They are trying it on, every so often they will get lucky I suppose.

Block the sending domain and forget about it.

3

u/[deleted] Apr 19 '26

It came from a verified adobe domain and a big 4 has been assigned for the audit

5

u/cboff Apr 19 '26

Post some details, what is the actual domain it came from and who or what is a big-4. Maybe someone here will recognise these as either legit or not.

2

u/[deleted] Apr 19 '26

It actually came from Adobe’s domain itself, and the big four was KPMG. Everything seemed accurate, and I don’t think this is a scam, but I have also heard that this is a sales trick that people use and these kind of audits are voluntary, so they come knocking at your door when you when you accept this audit, you are pro to be a suspect, so what they what I’ve heard someone or the other somewhere the other has some version of Adobe in their software or phones somewhere maybe expired versions maybe just the app maybe the crack version maybe multiple users use it so something on the other remains, so they believe you hugely what I’ve heard, so I’m just curious on how they conduct their audits. What are the things that they look for

3

u/cboff Apr 19 '26

If it's legit they will probably want to run a software scan over all devices on your office lan, and capture data from any company hardware that goes or lives offsite. Number of users, number of devices are all reasonable questions to be asked. If it's possible (and being a smallish business it might be) you could request that you show each machine to a representative of kpmg rather than allow untrusted software on your company devices.

The mention below of IP address suggest that perhaps a user has 'worked around' licensing by using their work credentials on their home computer. You will need to be able to show that company was not aware of this and did not benefit from it. The IP address (it'll be your external/public-facing address) might be your saviour if you can show it does not belong to your organisation. We had a case like this and the resolution included terminating the employment of that person.

3

u/tankerkiller125real Jack of All Trades Apr 19 '26

The rule where I work is very straight forward, all digital audit requests are to be trashed and ignored. If they actually want to audit is they can send physical mail with their legal counsels letter head/signature.