"Transaction Receipt" PDF email quietly installs Action1 remote access on your PC
A blurred "Transaction Receipt" PDF fetches a fake Adobe update that installs Action1, giving the sender remote control of your PC.
- Is it a scam?
- Yes, it's a scam. There's no real payment behind it, and opening the PDF can install a remote-management program that lets the sender run things on your computer.
- Type
- Email scam
- First reported
- October 6, 2026
- Status
- Still active
- Who it targets
- Anyone with an email address, including small businesses. The report doesn't name a country.
- Tools it uses
- Action1
If an email sent you a PDF called "Transaction Receipt" and it wanted an update before you could read it, it's a scam. There's no real payment. The file is built to install Action1, a remote-management program, so the sender can run things on your computer. Don't open it, and don't install any "Adobe update" it offers.
Xavier Mertens of the SANS Internet Storm Center described this on October 6, 2026. So far it has been reported by security researchers and a security blog, not by a government agency or by Action1.
What does the Transaction Receipt email look like?
It arrives as a fake invoice or payment receipt with a PDF attached. In the copy SANS examined, the attachment was named "Transaction Receipt .pdf" (with a space before .pdf). The receipt inside looks blurred, so it seems you need to do something before you can read it.
SANS also found a second version made to look like a DHL document. It leads to the same program.
What happens when you open it?
The PDF tries to open a web link as soon as it's opened. That link fetches a small script called adobe_new_update.vbs, named to look like an Adobe update. If it runs, it shows you a clear copy of the receipt so nothing looks wrong, and at the same time it downloads and installs a file called action1.msi in the background.
Action1 is a real product that IT teams use to manage and update computers from a distance. Here it's set up to report to the scammer's own account instead. Because the files are genuine, signed software, SANS found antivirus didn't flag them.
I got the email but didn't open it. What should I do?
Delete it. If you're worried about a real charge, check your bank or card account by typing the bank's web address yourself, or call the number on the back of your card. You can report the email at ReportFraud.ftc.gov.
I opened the PDF or ran the update. What now?
Take it one step at a time:
- Disconnect the computer from the internet (unplug the cable or turn off Wi-Fi). This cuts off the remote connection.
- Call your bank from another phone, using the number on the back of your card. Tell them someone may have had access to your computer.
- Change your email password from a different device, then your banking passwords.
- Check for the program. On Windows 11, go to Settings, then Apps, then Installed apps (on Windows 10 it's "Apps & features"), and look for anything named Action1. If it's there and you didn't install it, uninstall it.
- If you can't find or remove it, or you're not sure, ask a trusted local repair shop to look before you go back online for banking.
Follow our two-minute checklist for each step, and see what to do after a remote access scam for what to watch in the days after. Our guide on how to tell if someone is controlling your PC can help you check. If you lost money, report it at ic3.gov too.
How to spot it next time
- A receipt for something you didn't buy is a common opening move. Check your accounts yourself instead of opening the attachment.
- A PDF that asks you to install an update, a plugin or a "viewer" before you can read it is a trap. Real PDFs open without one.
- A file ending in .vbs, .hta or .msi is a program, not a document.
- If a surprise email is from a delivery company like DHL, track the parcel on the company's own website.
This scam doesn't need a phone call, so the main defense is not opening the file. Xcelcor Guardian is a Windows app that helps with the more common version, where a caller asks you to install AnyDesk, TeamViewer, ScreenConnect or Quick Assist. It holds each new remote connection until the account holder approves it by email or on xcelcor.com. It isn't antivirus and won't remove a program that's already installed.
Phone numbers, messages and files linked to this scam
Web addresses are written with [.] so they can’t be clicked by mistake. If something you received matches, it’s this scam.
Links
hxxps://up-theta-rose[.]vercel[.]app/adobe_new_update[.]vbshxxps://up-theta-rose[.]vercel[.]app/action1[.]msihxxps://update-two-tau[.]vercel[.]app/adobe-neLink in a second, DHL-themed PDF. Shown as printed in the SANS report.
Files
Transaction Receipt .pdfThe email attachment, with a space before .pdf, as shown by SANSadobe_new_update.vbsScript the PDF fetches, named to look like an Adobe updateaction1.msiInstaller the script downloads in the backgroundC:\Windows\Action1\action1_agent.exeWhere the program sits once installed
Other signs
Action1 AgentName of the Windows service it installs (service name A1Agent)
Questions people ask
Is the Transaction Receipt PDF real?
No. Researchers found it's a trap. Opening it fetches a script dressed up as an Adobe update, and that script installs a remote-management program called Action1.
What is Action1 and why is it on my computer?
Action1 is a real program IT teams use to manage computers from a distance. If you never set it up and you opened a surprise receipt or DHL PDF, treat it as a sign someone else may be able to control your PC.
I opened the PDF. What now?
Disconnect the computer from the internet, call your bank from another phone, and change your email password from another device. Then follow our checklist.
Sources
Last updated