Don’t do SECURITY. Do business SECURELY.

Adobe breach exposes customer data and product source code

Adobe disclosed a cyber attack exposing customer records and source code; the number of affected accounts later rose to at least 38 million.

Adobe disclosed that attackers had accessed customer information and the source code of several of its products. It first said 2.9 million customers were affected, but later confirmed that encrypted passwords and IDs for about 38 million active users had been taken.

What happened

  • The stolen data included Adobe IDs, encrypted passwords, and, for some customers, encrypted payment card details.
  • Source code for products including Acrobat, Reader, and ColdFusion was also taken.
  • A file containing many more account records later circulated online, and researchers criticised the way passwords had been encrypted rather than properly hashed.
  • Adobe reset affected passwords and offered credit monitoring to some customers.

Why it mattered

The breach was among the largest of its time and showed the risks of weak password storage and of source code theft, which can help attackers find new vulnerabilities in widely used software.

Lessons for organisations

Organisations should store passwords using modern, salted hashing algorithms, and protect source code repositories as critical assets. Prompt, clear customer notification also reduces harm when a breach occurs. Because leaked password databases are reused in credential-stuffing attacks, organisations should also encourage unique passwords and multi-factor authentication.

Source: Krebs on Security

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights