Skip to main content

Adobe suffers major security breach, 2.9 million customers affected

adobe suffers major security breach
Image used with permission by copyright holder

US software giant Adobe said Thursday it had suffered a security breach affecting almost three millions accounts.

“Our investigation currently indicates that the attackers accessed Adobe customer IDs and encrypted passwords on our systems,” Adobe chief security officer Brad Arkin said on the company’s website.

“We also believe the attackers removed from our systems certain information relating to 2.9 million Adobe customers, including customer names, encrypted credit or debit card numbers, expiration dates, and other information relating to customer orders.”

Arkin added that at the present time it doesn’t believe the hackers took any decrypted credit or debit card numbers from its systems.

The company is in the process of resetting passwords of those accounts it believes are affected by the security breach and is sending out email notifications explaining how these customers can then change their password to one of their choosing.

“We also recommend that you change your passwords on any website where you may have used the same user ID and password,” Arkin said.

He added that it was also contacting customers whose credit or debit card information may have been stolen in the incident with advice on steps to take to protect against possible misuse of the data.

“Adobe is also offering customers, whose credit or debit card information was involved, the option of enrolling in a one-year complimentary credit monitoring membership where available,” he said.

In another measure to protect customer accounts, the chief security officer explained that it was contacting banks processing customer payments for Adobe to warn them of the situation.

Arkin said that such data breaches “are one of the unfortunate realities of doing business today” and said the company “deeply regretted” that the incident had occurred.

In another headache for Adobe, Arkin said his team was also looking into the illegal access of source code for a number of its products, including Adobe Acrobat, ColdFusion, ColdFusion Builder.

“We are not aware of any zero-day exploits targeting any Adobe products,” Arkin said. “However, as always, we recommend customers run only supported versions of the software, apply all available security updates, and follow the advice in the Acrobat Enterprise Toolkit and the ColdFusion Lockdown Guide. These steps are intended to help mitigate attacks targeting older, unpatched, or improperly configured deployments of Adobe products.”

Although Adobe says it will be contacting customers it believes have been affected by the attack, for peace of mind Adobe customers may want to change their password anyway. You can do so by clicking here.

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Microsoft reveals a security breach of an internal customer support database
Microsoft Surface Go Hands-on

Microsoft announced today that an internal customer support database experienced a security breach in December 2019.

The technology company’s announcement came via a blog post published on Wednesday, January 22 on the Microsoft Security Response Center blog. According to the post, the breach occurred on December 5, 2019 and involved the “misconfiguration of an internal customer support database used for Microsoft support case analytics.” Essentially, the breach occurred when a change was made to the database’s network security group. This change carried with it “misconfigured security rules” which then caused the exposure of customer data. And according to ZDNet, the servers affected by the breach “contained roughly 250 million entries, with information such as email addresses, IP addresses, and support case details.”

Read more
Macy’s confirms hackers stole customer data from its website
macys confirms hackers stole customer data from its website macy s store in midtown manhattan

Macy’s says it’s been hit by a “highly sophisticated and targeted data security incident” that affected “a small number” of its customers.

The data breach, which stole information from customers as they shopped on Macy’s online shopping site, took place between October 7 and 15, 2019. Those affected have been notified and will be updated on developments, Macy’s told Digital Trends by email.

Read more
Adobe left millions of Creative Cloud user records exposed online
A hacker inputting code into a system.

Adobe Creative Cloud subscribers are being warned to keep a look out for phishing emails after it was discovered that data belonging to more than seven million accounts remained exposed online for about a week.

Adobe Creative Cloud is a suite of applications that subscribers pay a monthly fee to use. It includes Photoshop, Lightroom, Premiere Rush, Premier Pro, and Illustrator, among other software.

Read more