Skip to main content
  1. Home
  2. Photography
  3. Computing
  4. News

Adobe left millions of Creative Cloud user records exposed online

Add as a preferred source on Google

Adobe Creative Cloud subscribers are being warned to keep a look out for phishing emails after it was discovered that data belonging to more than seven million accounts remained exposed online for about a week.

Adobe Creative Cloud is a suite of applications that subscribers pay a monthly fee to use. It includes Photoshop, Lightroom, Premiere Rush, Premier Pro, and Illustrator, among other software.

Recommended Videos

U.K.-based tech firm Comparitech and security researcher Bob Diachenko discovered the exposed data, which they said could be viewed without a password or any other kind of authentication.

The researchers alerted Adobe on October 19, prompting the software company to secure the database on the same day.

Exposed data

The exposed data involved 7.5 million accounts and included email addresses, member IDs, country locations, account creation dates, Adobe products used, time since last login, payment status, and whether the user is an Adobe employee, among other details.

Payment information and passwords were not exposed.

Comparitech said that while the data isn’t “particularly sensitive,” it could nevertheless be used to launch phishing campaigns against subscribers.

“Fraudsters could pose as Adobe or a related company and trick users into giving up further info, such as passwords,” Comparitech said in a post about the incident.

There’s so far no evidence that the data was accessed by third parties during the time it was exposed online.

California-based Adobe acknowledged the incident in a message on its website.

“At Adobe, we believe transparency with our customers is important. As such, we wanted to share a security update,” the company said.

“Late last week, Adobe became aware of a vulnerability related to work on one of our prototype environments. We promptly shut down the misconfigured environment, addressing the vulnerability.”

It continued: “The environment contained Creative Cloud customer information, including e-mail addresses, but did not include any passwords or financial information. This issue was not connected to, nor did it affect, the operation of any Adobe core products or services. We are reviewing our development processes to help prevent a similar issue occurring in the future.”

It’s not the first time Adobe has run into trouble with how it handles user data. In 2013, the company suffered a far more serious incident when hackers stole information belonging to around 38 million users. In that case, the hackers managed to get their hands on encrypted customer data that included payment card details, names, usernames, and email addresses.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Fujifilm Instax Mini 13 review: This instant camera won me over with its no-frills retro charm
From printing instant memories to rediscovering the fading charm of polaroids, Fujifilm's camera offers a budget route to a simple indulgence.
Fujifilm Instax mini 13 camera.

See at Amazon

Quick review

Read more
Want to try film photography? Kodak’s new $35 camera is a great place to start
This retro inspired Kodak EC35 camera keeps film photography refreshingly simple.
Kodak-EC35

If you've been curious about film photography but didn't want to spend a fortune, Kodak has a new camera worth checking out. The new Kodak EC35 is a reusable 35mm point-and-shoot camera that costs just $34.99, making it one of the most affordable ways to try shooting on film.

Developed by Reto Project under the Kodak brand, the EC35 keeps things simple with a lightweight design, automatic flash, and a pocket-friendly body. It also arrives as interest in analog photography continues to grow, offering beginners an inexpensive alternative to disposable film cameras.

Read more
The FCC’s latest crackdown could put more than DJI drones at risk in the US
Robot, Person, Face

DJI may have found creative ways to keep some of its products flowing into the US, but those efforts are now drawing increased attention from regulators. According to The Verge, the US Federal Communications Commission (FCC) has started cracking down on several companies it believes could be helping DJI continue selling products in the country. These businesses have been described by industry observers as "DJI front companies" because they market or import products that appear to be closely tied to the Chinese drone maker while operating under different brand names.

DJI's alleged back door may be closing

Read more