Skip to main content

Adobe suffers major security breach, 2.9 million customers affected

adobe suffers major security breach
Image used with permission by copyright holder

US software giant Adobe said Thursday it had suffered a security breach affecting almost three millions accounts.

“Our investigation currently indicates that the attackers accessed Adobe customer IDs and encrypted passwords on our systems,” Adobe chief security officer Brad Arkin said on the company’s website.

Recommended Videos

“We also believe the attackers removed from our systems certain information relating to 2.9 million Adobe customers, including customer names, encrypted credit or debit card numbers, expiration dates, and other information relating to customer orders.”

Arkin added that at the present time it doesn’t believe the hackers took any decrypted credit or debit card numbers from its systems.

The company is in the process of resetting passwords of those accounts it believes are affected by the security breach and is sending out email notifications explaining how these customers can then change their password to one of their choosing.

“We also recommend that you change your passwords on any website where you may have used the same user ID and password,” Arkin said.

He added that it was also contacting customers whose credit or debit card information may have been stolen in the incident with advice on steps to take to protect against possible misuse of the data.

“Adobe is also offering customers, whose credit or debit card information was involved, the option of enrolling in a one-year complimentary credit monitoring membership where available,” he said.

In another measure to protect customer accounts, the chief security officer explained that it was contacting banks processing customer payments for Adobe to warn them of the situation.

Arkin said that such data breaches “are one of the unfortunate realities of doing business today” and said the company “deeply regretted” that the incident had occurred.

In another headache for Adobe, Arkin said his team was also looking into the illegal access of source code for a number of its products, including Adobe Acrobat, ColdFusion, ColdFusion Builder.

“We are not aware of any zero-day exploits targeting any Adobe products,” Arkin said. “However, as always, we recommend customers run only supported versions of the software, apply all available security updates, and follow the advice in the Acrobat Enterprise Toolkit and the ColdFusion Lockdown Guide. These steps are intended to help mitigate attacks targeting older, unpatched, or improperly configured deployments of Adobe products.”

Although Adobe says it will be contacting customers it believes have been affected by the attack, for peace of mind Adobe customers may want to change their password anyway. You can do so by clicking here.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Hackers are trying to sell a haul of more than 73 million user records
Hands on a laptop.

More than 73 million user records stolen from across a number of online services are being offered for sale on the dark web by hacker group ShinyHunters, according to ZDNet.

Affected services include online dating app Zoosk (30 million user records), printing service Chatbooks (15 million), food delivery service Home Chef (8 million), online marketplace Minted (5 million), and U.S. news site Star Tribune (1 million).

Read more
Microsoft reveals a security breach of an internal customer support database
Microsoft Surface Go Hands-on

Microsoft announced today that an internal customer support database experienced a security breach in December 2019.

The technology company’s announcement came via a blog post published on Wednesday, January 22 on the Microsoft Security Response Center blog. According to the post, the breach occurred on December 5, 2019 and involved the “misconfiguration of an internal customer support database used for Microsoft support case analytics.” Essentially, the breach occurred when a change was made to the database’s network security group. This change carried with it “misconfigured security rules” which then caused the exposure of customer data. And according to ZDNet, the servers affected by the breach “contained roughly 250 million entries, with information such as email addresses, IP addresses, and support case details.”

Read more
Here’s why some PC gamers shouldn’t install the latest Windows 11 update
Overwatch 2 running on the LG OLED 27 gaming monitor.

The latest Windows 11 update, codenamed 24H2, has been a troubled rollout for Microsoft, but one thing's been clear from the beginning: PC gamers should wait to install it. Let's add another issue to the list, shall we?

As spotted by Windows Latest, Microsoft has confirmed in an update to its Windows 11 24H2 problems page, that Windows 11 24H2 is causing issues with its Auto HDR feature. The result of the bug is that incorrect colors are being displayed or, even worse, are breaking games entirely and causing them to not be responsive.

Read more