Adobe Hack Results in Stolen Source Code and Customer Data
Adobe alerted customers on Thursday that a breach by hackers has resulted in the loss of 2.9 million customers' personal data -- including user names, encrypted credit card information and passwords.
"Very recently, Adobe's security team discovered sophisticated attacks on our network, involving the illegal access of customer information as well as source code for numerous Adobe products," wrote Adobe's Chief Security Officer Brad Arkin in an Adobe blog post. "We believe these attacks may be related."
Along with personal customer information, those responsible also accessed Adobe software source code. However, Arkin said he believes this won't lead to any additional security threats.
Earlier in the day, security expert Brian Krebs discussed in his Krebs on Security blog that he and a team with Hold Security had discovered the Adobe source code leak sometime last week and said more than 40 GB of stolen data related to Adobe Acrobat and ColdFusion were found on a server connected to a criminal ring specializing in identity theft services.
"In an interview with this publication earlier today, Adobe confirmed that the company believes that hackers accessed a source code repository sometime in mid-August 2013, after breaking into a portion of Adobe's network that handled credit card transactions for customers," wrote Krebs. "Adobe believes the attackers stole credit card and other data on approximately 2.9 million customers, and that the bad guys also accessed an as-yet-undetermined number of user names and passwords that customers use to access various parts of the Adobe customer network."
In response to the attack, Adobe has resetted the passwords of those customers affected and are urging Adobe users to immediately change any shared passwords used for both Adobe and other Web sites.
As for the stolen financial information, Arkin said the company is currently contacting customers who are affected and are offering a year of a free credit monitoring services and have alerted customer-used financial institutions of the situation.