Security Advisor

Adobe Hack Results in Stolen Source Code and Customer Data

Adobe alerted customers on Thursday that a breach by hackers has resulted in the loss of 2.9 million customers' personal data -- including user names, encrypted credit card information and passwords.

"Very recently, Adobe's security team discovered sophisticated attacks on our network, involving the illegal access of customer information as well as source code for numerous Adobe products," wrote Adobe's Chief Security Officer Brad Arkin in an Adobe blog post. "We believe these attacks may be related."

Along with personal customer information, those responsible also accessed Adobe software source code. However, Arkin said he believes this won't lead to any additional security threats.

Earlier in the day, security expert Brian Krebs discussed in his Krebs on Security blog that he and a team with Hold Security had discovered the Adobe  source code leak sometime last week and said more than 40 GB of stolen data  related to Adobe Acrobat and ColdFusion were found on a server connected to a criminal ring specializing in identity theft services.

"In an interview with this publication earlier today, Adobe confirmed that the company believes that hackers accessed a source code repository sometime in mid-August 2013, after breaking into a portion of Adobe's network that handled credit card transactions for customers," wrote Krebs. "Adobe believes the attackers stole credit card and other data on approximately 2.9 million customers, and that the bad guys also accessed an as-yet-undetermined number of user names and passwords that customers use to access various parts of the Adobe customer network."

In response to the attack, Adobe has resetted  the passwords of those customers affected and are urging Adobe users to immediately change any shared passwords used for both Adobe and other Web sites.

As for the stolen financial information, Arkin said the company is currently contacting customers who are affected and are offering a year of a free credit monitoring services and have alerted customer-used financial institutions of the situation.


  • Microsoft Starting To Roll Out New Excel Connected Data Types

    Microsoft on Thursday announced some Excel and Power BI enhancements that add "connected data types" on top of the standard strings and numbers options.

  • Windows 10 Users Getting New Process for Finding Optional Driver Updates

    Accessing Windows 10 drivers classified as "optional updates" will be more of a manual seek-and-install type of experience, starting on Nov. 5, 2020, Microsoft explained in a Wednesday announcement.

  • Microsoft Changes Privacy Platform Name to SmartNoise

    Microsoft Research has changed the name of its "differential privacy" platform from "WhiteNoise" to "SmartNoise," according to a Wednesday announcement.

  • Why Restarting a Failed SCVMM Job Might Be a Bad Idea

    Occasionally, restarting a failed System Center Virtual Machine Manager job can leave your virtualization infrastructure in an unknown state. Here's how to avoid that.

comments powered by Disqus