Breach report
Consumer TechAdobe
Adobe Breach Impacted At Least 38 Million Users
Attackers who breached Adobe in 2013 took encrypted credentials for 38 million active users, a larger file of roughly 153 million account records, and source code for flagship products including Photoshop and Acrobat.
Reported by Krebs on Security
Records exposed
153M
38 million active users; roughly 153 million account records leaked
Scale vs. largest on file
- When
- 2013
- How they got in
- Network intrusion and exfiltration of customer database and source code
- Sector
- Consumer Tech
Adobe discovered in mid-September 2013 that attackers had broken into its network, and on October 3 it disclosed that information on about 2.9 million customers, including names and encrypted payment card numbers, had been accessed. Within weeks the picture grew much worse. Security journalist Brian Krebs reported that a file of roughly 150 million usernames and encrypted passwords had surfaced online, and Adobe acknowledged that credentials for at least 38 million active users had been taken. The attackers had also stolen source code for Acrobat, Reader, ColdFusion and Photoshop.
The leaked database, about 3.8 gigabytes, eventually proved to contain around 153 million records. Security researchers quickly found serious weaknesses in how Adobe had protected passwords. Rather than salted hashes, the company had used a single block cipher in a mode that produced identical output for identical passwords, and it stored users' password hints in plain text alongside them. That combination let analysts infer huge numbers of passwords simply by grouping matching entries and reading the hints, and lists of the most common Adobe passwords circulated widely.
Adobe reset passwords for affected accounts, notified customers by email, and offered a year of free credit monitoring to people whose card data was involved. The theft of source code raised separate concerns: security experts warned that criminals could study the code to find new vulnerabilities in software installed on hundreds of millions of computers.
Legal consequences followed. Adobe settled a consumer class action in 2015, agreeing to improve its security practices and cover plaintiffs' legal fees, and in 2016 it paid $1 million to resolve an investigation by 15 US state attorneys general. The company also shifted its customers toward its cloud subscription model in the following years, which changed how accounts and licenses were managed.
The Adobe breach became a textbook example of poor password storage. It showed that encryption is not the same as proper hashing, and that auxiliary data such as password hints can undo whatever protection exists. Because the leaked email and password pairs were reused on other sites, the data fed credential-stuffing attacks for years. It remains one of the most frequently cited datasets in breach-notification services and a reminder that companies should never be able to recover a user's password.