Data breach
Adobe
- Records
- 152,437,709
- Breach date
- 4 October 2013Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses152,437,709
- Password hints152,429,396
- PasswordsReported, not counted
- Card numbersReported, not counted
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In October 2013, attackers broke into Adobe's network and walked off with one of the largest collections of customer account data ever seen at that time. Our investigation team indexes this breach at 152,437,709 records, each containing an email address and, for nearly all of them, a plaintext password hint. Adobe initially disclosed the attack as a theft of 2.9 million customer records, then revised the figure to about 38 million active accounts, before independent researchers found the full stolen file circulating online. The attackers also took source code for some Adobe products.
Breach Timeline
October 3, 2013: Adobe publicly disclosed that attackers had accessed its network and stolen customer data, initially reporting about 2.9 million affected accounts with encrypted credit or debit card numbers and expiration dates, according to BBC News and The Register.
October 30, 2013: Adobe revised its estimate, saying usernames and encrypted passwords had been stolen for roughly 38 million active users, and confirmed the theft of parts of the Photoshop source code, per BBC News.
November 8, 2013: Reporting by the Sydney Morning Herald described LastPass researchers finding a stolen file online containing data from about 152 million Adobe accounts, including email addresses, encrypted passwords, and password hints stored in clear text. Adobe confirmed the records came from its systems but said many were inactive or invalid.
What Information Was Compromised?
Our analysis found the following data types in this breach: 152,437,709 email addresses and 152,429,396 password hints, stored in plain text.
Reporting from The Register indicates the stolen file also contained encrypted passwords, Adobe customer IDs, and usernames. In the smaller group of about 2.9 million accounts Adobe first disclosed, BBC News reported that encrypted credit and debit card numbers and card expiration dates were also taken. Adobe later said the passwords had not been salted, a weakness that made them far easier for attackers to crack. Security researchers analyzing the leaked file found "123456" was the most common password, used about 1.9 million times, according to BBC News.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Password hints are the most underappreciated part of this breach. People often write hints like "my dog's name" or "same as my email password," and those clues can help an attacker crack an encrypted password or guess it on another site. Because Adobe's password encryption was weak and unsalted, researchers recovered huge numbers of plaintext passwords from the leaked file.
The practical risks are credential stuffing and password reuse. If you used your Adobe email and password on other services, those accounts are the ones in danger. The email addresses in the file also remain useful for phishing, since criminals can send convincing messages that reference Adobe or your account details. For the smaller group whose encrypted card numbers were taken, there is a risk of card fraud, though Adobe said the numbers were encrypted.
What Is Adobe Doing in Response?
Adobe reset passwords for affected Adobe IDs, shut down compromised accounts, and began notifying users, according to BBC News. The company said it worked with law enforcement and outside investigators to determine the scope of the breach and contacted holders of inactive accounts as its investigation widened. The company also faced a $1 million settlement with 15 states, which alleged Adobe did not take reasonable steps to protect consumer information, according to BankInfoSecurity.
What Should You Do If You Were Affected?
Change your Adobe password if you have not since 2013, and pick a long, unique one.
Change passwords on any other accounts where you reused the same password or a close variation.
Delete or ignore password hints that reveal real personal details; use nonsense phrases instead.
Turn on two-factor authentication wherever it is offered.
Watch for phishing emails that reference Adobe or your account, and never click password reset links in unsolicited email.
If your card details were in the smaller exposed group, review your card statements for unfamiliar charges and consider a replacement card.
In the news
- BBC News: Analysis reveals popular Adobe passwordsbbc.com (opens in a new tab)
- BBC News: Adobe hack: At least 38 million accounts breachedbbc.com (opens in a new tab)
- The Register: Three million Adobe accounts hacked? Sorry, make that 38 MILLIONtheregister.com (opens in a new tab)
- Sydney Morning Herald: Adobe user data found online after hacksmh.com.au (opens in a new tab)
- BankInfoSecurity: Adobe Pays Small Amount to Settle With States Over Breachbankinfosecurity.com (opens in a new tab)
