Adobe today announced that hackers have managed to obtain information on approximately 2.9 million of its customers that have downloaded its software, including customer IDs, encrypted passwords, customer names, encrypted credit/debit card numbers, expiration dates, and other information on customer orders.

adobe_creative_cloud_feature
Adobe does not believe that the attackers were able to obtain decrypted credit or debit card numbers from its system, and is currently working with external partners and law enforcement to address the issue.

As a precautionary measure, Adobe is contacting users with affected accounts, initiating password resets. The company is also offering customers that had their credit or debit card information accessed the option of enrolling in a one-year complimentary credit monitoring service.

As a precaution, we are resetting relevant customer passwords to help prevent unauthorized access to Adobe ID accounts. If your user ID and password were involved, you will receive an email notification from us with information on how to change your password. We also recommend that you change your passwords on any website where you may have used the same user ID and password.

We are in the process of notifying customers whose credit or debit card information we believe to be involved in the incident. If your information was involved, you will receive a notification letter from us with additional information on steps you can take to help protect yourself against potential misuse of personal information about you. Adobe is also offering customers, whose credit or debit card information was involved, the option of enrolling in a one-year complimentary credit monitoring membership where available.

We have notified the banks processing customer payments for Adobe, so that they can work with the payment card companies and card-issuing banks to help protect customers’ accounts.

We have contacted federal law enforcement and are assisting in their investigation.

In addition to customer accounts, the hackers also accessed the source code of a number of Adobe products, but Adobe says that it is unaware of any increased risk to customers as a result of that particular attack.

Top Rated Comments

nagromme Avatar
144 months ago
Hmmm.... I wonder if there's a business model where we can get paid again and again forever whether we fix bugs or not, and EVEN if our updates are not very useful ones. One where we're under NO pressure to make our software great, because it won't affect our income. One where we can be paid for apps we let stagnate, alongside the ones we still work on. One where our customers' own creative work is held to monthly ransom, ready for us to lock them out at any time. One where we load their machines with layers of buggy crapware and updaters. And one where we keep ALL our users' credit card numbers on file forever!

�� I think I have an idea!
Score: 21 Votes (Like | Disagree)
thejadedmonkey Avatar
144 months ago
Maybe the hackers can release a version of Adobe Acrobat that isn't full of security holes :rolleyes:
Score: 17 Votes (Like | Disagree)
brianbobcat Avatar
144 months ago
Yet another good reason I'm not on the cloud. Adobe: "Hey, hackers may have gotten your credit card, and we're not gonna give you any free months of CC. Keep an eye on your own credit card." Greedy bastards!
Score: 13 Votes (Like | Disagree)
mrxak Avatar
144 months ago
Silly question but. If hackers got Adobe ID's and passwords whats to keep them from changing the password ?
They got encrypted passwords, which are useless without decryption.
Specifically, the passwords are stored in a hash. What happens is you select your password and Adobe takes that password, does some math to it, then stores the resulting hash in their database somewhere, rather than storing your actual password. Then, when you enter your password to log in, it does the same math on it, and compares the result to the hash they have stored in the database. If the two hashes are the same, it knows you entered your password and it lets you in. If somebody gets the hash straight off their database, as would seem to be the case here, that doesn't help an attacker know what password to type in when they want to log in with your account, unless they can reverse engineer the hash algorithm. So, it really depends on what kind of hash algorithm they used for their database, as to how secure your password actually is.

Generally, it's a good idea to have everyone change their password anyway, just in case the algorithm eventually proves to be vulnerable to attack, or an attacker is properly motivated and willing to spend enough time to crack your password. Some hashes still in use today are considered vulnerable, though, so attackers may very well already be crunching through the hashes and getting plaintext passwords. One can hope Adobe is using a more secure hash, but plenty of big companies have used insecure algorithms in the past.

Hashes are designed not to be reversible, unlike regular encryption designed for actual decrypting at some point, but if the algorithm is known it's possible to simply use it to hash a bunch of password guesses, and then compare those guesses to the hashed passwords. Just search through the database for hashes you've made yourself, and you know the password for each of the accounts with the same password hash. It's essentially a dictionary attack, but it bypasses whatever system Adobe uses to prevent unlimited repeated invalid password entries (like locking your account after a certain number of attempts, or adding delays to the algorithm/webpage so it would take a prohibitively long time to try every possible password).

One method of preventing lookup table attacks like the above is to add a "salt" to the password before it's hashed so the result in the database isn't something the attacker can generate for a table without knowing the salt. Any old salt won't do, though. It needs to be a cryptographically-secure pseudo-random number, unique to each account, never reused when a user changes their password, and long enough that an attacker can't simply make as many tables as there are possible salts. Bear in the mind, the salt still has to be stored alongside the hash in order to authenticate a user, so an attacker knows the salt to use. But, by using a nice long pseudorandom salt for every individual password, each individual password needs a separate lookup table to brute force. Dictionary attacks are still possible if the hash algorithm and salt method is known, but take incredibly long amounts of time to crack the whole database and incredibly large amounts of storage. Against a single specific user, their password may be discovered, but only that one user, and only if they used a guessable password, and each single specific user will require a separate attack. In other words, they're still doing an ordinary dictionary attack, and the usual rules about making your passwords resistant to dictionary attacks apply. Properly salted passwords hashed with a modern secure algorithm are simply not feasible to extract from a database like this, en masse, but it's still a good idea for everyone to change their passwords. It's also a good idea to change any other passwords you have if you've made the common error of reusing passwords on multiple sites.
Score: 12 Votes (Like | Disagree)
dumastudetto Avatar
144 months ago
Maybe the hackers can release a version of Adobe Acrobat that isn't full of security holes :rolleyes:

Hackers are good but they aren't miracle workers.
Score: 8 Votes (Like | Disagree)
kylepro88 Avatar
144 months ago
Here come the "This is why subscription service sucks" posts...

Either way, bummer. :/
Score: 8 Votes (Like | Disagree)

Popular Stories

ipad mini 2021 youtube

New Report Reveals When to Expect the iPad Mini 7

Tuesday October 1, 2024 2:09 pm PDT by
Apple is working on a new iPad mini that will "potentially" be released "by the end of 2024," according to a report today from Bloomberg's Mark Gurman. Last month, Gurman reported that Apple had "new iPads in the works," including an upgraded version of the iPad mini. At the time, he said the device was "on deck for Apple's October event" alongside the first M4 Macs. The wording in his...
Generic iOS 18

Apple Releases iOS 18.0.1 With Touch Screen Bug Fix and More

Thursday October 3, 2024 2:22 pm PDT by
Apple today released iOS 18.0.1 and iPadOS 18.0.1, the first updates to the iOS 18 and iPadOS 18 operating systems that debuted earlier in September. iOS 18.0.1 and iPadOS 18.0.1 come two weeks after the launch of iOS 18. The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. According to Apple's release notes, the...
apple silicon mac lineup wwdc 2022 feature purple

MacBook Pro, iMac, and Redesigned Mac Mini With M4 Chips on Track to Launch 'This Year'

Tuesday October 1, 2024 1:57 pm PDT by
Apple plans to release new MacBook Pro, iMac, and Mac mini models with the M4 series of chips "this year," according to Bloomberg's Mark Gurman. Gurman initially said these Macs would likely be announced during a virtual event this October, but he has been more vague about the timing lately, with wording such as "in the coming weeks" and now merely "this year." In any case, it is clear that...
15 New Things Your iPhone Can Do in iOS 18

15 New Things Your iPhone Can Do in iOS 18.1

Friday September 27, 2024 6:14 am PDT by
Apple is set to release iOS 18.1 in October, bringing the first set of Apple Intelligence features to iPhone 15 Pro and iPhone 16 models. This update marks a significant step forward in Apple's AI integration, offering a new Siri contextually-aware experience and a range of additional capabilities powered by on-device machine learning and large language models. There are a couple of handy new...
macOS Sequoia Night Feature

Apple Releases macOS Sequoia 15.0.1 With Bug Fixes

Thursday October 3, 2024 2:27 pm PDT by
Apple today released macOS Sequoia 15.0.1, the first update for the macOS Sequoia operating system. The 15.0.1 update comes a week after Apple first released macOS Sequoia 15. Mac users can download the ‌macOS Sequoia‌ update by using the Software Update section of System Settings. According to Apple's release notes, macOS Sequoia 15.0.1 fixes a bug that could cause the Messages app...
airpods pro 2 gradient

AirPods Pro 3 Expected Next Year: Here's What We Know

Tuesday October 1, 2024 5:47 am PDT by
Despite being released over two years ago, Apple's AirPods Pro 2 continue to dominate the wireless earbud market. However, with the AirPods Pro 3 expected to launch sometime in 2025, anyone thinking of buying Apple's premium earbuds may be wondering if the next generation is worth holding out for. Apart from their audio and noise-canceling performance, which are generally regarded as...
Generic iOS 18

iOS 18.0.1 Coming Soon: What to Expect for Your iPhone

Wednesday October 2, 2024 5:50 am PDT by
Following the release of iOS 18 for the iPhone last month, Apple is preparing to release iOS 18.0.1 with bug fixes in the near future. We previously reported that Apple has been internally testing iOS 18.0.1, and today a private account on X with a proven track record of sharing iOS-related information said the update will have a build number of 22A3370. We expect iOS 18.0.1 to be a minor ...
Apple Logo

Apple in October: Six New Things to Expect This Month

Tuesday October 1, 2024 11:47 am PDT by
The calendar has turned to October, and it should be another busy month for Apple. Apple is likely to hold another event this month to announce new Macs and iPads, and there are also a couple of iOS 18 updates that are expected to be released soon. Below, we outline six new things to expect from Apple this month. MacBook Pro Apple plans to announce updated 14-inch and 16-inch...
macOS Sequoia Feature

Here Are All the New Features Coming to macOS Sequoia This Month

Thursday October 3, 2024 6:27 am PDT by
‌Apple in October will release macOS Sequoia‌ 15.1, bringing to Macs the first Apple Intelligence features such as Writing Tools, new Siri features, Smart Replies, and more. In addition, macOS 15.1 adds a handful of welcome tweaks and improvements to existing Mac capabilities. Here's what we can expect from the first major update to macOS Sequoia later this month. Note that Apple...