Data Security

Alleged Adobe helpdesk system breach reported

Adobe released an emergency patch for a critical vulnerability in its Magento 2 e-commerce platform. Pictured: The Adobe logo is displayed on the side of the Adobe Systems headquarters Jan. 15, 2010, in San Jose, Calif. (Photo by Justin Sullivan/Getty Images)

Cybernews reports that Adobe was noted by International Cyber Digest analysts to have had 13 million support tickets with personal information and 15,000 employee records purportedly stolen from its helpdesk system by the threat actor "Mr. Raccoon."

Multiple screenshots provided by Mr. Raccoon, who allegedly obtained access through an India-based business process outsourcing firm, included captured webcam footage of an employee, an Adobe Internal OneDrive, and access to different documents on customer experience. ICD noted that the attacker likely used a remote access trojan through a malicious email. Adobe has not verified the purported attack. While vx-underground researchers said the reported breach seemed legitimate, they suggested that the intrusion may be limited to the helpdesk environment and not the company's entire network. However, Cybernews researchers urged users who have recently used the helpdesk to remain alert.

"Support tickets more often than not contain customer information, including the products they use, and a large number of these tickets could be related to billing/refund issues people encounter. All of this information would be useful for malicious actors to craft more convincing phishing emails," researchers said.

You can skip this ad in 5 seconds