Cyber Threat Actor: Mr. Raccoon
| Actor Type | Location | Known Incidents |
Undetermined
|
—
|
1 incident |
|---|
Profile
Mr. Raccoon is the alias used to refer to the threat actor responsible for the April 2026 compromise of Adobe’s support infrastructure. The actor gained public attention after security researchers linked the breach to a phishing campaign that targeted an Indian business‑process outsourcing contractor working with Adobe. No other aliases or affiliations have been publicly attributed to Mr. Raccoon in the available reporting.
The intrusion began with a phishing email that delivered a remote‑access tool to a contractor employee, establishing an initial foothold within the contractor’s network. From there the actor escalated privileges, allowing movement to a manager’s account that had access to Adobe’s helpdesk environment. Using that elevated access, the actor pivoted to the helpdesk system where a single support agent could export all tickets in a single request. The attack chain is described as a supply‑chain compromise that relied on phishing followed by privilege escalation rather than exploiting a software vulnerability.
As a result of the unauthorized access, approximately thirteen million customer support tickets, fifteen thousand employee records, and the complete set of HackerOne bug‑ bounty submissions were exposed, including customer names, email addresses, account IDs, internal technical notes, and unpublished vulnerability reports. Adobe has not publicly confirmed or denied the breach, and the details of the incident were reported by third‑party security analysts citing a post on a cybersecurity blog. The exposed data encompassed both customer‑facing information and internal development artifacts, illustrating the breadth of information that could be harvested through the described attack vector.
