CSIDB logo
Incident

Adobe Inc.

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 23:56

Linked entities

Victim
Adobe Inc.
Threat actors
8 actors
Sources
1 source

Timeline

Occurred
Apr 2026
Discovered
Undetermined
Disclosed
May 2026
Resolved
Pending

Summary

Adobe was allegedly breached through an Indian BPO support contractor after a phishing email delivered a remote access tool, allowing the attacker to pivot to a manager’s account and access the helpdesk environment. From there, a single helpdesk agent could export all tickets, resulting in the claimed exposure of 13 million customer support tickets, 15,000 employee records, and the complete set of HackerOne bug bounty submissions. The compromised data included customer names, email addresses, account IDs, internal technical notes, and unpublished vulnerability reports, while the company has not publicly confirmed or denied the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In April 2026, a threat actor known as 'Mr. Raccoon' allegedly breached Adobe's systems through an Indian Business Process Outsourcing (BPO) firm that was contracted for support operations. The attacker initiated the compromise by delivering a Remote Access Tool via a phishing email to an employee of the BPO contractor. After gaining initial access, the actor pivoted to a manager’s account within the BPO environment. From there, the actor moved into Adobe’s helpdesk environment where a single support agent possessed the ability to export all tickets in a single request.

The alleged breach resulted in the exposure of approximately thirteen million customer support tickets, fifteen thousand employee records, and the complete set of HackerOne bug bounty submissions associated with Adobe. The data that was reportedly accessed included customer names, email addresses, account identifiers, internal technical notes, and unpublished vulnerability reports. No encryption or other protective measures were described as having prevented the actor from extracting this information in one query. The scale of the disclosed data made the incident one of the larger supply‑chain compromises reported for that month.

Adobe has not issued a public statement confirming or denying the alleged breach, and the details presented come from a report by International Cyber Security News. The report cites the actor’s use of phishing and privilege escalation as the breach cause, attributing the entry point to the third‑party BPO contractor. As of the date of the report, no further information regarding detection, containment, or remediation actions by Adobe has been made publicly available.

Sources

Sources available to members: 1 source.

CSIDB