Adobe Inc.
Incident posture
Linked entities
- Victim
- Adobe Inc.
- Threat actors
- 8 actors
- Sources
- 1 source
Timeline
Summary
Adobe was allegedly breached through an Indian BPO support contractor after a phishing email delivered a remote access tool, allowing the attacker to pivot to a manager’s account and access the helpdesk environment. From there, a single helpdesk agent could export all tickets, resulting in the claimed exposure of 13 million customer support tickets, 15,000 employee records, and the complete set of HackerOne bug bounty submissions. The compromised data included customer names, email addresses, account IDs, internal technical notes, and unpublished vulnerability reports, while the company has not publicly confirmed or denied the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In April 2026, a threat actor known as 'Mr. Raccoon' allegedly breached Adobe's systems through an Indian Business Process Outsourcing (BPO) firm that was contracted for support operations. The attacker initiated the compromise by delivering a Remote Access Tool via a phishing email to an employee of the BPO contractor. After gaining initial access, the actor pivoted to a manager’s account within the BPO environment. From there, the actor moved into Adobe’s helpdesk environment where a single support agent possessed the ability to export all tickets in a single request.
The alleged breach resulted in the exposure of approximately thirteen million customer support tickets, fifteen thousand employee records, and the complete set of HackerOne bug bounty submissions associated with Adobe. The data that was reportedly accessed included customer names, email addresses, account identifiers, internal technical notes, and unpublished vulnerability reports. No encryption or other protective measures were described as having prevented the actor from extracting this information in one query. The scale of the disclosed data made the incident one of the larger supply‑chain compromises reported for that month.
Adobe has not issued a public statement confirming or denying the alleged breach, and the details presented come from a report by International Cyber Security News. The report cites the actor’s use of phishing and privilege escalation as the breach cause, attributing the entry point to the third‑party BPO contractor. As of the date of the report, no further information regarding detection, containment, or remediation actions by Adobe has been made publicly available.
Sources
Sources available to members: 1 source.