Adobe says warning customers about breach is taking longer than anticipated

Advertisement
By Reuters | Updated: 26 November 2013 11:09 IST
Adobe Systems Inc said it is taking longer than expected to warn customers about a massive data breach that compromised data on tens of millions of people, leaving some in the dark 10 weeks after the attack was discovered.

That puts those who have yet to be alerted at increased risk of cyber-scams and identity theft, because part of the massive trove of data stolen from Adobe is circulating on the Internet.

(Also see: Adobe's breached user data found stashed on underground website by LastPass)

"This is a pretty massive screw-up," said Chester Wisniewski, a senior security advisor at anti-virus software maker Sophos. "Anybody can go and download the list. It's not a secret."

Advertisement

Adobe identified the attack on September 17 and began notifying customers "immediately" after it disclosed the breach on October 3, according to company spokeswoman Heather Edell.

Advertisement

(Also see: Adobe data breach larger than reported, more than 38 million accounts affected)

"Email notifications are taking longer than we anticipated," she said.

Advertisement

The company has had to validate email addresses of those affected, and also limit the number of notifications sent at any one time to make sure they don't get blocked by email providers or tagged as spam, she said.

Edell said the company has notified by email and letter some 2.9 million Adobe customers with credit or debit card information taken by the attackers.

Advertisement

It is in the process of notifying tens of millions of others who have Adobe ID accounts for using its customer website, she said. She declined to provide a specific number on how many had been affected, saying the investigation was still ongoing.

A file containing information on some 152 million Adobe ID accounts has circulated on the Internet for at least three weeks. It includes email addresses along with encrypted passwords and password hints, according to multiple security firms that have reviewed its contents.

Yet Edell said it was not accurate to say 152 million customer accounts had been compromised because the database attacked was a backup system about to be decommissioned.

She said the records included some 25 million records containing invalid email addresses, and 18 million with invalid passwords. "A large percentage" of the accounts were fictitious, having been set up for one-time use so that their creators could get free software or other perks, she added.

Still, security experts at Sophos and other firms successfully identified an unknown number of passwords in that file by analyzing password hints and using other techniques to guess at them.

Other companies, including Facebook Inc, have identified users who employed the same passwords as those contained in the widely circulated file on Adobe customers.

The social network then required affected users to verify their identity and reset their passwords.

"We actively look for situations where the accounts of people who use Facebook could be at risk, even if the threat is external to our service," said Facebook spokesman Jay Nancarrow. "When we find these situations, we present messages to people to help them secure their accounts."

Computer users need to watch out for scammers who are sending out emails that appear to be security-breach notifications from Adobe, but contain malicious links, said Wisniewski of Sophos.

"The bad guys already know you have a relationship with Adobe," he said. "That makes it easier for them to scam you."

© Thomson Reuters 2013

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Adobe, Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy S26+ Reportedly Listed for Sale Online Ahead of Launch
  2. Oppo K14x 5G With 6,500mAh Battery Goes on Sale in India: See Price, Offers
  3. Apple to Reportedly Launch Low-Cost MacBook in 'Playful Colors' in March
  4. Samsung Galaxy A27 5G Lands on IMEI Database, Could Launch Soon
  5. Vivo X300 FE Reportedly Bags IMDA and TUV Certifications Ahead of Launch
  6. Tecno Spark 50 4G Launch Timeline, Design, Colourways, Key Features Leaked
  7. Anthropic's First Indian Office in Bengaluru Is Now Open
  8. X Will Soon Let Users Check Cryptocurrency Prices in Real-Time
  9. AI Impact Summit: From Registration to Schedule, All You Need to Know
  10. Lava Bold N2 Will Be Launched in India on This Date: See Expected Specs
  1. X Building Smart 'Cashtags' to Let Users Check Cryptocurrency Prices in Real-Time
  2. Samsung Galaxy A27 5G Listing on IMEI Database Suggests a Galaxy A26 Successor Is on the Way
  3. Anthropic Inaugurates First Indian Office in Bengaluru, Starts Hiring Local Talent
  4. Apple Tipped to Adopt Samsung's Privacy Display Technology for MacBook Models by 2029
  5. Oppo Find X10 Series Tipped to Launch in H2 2026 With Built-In Magnets for Wireless Charging
  6. AMD and TCS to Co-Develop Helios AI Data Centre Architecture, Deliver 200MW Data Centre Blueprint
  7. Tecno Spark 50 4G Tipped to Launch Globally Soon; Design, Colourways, Key Features Leaked
  8. Lava Bold N2 India Launch Date Revealed; Will Be Exclusively Available via Amazon
  9. Government Green Lights Rs. 10,000 Crore Fund of Funds 2.0 Under the Startup India Mission
  10. Samsung’s 'Wide' Galaxy Z Fold Design Revealed via Leaked One UI 9 Animations
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.