Friday, September 11, 2026

Adobe Data Breach Allegedly Exposes 13 Million Support Tickets

A threat actor known as “Mr. Raccoon” claims to have breached Adobe, stealing a massive amount of sensitive data.

According to a report by International Cyber Digest, the stolen files include 13 million customer support tickets, 15,000 employee records, internal documents, and all of the company’s HackerOne bug bounty submissions.

The attacker did not hack into Adobe’s main network directly. Instead, they used a supply chain attack through an Indian Business Process Outsourcing (BPO) company that handles support services for Adobe.

According to CSN, the breach reportedly began when a BPO employee received a malicious email.

This email installed a Remote Access Tool (RAT) on the employee’s computer. Once the hacker had this initial foothold, they sent a targeted phishing message to the employee’s manager to gain deeper network access.

The hacker also claimed the remote software gave them access to the employee’s webcam and allowed them to read their private WhatsApp messages.

A Major Security Flaw

One of the most surprising details of this breach was a simple misconfiguration in Adobe’s support ticketing platform.

The threat actor told reporters, “They allowed you to export all tickets in one request from an agent.”

This suggests there were no limits or security blocks in place to stop bulk data downloads.

An agent account could simply request a massive export of millions of records without triggering any alarms or requiring special approval.

Directories open to access (Source:International Cyber Digest )
Directories open to access (Source:International Cyber Digest )

The files taken in this alleged breach are highly valuable to cybercriminals. Customer support tickets usually contain names, email addresses, account details, and notes about technical problems.

Hackers can easily weaponize this information to launch highly convincing phishing scams or steal identities.

The theft of the HackerOne bug bounty reports is even more dangerous. These files contain step-by-step details about software vulnerabilities found by security researchers.

If any of these flaws have not been patched yet, other threat actors could use them to launch new attacks against Adobe users.

Adobe has not yet released an official statement to confirm or deny this breach. However, if these claims are true, it represents one of the largest data exposures of 2026 and highlights the growing dangers of third-party vendor access.

Security teams across all industries should use this incident as a reminder to monitor their BPO contractors.

Companies must audit their systems to ensure no single user has the power to download bulk data without strict security checks.

Note: This article is based on unverified claims reported by International Cyber Digest. Adobe has not officially confirmed the breach at the time of publication.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News