The encyclopedia · Software & IT · Operational decision · 2013
Adobe's 2013 breach stole 153M user records — and the source code for Photoshop
In 2013, hackers stole 153M Adobe user records and the source code for Photoshop, Acrobat and ColdFusion. It was one of the largest breaches of its era.
Adobe Inc. · 2013-10
What happened
In October 2013, Adobe disclosed that hackers had accessed its systems and stolen approximately 153 million user records, including names, encrypted passwords and credit card numbers. The hackers also stole source code for Adobe's flagship products: Photoshop, Acrobat and ColdFusion.
The breach was notable for its dual impact: the user data theft affected millions of customers, and the source code theft gave competitors and malicious actors access to Adobe's most valuable intellectual property. The stolen ColdFusion source code was subsequently used in attacks against other organizations.
Adobe was criticized for its password storage practices (the passwords were encrypted but not hashed, making them vulnerable to decryption) and for its slow disclosure. The case illustrated how a breach can have two distinct impacts — customer data and intellectual property — and how the theft of source code can create a cascading risk that extends far beyond the breached company.
Why it happened
- Hackers stole 153M user records and source code for Photoshop, Acrobat and ColdFusion.
- Adobe's password storage (encrypted, not hashed) made passwords vulnerable to decryption.
- The stolen ColdFusion source code was used in attacks against other organizations.
- Adobe was criticized for slow disclosure and inadequate security practices.
The lesson
A breach that steals source code is an IP breach with cascading consequences. Adobe's stolen ColdFusion code was used to attack other companies. Source code is a weapon in the wrong hands.
Aftermath
Adobe overhauled its security practices and migrated to a cloud-based subscription model (Creative Cloud). The case influenced the industry's shift toward cloud-based software, which centralizes security and reduces the attack surface of distributed installations.
Sources
- CSO Online — Stolen Adobe account data goes public; Photoshop source code breached (Oct 2013; 153M records; source code theft; password encryption flaws)
- Adobe Data Breach — Huntress Threat Library
spotted an error? The club wants to know.
More like this
Okta's support engineer was screen-shared into — and 366 customers were breached
LastPass was hacked twice in 2022 — the second breach exposed password vaults
Hackers exploited zero-days in Microsoft Exchange — and 250,000 servers were compromised
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.