Global software giant Adobe is hit by a major security incident. Since April 2, the security community has been buzzing over an attack claimed by a hacker calling himself Mr. Raccoon. Leaked screenshots show the attacker penetrated Adobe systems and exfiltrated highly sensitive internal data: 13 million customer support tickets containing personal information, 15,000 employee records, and even detailed HackerOne bug bounty submissions. The scale and scope signal a catastrophic breach.
Indian BPO Contractor as the Weak Link
The attack did not target Adobe's hardened core network directly. Instead, it used a supply chain attack method. Hackers focused on an Indian business process outsourcing (BPO) company handling Adobe customer support. They first sent a phishing email to a BPO employee, planting a remote access tool (RAT). Once inside, they took over the employee's workstation and webcam, even accessing private WhatsApp messages. After establishing a foothold, the hacker used the compromised employee's credentials to spear-phish that person's manager, gaining elevated access. This incident highlights a harsh truth: outsourcing core services to a vendor with weak security can turn that vendor into the enterprise's biggest vulnerability.
System Flaw Lets Attackers Dump Millions of Records
With higher privileges, the hacker discovered a critical design flaw in Adobe's customer support system — the backend allowed agents to export all tickets at once, with no rate limiting or bulk export audit. This lack of safeguard let the hacker drain 13 million records unimpeded. The theft of HackerOne bug reports is even more alarming. It means the attacker likely now knows about unpatched vulnerabilities and internal operations, opening the door to secondary attacks and extortion.
No Official Statement Yet, Experts Urge Immediate Action
As of press time, Adobe has not issued any public statement on its website or social channels. But the breach has already ignited a firestorm of criticism online, with many users blasting Adobe for entrusting core customer service to a security-lax third party. If confirmed, Adobe could face massive fines under GDPR and CCPA, plus a severe erosion of user trust. Security experts strongly advise all Adobe users to change passwords immediately, enable multi-factor authentication (MFA), and monitor bank accounts and credit cards for suspicious activity. Those who have ever submitted a support ticket should be especially vigilant against targeted phishing attacks leveraging the leaked data.

