Jump to content

Adobe leaks half of its cloud user data

williamcll

Last week, security researchers discovered a database that could be accessed without the use of a password, the leak was patched on the same day.

Quote

Nearly 7.5 million Adobe Creative Cloud user records were left exposed to anyone with a web browser, including email addresses, account information, and which Adobe products they use.

Comparitech partnered with security researcher Bob Diachenko to uncover the exposed database. The Elasticsearch database could be accessed without a password or any other authentication.

Diachenko immediately notified Adobe on October 19 and the company secured the database on the same day.

Timeline of the exposure

adobe dump

Upon discovering the exposed data, Diachenko immediately took steps to notify Adobe.

  • October 19, 2019 – Security researcher Diachenko discovered the exposed data and immediately notified Adobe.
  • October 19, 2019 – Adobe secured the instance.

We do not know when, exactly, the database first appeared, but Diachenko estimates it was exposed for about a week. We do not know whether anyone else gained unauthorized access to the database in the meantime.

What information was exposed?

adobe cc exposure

The exposed user data wasn’t particularly sensitive, but it could be used to create phishing campaigns that target the Adobe users whose emails were leaked. The following user data was included:

  • Email addresses
  • Account creation date
  • Which Adobe products they use
  • Subscription status
  • Whether the user is an Adobe employee
  • Member IDs
  • Country
  • Time since last login
  • Payment status

The data did not include payment information or passwords.

Dangers of exposed data to Adobe Creative Cloud users

The information exposed in this leak could be used against Adobe Creative Cloud users in targeted phishing emails and scams. Fraudsters could pose as Adobe or a related company and trick users into giving up further info, such as passwords, for example.

The information does not pose a direct financial or security threat. No credit cards or other payment information was exposed, nor were any passwords.

 

Comparitech conducts security research that entails scanning the web for exposed databases. When we uncover a database that hasn’t been properly secured and allows unauthorized access, we immediately notify the owner.

Our aim is to mitigate potential harm to end users. Bob Diachenko leans on his extensive cybersecurity experience to quickly uncover breaches, analyze the data, and track down the responsible organization.

Once the database has been secured, we write a report like this one to help notify affected users and make them aware of the risks. We hope our work can make users safer and limit abuse by malicious parties.

Source:https://www.comparitech.com/blog/information-security/7-million-adobe-creative-cloud-accounts-exposed-to-the-public/

https://thenextweb.com/security/2019/10/28/oops-adobe-leaves-7-5-million-creative-cloud-accounts-exposed/

Thoughts: While it is not a serious at the previous leak back in 2013 that had payment information, it is a kind reminder to change your credentials every so often. I am still using CS4 so this doesn't affect me at all.

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

Thanks Adobe.

Resident Mozilla Shill.   Typed on my Ortholinear JJ40 custom keyboard
               __     I am the ASCIIDino.
              / _)
     _.----._/ /      If you can see me you 
    /         /       must put me in your 
 __/ (  | (  |        signature for 24 hours.
/__.-'|_|--|_|        
Link to comment
Share on other sites

Link to post
Share on other sites

Given how quickly the exploit was patched, I'll keep my pitchfork in storage (still need my torch out though because PG&E), and chalk it down to *expletives* happen.

My eyes see the past…

My camera lens sees the present…

Link to comment
Share on other sites

Link to post
Share on other sites

Lol. Adobe products. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

sigh, here we go again

~New~  BoomBerryPi project !  ~New~


new build log : http://linustechtips.com/main/topic/533392-build-log-the-scrap-simulator-x/?p=7078757 (5 screen flight sim for 620$ CAD)LTT Web Challenge is back ! go here  :  http://linustechtips.com/main/topic/448184-ltt-web-challenge-3-v21/#entry601004

Link to comment
Share on other sites

Link to post
Share on other sites

And now we'll see a price hike to their cloud suite in order to improve user security.

 

You would think that in this day and age, we would see less companies leaving databases open to the public like this. What absolute hooligans.

if you have to insist you think for yourself, i'm not going to believe you.

Link to comment
Share on other sites

Link to post
Share on other sites

Riiiiiight when I decided to renew my CC sub

 

Thanks

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

I see they've learned nothing since the last time.  That, plus given how poorly secured this was has now made me realize they have no clue what they're doing and don't care, and that's just one more reason to avoid their cloud offerings... not that I was interested anyway, even if they were free.  Tried it once, thoroughly unimpressed.  I'll stick with CS6.

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Adc31.pngbe

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, williamcll said:

a database that could be accessed without the use of a password

LMAO

 

Imagine paying hundreds in monthly fees and expecting anything other than the worst kind of incompetence.

4 hours ago, Ryan_Vickers said:

I'll stick with CS6.

If this is the level they operate at it's just a matter of time something goes equally wrong with everything else they sell ?

Don't ask to ask, just ask... please 🤨

sudo chmod -R 000 /*

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Sauron said:

If this is the level they operate at it's just a matter of time something goes equally wrong with everything else they sell

And that's why everyone torrents it.

 

I actually bought ClipStudio Paint but still find myself doing a lot of non-drawing stuff in CS6

🌲🌲🌲

 

 

 

◒ ◒ 

Link to comment
Share on other sites

Link to post
Share on other sites

Same Adobe that limited user passwords to max 8 characters few years ago... And I think it could only be alphanumeric, no special characters. Peak security expected from company that does this kind of shit...

Link to comment
Share on other sites

Link to post
Share on other sites

They're really tempting me to fully ditch Lightroom at this point in time.

The Workhorse (AMD-powered custom desktop)

CPU: AMD Ryzen 7 3700X | GPU: MSI X Trio GeForce RTX 2070S | RAM: XPG Spectrix D60G 32GB DDR4-3200 | Storage: 512GB XPG SX8200P + 2TB 7200RPM Seagate Barracuda Compute | OS: Microsoft Windows 10 Pro

 

The Portable Workstation (Apple MacBook Pro 16" 2021)

SoC: Apple M1 Max (8+2 core CPU w/ 32-core GPU) | RAM: 32GB unified LPDDR5 | Storage: 1TB PCIe Gen4 SSD | OS: macOS Monterey

 

The Communicator (Apple iPhone 13 Pro)

SoC: Apple A15 Bionic | RAM: 6GB LPDDR4X | Storage: 128GB internal w/ NVMe controller | Display: 6.1" 2532x1170 "Super Retina XDR" OLED with VRR at up to 120Hz | OS: iOS 15.1

Link to comment
Share on other sites

Link to post
Share on other sites

And people wonder why I ditched everything to do with Adobe a while back.

Jeannie

 

As long as anyone is oppressed, no one will be safe and free.

One has to be proactive, not reactive, to ensure the safety of one's data so backup your data! And RAID is NOT a backup!

 

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, Lady Fitzgerald said:

And people wonder why I ditched everything to do with Adobe a while back.

Well, not everyone has that luxury. If you're a professional in the creative space, you're stuck with Adobe UNLESS you work alone.

 

They need viable competition for people to turn to. Affinity is very close on the graphic design front, but still lacks some layers of compatibility with CS.

MacBook Pro 16 i9-9980HK - Radeon Pro 5500m 8GB - 32GB DDR4 - 2TB NVME

iPhone 12 Mini / Sony WH-1000XM4 / Bose Companion 20

Link to comment
Share on other sites

Link to post
Share on other sites

Yet again adobe fail but barely anyone blinks an eye due to wide adoption. Sadly there are equal if not better alternatives for free for virtually every operating system but because learning how to do something differently is too complicated for most users especially on the windows platform, they go mostly ignored.

 

Unfortunately, this will also have no effect to fan boys like linus who unceremoniously take every opportunity to provide advertising free of charge in many of their videos for adobe products often citing them as an excuse not to adapt or change.

Link to comment
Share on other sites

Link to post
Share on other sites

On 10/29/2019 at 7:40 PM, Vitamanic said:

Well, not everyone has that luxury. If you're a professional in the creative space, you're stuck with Adobe UNLESS you work alone.

 

They need viable competition for people to turn to. Affinity is very close on the graphic design front, but still lacks some layers of compatibility with CS.

I'm retired. I'll use whatever I jolly well please. ?

Jeannie

 

As long as anyone is oppressed, no one will be safe and free.

One has to be proactive, not reactive, to ensure the safety of one's data so backup your data! And RAID is NOT a backup!

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×