Home Artists Posts Import Register

Downloads

Content

By Shannon Morse, ThreatWire 

Adobe left an Elasticsearch database connected online without a password, leading to the exposure of 7.5 million Creative Cloud customer details. Creative cloud is a subscription service used by creators with access to products such as Photoshop, Lightroom, Premiere Pro, After Effects, and more. 

Data exposed included email addresses, account creation date, Adobe products subscribed to, subscription status, payment status, member ID, country, time since last login, and Adobe employee status. No financial information or passwords were exposed. The data was found on October 19 by Bob Diachenko, a security researcher from Security Discovery, and Paul Bischoff, tech journalist for CompariTech. They notified Adobe, and the company secured their data the same day. Adobe later posted a public bulletin about the data on October 25. It’s unknown how long the data was online.

Adobe concluded that this leak was due to a misconfiguration of a prototype environment and it was not in connection to any core products or services. Since Adobe has somewhere between 12 to 15 million Creative Cloud users, and this affected 7.5 million users, that means it affected about half of paying subscribers.

While the data leaked is minimal, the information could have been obtained by an attacker or downloaded without Adobe knowing, and this could lead to spear phishing attacks since it did include email addresses. Scrutinize any emails sent from addresses purportedly owned by Adobe, and set up 2 factor authentication on your creative cloud account if you haven’t done so already.

Support me on alternative platforms! https://snubsie.com/support

https://www.youtube.com/shannonmorse --  subscribe to my new channel!

ThreatWire is only possible because of our Patreon patrons! https://www.patreon.com/threatwire 

https://www.comparitech.com/blog/information-security/7-million-adobe-creative-cloud-accounts-exposed-to-the-public/

https://theblog.adobe.com/security-update/

https://threatpost.com/adobe-creative-cloud-users-exposed-hackers/149563/

https://thehackernews.com/2019/10/adobe-database-leaked.html

Comments

No comments found for this post.