TL;DR: A threat actor going by "Mr. Raccoon" says they breached Adobe through an Indian BPO contractor. The claimed haul: 13 million customer support tickets, 15,000 employee records, and all of Adobe's HackerOne bug bounty submissions: detailed vulnerability reports that could hand attackers a roadmap to exploit unpatched flaws. The entry point was a phishing email to a single outsourced employee. Adobe hasn't confirmed or denied anything. If you've ever filed an Adobe support ticket, your data may be exposed.
What Mr. Raccoon Claims
On April 2, 2026, a threat actor calling themselves "Mr. Raccoon" posted claims on the IntCyberDigest X account that they'd breached Adobe's internal systems [1]. Not by hacking Adobe directly. By hacking Adobe's contractor.
The claimed data haul is massive:
- ~13 million customer support tickets: names, email addresses, phone numbers, account details, and the contents of every support conversation
- ~15,000 employee records: internal Adobe employee data
- All HackerOne bug bounty submissions: step-by-step vulnerability reports submitted by security researchers
- Internal corporate documents: unspecified company files
The breach hasn't been independently verified. Adobe has stayed silent: no confirmation, no denial, no customer notification. As of April 8, 2026, the company hasn't issued any public statement [2].
How the Attack Worked
The attack path reads like a textbook supply chain compromise. Mr. Raccoon didn't need to breach Adobe's perimeter. They breached someone who was already inside it.
Step 1: Phish the Contractor
Mr. Raccoon targeted an employee at an Indian BPO (Business Process Outsourcing) firm contracted by Adobe for support operations. A phishing email delivered a RAT (a Remote Access Tool) that gave the attacker full control of the employee's workstation [1].
Full control means everything. Keystrokes, screen content, webcam, even private WhatsApp messages. The attacker had complete visibility into the employee's digital life [3].
Step 2: Phish Upward
With the BPO employee's credentials and context (knowing their communication style, their manager's name, internal tools they used) Mr. Raccoon launched a targeted phishing attack against the employee's manager [3].
This "upward phish" succeeded. The manager's elevated privileges unlocked access to Adobe's internal support systems.
Step 3: Export Everything
Here's where Adobe's own systems failed. According to Mr. Raccoon, Adobe's support portal allowed bulk data exports with no rate limiting and no volume restrictions. As the attacker put it: "They allowed you to export all tickets in one request from an agent" [3].
No alerts triggered. No export limits kicked in. Thirteen million tickets downloaded in what appears to be a single bulk operation.
Why the Bug Bounty Data Is the Real Bomb
Thirteen million support tickets is a privacy disaster. But the HackerOne bug bounty submissions? That's a security catastrophe.
Bug bounty programs work on trust. Security researchers find vulnerabilities in Adobe's products (Acrobat, Photoshop, Creative Cloud, Experience Manager) and privately report them through HackerOne. In exchange, they get paid. Adobe gets time to patch before anyone else knows.
Those reports contain:
- Exact steps to reproduce each vulnerability
- Proof-of-concept exploit code
- Severity assessments and attack surface analysis
- Internal Adobe responses about patch timelines
If any of those vulnerabilities remain unpatched, every Adobe user just got exposed. Attackers can skip the hard part (finding the bugs) and jump straight to exploitation. And Adobe's products run on hundreds of millions of devices worldwide [1].
This isn't theoretical. Bug bounty leaks have triggered real-world exploitation chains before. When HackerOne itself was breached via Navia Benefit Solutions earlier this year, the security community shuddered. Now the actual vulnerability data may be in the wild.
The BPO Backdoor
Adobe didn't get hacked because their firewalls were weak. They got hacked because their vendor's employee clicked a phishing email.
This isn't an anomaly. It's the pattern. Third-party breaches doubled to 30% of all breaches according to the 2025 Verizon DBIR [4]. Seventy percent of organizations experienced supply chain incidents in 2025, with losses reaching $60 billion globally [5].
The list of companies breached through outsourcing partners keeps growing:
- Crunchyroll: breached through Telus, an Indian outsourcing partner
- Korean Air: 30,000 employee records stolen via vendor
- Conduent: 25 million Americans affected through a government services processor
BPO firms are high-value targets because they sit on the inside. They have credentials. They have access. And their security budgets are often a fraction of the companies they serve. Your data is only as safe as the least-trained employee at your vendor's subcontractor.
Adobe's Silence
Six days since the claims surfaced. Zero from Adobe.
No confirmation. No denial. No "we're investigating." No customer notification. No SEC 8-K filing. Nothing on their security advisories page. Nothing on their blog [2].
Companies often go quiet during active incident response, and that's not unusual. But Adobe's 300+ million Creative Cloud subscribers deserve to know whether their support tickets, account details, and interactions with Adobe are sitting on a threat actor's server.
If the breach is real, Adobe's lack of disclosure could have legal consequences. Multiple US states now require breach notification within 30-72 hours of discovery. The EU's GDPR mandates notification to authorities within 72 hours.
What Adobe Customers Should Do Now
Change Your Adobe Password
If you've ever contacted Adobe support (especially through email or their portal) change your password now. Use a unique password you don't reuse anywhere else.
Enable Two-Factor Authentication
Adobe supports 2FA via authenticator apps. Turn it on: Adobe Account → Security → Two-Step Verification. Don't use SMS. Use an authenticator app or hardware key.
Watch for Targeted Phishing
If your support tickets leaked, attackers know what Adobe products you use, what problems you've had, and potentially your contact details. Expect convincing phishing emails referencing real support issues.
Monitor Your Accounts
Support tickets often contain email addresses, phone numbers, and account-specific details. Watch for unauthorized access attempts across all services using that email address.
The Outsourcing Problem Nobody Wants to Fix
Adobe outsourced customer support to save money. Most big tech companies do. But when you outsource operations, you outsource risk.
The Indian BPO industry processes data for nearly every Fortune 500 company. It's a $250 billion sector. And it's become the most reliable entry point for attackers who can't breach their primary target directly.
The fix isn't complicated in theory: vendors need the same security standards as the companies they serve. In practice, nobody wants to pay for it. Vendor security assessments are often checkbox exercises. Annual audits don't catch real-time phishing attacks. And a RAT on one contractor's laptop can blow open a data vault holding 13 million customer records.
Until companies treat their supply chain as their own attack surface, this pattern will repeat. Adobe won't be the last.
References
- Cyber Security News: Adobe Breach: Threat Actor Allegedly Claims Leak of 13 Million Support Tickets and Employee Records (April 3, 2026)
- CyberNews: Threat actor claims Adobe breach and theft of 13 million support tickets – allegations unverified (April 4, 2026)
- Security Online: The BPO Backdoor: How "Mr. Raccoon" Swiped 13 Million Adobe Support Tickets (April 3, 2026)
- DeepStrike: Supply Chain Attack Statistics 2025: Costs, Cases, Defenses
- DeepStrike: Supply Chain Cybersecurity Statistics 2026: Risks and Trends
Published: April 8, 2026