TL;DR: A threat actor called "Mr. Raccoon" claims to have stolen 13 million Adobe customer support tickets, 15,000 employee records, and unpublished HackerOne bug bounty submissions, all by hacking an Indian outsourcing firm that handles Adobe's customer support. He phished one BPO employee, installed a remote access tool, watched their webcam and WhatsApp to learn the internal hierarchy, then phished the employee's manager for admin access. The entire support ticket database was exported in a single request. No rate limiting. No DLP alert. No alarm whatsoever. Adobe hasn't confirmed or denied the breach.
The Attack: One BPO Employee Was Enough
Mr. Raccoon didn't hack Adobe. He hacked the people Adobe pays to talk to its customers.
The attack chain, as described by the threat actor and corroborated by security researchers [1][2]:
- Phishing email to BPO agent. A convincing message to a support agent at an unnamed Indian BPO firm that handles Adobe's customer service. The agent clicked and installed a Remote Access Tool (RAT).
- Reconnaissance via webcam and WhatsApp. With full control of the agent's machine, Mr. Raccoon turned on the webcam, read private WhatsApp messages, and mapped the internal reporting structure. He knew who the agent's manager was and how the team communicated.
- Spear-phishing the manager. Using the compromised agent's email account, Mr. Raccoon sent a targeted phishing message to the agent's manager. The manager fell for it, handing over elevated credentials with admin-level access to Adobe's support systems.
- Mass data export. With manager credentials, Mr. Raccoon exported the entire support ticket database. His words: "They allowed you to export all tickets in one request from an agent" [1].
Two phishing emails. That's all it took to access 13 million customer records.
What Was Stolen
If the claims are legitimate (and independent researchers say the evidence is plausible [3]) this is what's out there:
13 Million Support Tickets
Customer names, emails, account IDs, technical details about their Adobe installations, and the full text of every support conversation.
15,000 Employee Records
Internal staff data, potentially including addresses, payroll information, and organizational structure details.
HackerOne Bug Bounty Submissions
Full vulnerability reports with proof-of-concept exploits. This is the most dangerous piece: unremediated bugs that could be weaponized before patches ship.
Internal Documents
Corporate strategy documents and technical specifications from Adobe's internal systems.
The HackerOne Problem
Forget the support tickets for a second. The HackerOne data is potentially catastrophic.
Bug bounty platforms like HackerOne exist so that security researchers can privately report vulnerabilities to companies before attackers find them. The whole system depends on confidentiality. Researchers submit proof-of-concept exploits. Companies fix them. Nobody else sees the details until a patch is out.
If Mr. Raccoon actually has Adobe's HackerOne submissions, he has a collection of step-by-step instructions for exploiting Adobe products, some of which may not be patched yet. That turns a customer data breach into a potential weapon against every Adobe user on the planet.
Adobe Creative Cloud has over 30 million subscribers. Adobe Acrobat Reader is installed on basically every computer in existence. Unpatched vulnerabilities in those products aren't just theoretical risks.
The BPO Backdoor Nobody Talks About
Here's the part of this story that should keep every CISO up at night: the attack surface wasn't Adobe's network. It was a third-party call center in India. It's the same pattern driving supply chain attacks across 2026, where the weak link is a vendor.
Business Process Outsourcing is a $300+ billion industry. Companies outsource customer support because it's cheaper, sometimes 70-80% cheaper than domestic staff. But those BPO agents aren't temporary contractors with limited access. They sit in your support portals all day. They read customer data. They access internal tools. They are, functionally, your employees, except they work in a different country, on a different company's network, under a different company's security policies.
What a BPO support agent can typically access:
- Customer contact information (name, email, phone, address)
- Account details and purchase history
- Technical system information shared during troubleshooting
- Internal knowledge bases and documentation
- Escalation tools that connect to deeper systems
And in Adobe's case, apparently, the ability to export the entire ticket database in a single request with no rate limiting, no DLP alert, and no behavioral anomaly detection [1].
The agent's account behaved like a database administrator. The SOC didn't blink.
Four Security Failures That Made This Possible
Even if Adobe's own network is Fort Knox, the BPO relationship created holes that a moderately skilled attacker exploited in days:
- No rate limiting on data exports. A single support agent account could export 13 million records in one request. That's not a bug. That's a missing guardrail.
- No Data Loss Prevention (DLP). When a support agent suddenly downloads the entire ticket database, alarms should fire. They didn't.
- No behavioral anomaly detection. The system couldn't tell the difference between a support agent helping one customer and an attacker draining the whole database.
- Excessive BPO access privileges. A manager at a third-party company had admin credentials for Adobe's support infrastructure. That's too much access for a contractor.
Adobe's Response: Silence
As of April 17, 2026, Adobe has not confirmed or denied the breach. No official statement. No breach notification. No comment to any of the publications that have covered the story [3][4][5].
The breach claims first surfaced around April 4. That's nearly two weeks of silence. If 13 million customers' support tickets are floating around the internet, those customers deserve to know.
Verification group vx-underground has reportedly examined the data and considers it plausible, but full confirmation hasn't been established [3].
If You've Ever Contacted Adobe Support
Until Adobe confirms or denies, treat this as real. If you've ever opened an Adobe support ticket, here's what to do:
Assume Your Ticket Is Public
Whatever you told Adobe support (your name, email, system details, license keys, error logs) assume a stranger has read it.
Watch for Targeted Phishing
Attackers could craft convincing phishing emails referencing your actual Adobe support case. "Re: Your ticket #12345 about Photoshop crashing" would fool a lot of people.
Change Your Adobe Password
Support tickets sometimes contain account details or system information that could help an attacker access your account.
Enable Two-Factor Authentication
If you haven't already, turn on 2FA for your Adobe account. Go to account.adobe.com → Security → Two-step verification.
Your Support Tickets Are a Goldmine
People say things in support tickets they'd never put anywhere else. License keys. Internal system configurations. Error logs with file paths. Screenshots of their desktop. "Can you help me access my coworker's account while they're on leave?"
A database of 13 million support tickets isn't just a list of names and emails. It's 13 million conversations between people who had problems and the company they trusted to help. Every one of those conversations contains information the customer assumed was private.
Every company that outsources customer support should be asking itself right now: could this happen to us? If the answer isn't an immediate, confident "no," it's time for an audit. Because Mr. Raccoon showed exactly how easy the BPO backdoor is to open.
References
- Security Online - The BPO Backdoor: How "Mr. Raccoon" Swiped 13 Million Adobe Support Tickets (April 2026)
- The CyberSec Guru - Adobe Data Breach 2026: Mr. Raccoon Leaks 13M Support Tickets (April 2026)
- Cybernews - Threat actor claims Adobe breach and theft of 13 million support tickets (April 2026)
- Cybersecurity News - Adobe Breach: Threat Actor Claims Leak of 13 Million Support Tickets (April 2026)
- GBHackers - Adobe Data Breach Exposes 13 Million Tickets (April 2026)