A phishing email sent to a single support agent at a third party outsourcing vendor allegedly gave an attacker calling itself Mr Raccoon a path to 13 million Adobe customer support tickets and Adobe’s entire trove of unpublished HackerOne vulnerability reports, according to Security Boulevard. The root cause, per the outlet’s reporting, was not a zero day but a support ticketing platform that let one agent export millions of records in a single request with no rate limits or alerts attached.
How did a single phished support agent lead to a breach this size?
The intrusion reportedly began with a malicious email sent to an employee at a business process outsourcing firm that handles Adobe’s customer support, according to CyberSecurityNews. The email delivered a remote access tool that, the outlet reports, gave the attacker webcam access and the ability to intercept WhatsApp messages on the compromised machine. Rather than moving directly into Adobe’s core systems, the attacker allegedly used that initial foothold to spear phish the employee’s manager, according to CyberPress, widening access within the BPO’s environment before reaching the ticketing platform itself.
That pattern, a low privileged contractor account as the initial entry point, mirrors a run of 2026 incidents that have moved industry attention away from a target company’s own perimeter and onto its vendors. Accenture’s July breach, which exposed 35GB of source code and Azure credentials, and the Estée Lauder breach traced to an exploited Oracle flaw, both followed the same shape: a trusted third party became the weak link that a much larger company’s defenses never accounted for.
What did the ticketing platform get wrong?
According to Security Boulevard, the flaw was strikingly simple: a single support account could query and export the entire ticket database in one request, with no volume caps, no anomaly alerting and no additional authorization step for bulk actions. Deepak Gupta, the security researcher and GrackerAI co-founder cited by Security Boulevard, put it plainly: “A single account querying millions of records is not normal support activity. It is either a breach or a policy violation, and either way it should trigger an immediate alert.”
That is a textbook violation of least privilege design: a support agent’s job requires looking up individual tickets, not exporting the whole warehouse, and the system should never have allowed the two to look the same. Security Boulevard frames third party access broadly as the dominant breach vector of 2026, pointing to comparable incidents this year involving Vercel, Mercor and the EU Commission as evidence the pattern is systemic rather than a one off failure by Adobe’s vendor.
Why do the unpublished vulnerability reports matter most?
Of everything in the alleged haul, the coverage agrees the HackerOne submissions carry the sharpest edge. CyberPress and CyberSecurityNews both report that the exposure includes all of Adobe’s bug bounty submissions, meaning vulnerability details that researchers disclosed privately, and that Adobe had not yet patched, may now sit outside Adobe’s control. A support ticket leak is a privacy and phishing problem for named customers. An unpatched vulnerability report in the hands of an unknown party is a live weapon that can be used against every Adobe customer running the affected product, not just the 13 million whose ticket data was allegedly taken.
Alongside the customer tickets and bug bounty data, the claimed haul includes 15,000 employee records and internal documents, according to CyberPress and CyberSecurityNews, both citing the threat actor’s own claims as first surfaced by International Cyber Digest. Adobe had not issued a statement confirming or denying the breach at the time any of the three outlets published.
| What happened | A support agent at a third party BPO vendor was allegedly phished and used to bulk export Adobe support tickets and unpublished HackerOne vulnerability reports, according to Security Boulevard |
|---|---|
| Threat actor | A group or individual using the name Mr Raccoon has claimed responsibility, according to CyberSecurityNews and CyberPress |
| Who is affected | Adobe customers named in support tickets, roughly 15,000 Adobe employees, and security researchers whose private vulnerability submissions were allegedly taken |
| Scale claimed | Approximately 13 million support tickets, 15,000 employee records, and all HackerOne bug bounty submissions, per CyberPress |
| Root cause | A ticketing platform misconfiguration allegedly allowed bulk export of all tickets in a single request with no rate limits or alerts, according to Security Boulevard |
| Status | Adobe has not confirmed or denied the breach as of publication |
Is this part of a wider pattern of BPO and vendor compromise?
Yes, and the shape recurs across this year’s biggest breach stories. The common denominator across the ShinyHunters campaign against Instructure and US schools and the 23 million user Paidwork breach is that attackers increasingly find it easier to phish a person with legitimate access than to break an application directly. Each of these incidents scales the same lesson: the size of the loss is set less by the sophistication of the intrusion and more by how much a single compromised account is trusted to touch.
What should security leaders do now?
For CISOs, the Adobe claims are a prompt to audit exactly this failure mode inside their own support and vendor stack, not just Adobe’s. Three questions are worth asking this week: can any single support seat export bulk customer data without triggering an alert; does the organization’s vendor risk program extend real monitoring to BPO staff accounts, or only to the vendor’s stated policies; and would a spear phishing attempt against a support manager, the second stage of this alleged attack, actually be caught by a current security awareness or human risk management program.
Board reporting should reflect that this is a governance failure as much as a technical one. Contract language with support and BPO vendors should require bulk export logging, rate limiting and breach notification timelines as a condition of handling customer data, and procurement teams should treat “can one compromised seat exfiltrate everything” as a standard due diligence question rather than an afterthought. Adobe’s own patching record adds context: the company was already under pressure this year after CISA ordered federal agencies to patch a max severity ColdFusion flaw, and an unpublished vulnerability report leak, if confirmed, would add a second front to that exposure.
Until Adobe issues an official statement, the scale, timeline and even the identity of the responsible party rest on the threat actor’s own claims as relayed by Security Boulevard, CyberSecurityNews and CyberPress. Security leaders should treat the underlying lesson, that one over privileged support account can be worth more than a network perimeter, as confirmed regardless of how the specific numbers eventually shake out.
Frequently asked questions
What happened in the Adobe BPO breach claims?
A phishing email sent to a support agent at a third party outsourcing vendor allegedly led to the export of 13 million Adobe customer support tickets and all of Adobe’s unpublished HackerOne vulnerability reports, according to Security Boulevard. Adobe has not confirmed or denied the reported breach.
Who is claiming responsibility for the Adobe data leak?
A threat actor using the name Mr Raccoon has claimed the breach, according to CyberSecurityNews and CyberPress. Both outlets note the claims trace back to reporting by International Cyber Digest and that Adobe has not verified them.
Why are the exposed HackerOne reports considered the bigger risk?
Unlike customer ticket data, unpublished vulnerability reports describe security flaws Adobe had not yet patched. If those details reached unauthorized parties, they could be used to attack Adobe products before fixes ship, according to reporting on the claimed leak.

Leave a Reply