Data from nearly 7.5 million Adobe Creative Cloud users was exposed online by a password-free Elasticsearch database.
The leaked information mainly included details of Adobe Creative Cloud customer accounts, but no passwords or stored payment information.
The exposed user information included email addresses, Adobe member IDs (usernames), country of origin, and the Adobe products they used. It also included the account creation date, the last login date, whether the account belonged to an Adobe employee, and the subscription status (active or not).
The data leak was discovered last week (Saturday, October 19) by security researcher Bob Diachenko of Security Discovery and Paul Bischoff, a technology journalist at CompariTech.
The researchers shared their findings with Adobe, and the company secured the database the same day.
Diachenko and Bischoff praised Adobe for its quick response and admitted that the data leak was not as serious as other leaks that have been published in the past, as it did not contain passwords, payment information or the real names of the company's customers.
However, it is unclear whether anyone else has managed to access this database and downloaded its contents. The data could be used to send spam to users whose email addresses were exposed.
Specifically, hackers could target active Adobe Premium account owners with phishing emails to obtain Adobe Creative Cloud accounts, which as you may know are quite expensive. These accounts could then be sold online, on specialized Dark Web marketplaces.
For its part, Adobe admitted to the exposure of the information in a blog post on Friday, October 25.
It should be noted that this leak is nothing compared to the massive Adobe breach in 2013, where hackers obtained almost all of the data from 38 million Adobe users. At the time, the Adobe breach was one of the largest hacks ever.
