Adobe Breach Through Third-Party Support Vendor Exposes 13 Million Tickets

A threat actor calling itself Raccoon has allegedly breached Adobe not by attacking Adobe’s own infrastructure directly, but by compromising an Indian business process outsourcing firm contracted for customer support operations, ultimately exposing 13 million customer support tickets, 15,000 employee records, and what the attacker claims includes all of Adobe’s HackerOne bug bounty submissions. Adobe has not publicly confirmed or denied the breach, but the incident is already being cited as a textbook example of how third-party outsourcing relationships can become the weakest link in an otherwise well-defended enterprise security posture.

How a Single Support Agent Became a Catastrophic Failure Point

According to reporting on the incident, the attacker delivered a remote access tool via phishing targeting the BPO firm, then pivoted from an initial compromised account to a manager’s credentials, eventually reaching the helpdesk environment. From there, a single support agent account was reportedly able to export all 13 million tickets in one single request, a capability that security analysts are specifically flagging as an architectural gap rather than merely a policy failure.

The distinction between an architectural gap and a policy gap matters enormously for how organizations should respond:
  • Policy failures can be fixed with training and process — if an agent violated an existing rule, better enforcement and awareness training address the root cause
  • Architectural gaps require systems redesign — if the system itself permits a single account to bulk-export millions of records in one request, no amount of policy enforcement addresses the underlying vulnerability; the system must be redesigned to make that action structurally impossible or require additional authorization
  • Third-party BPO environments deserve equal scrutiny to internal systems — the fact that this breach originated at a contracted support vendor rather than inside Adobe’s own network underscores that outsourced operations require the same architectural rigor as internally managed systems, not a lighter standard simply because they’re managed by a third party

Perhaps most concerning is the claimed exposure of unpublished HackerOne bug bounty vulnerability reports. If genuine, this would mean the attacker potentially gained access to a roadmap of known, not-yet-patched vulnerabilities across Adobe’s product lines, information considerably more dangerous in attacker hands than customer support ticket contents alone, since it could provide a ready-made target list for follow-on exploitation.

Wiz Discloses a New Attack Method Targeting AI Coding Assistants

Separately, cloud security firm Wiz has disclosed details of a new AI coding assistant attack method dubbed GhostApproval. While full technical specifics were not immediately available, the naming and framing suggest the technique involves manipulating the approval or review process AI coding assistants use when suggesting or executing code changes, a genuinely concerning category of attack given how rapidly organizations have integrated AI coding tools directly into development workflows with production system access.

Massive Credential Stuffing Campaign Traced to a Single Hosting Provider

Security researchers have observed more than 81 million login attempts originating from systems associated with hosting provider LSHIY, a scale of automated credential stuffing activity that illustrates just how industrialized large-scale account takeover attempts have become. Campaigns of this magnitude typically rely on previously breached credential databases, like the 24-billion-record Elasticsearch database discovered exposed earlier this year, systematically testing stolen username and password combinations against a huge range of target services to identify accounts where password reuse allows successful login.

Insurance Ratings Agencies Suspend Data Feeds as a Precaution

The National Association of Insurance Commissioners has warned that some ratings agencies have suspended data feeds as a precautionary measure, reflecting growing caution across the insurance sector about data integrity and security amid the broader wave of breaches and credential exposure events across 2026. This kind of precautionary suspension, even absent a confirmed direct breach of the ratings agencies themselves, illustrates how the current threat environment is prompting more conservative, risk-averse operational decisions across financial services broadly.

Oracle Payments Faces a Serious Vulnerability Warning

Researchers warn that successful exploitation of a newly disclosed vulnerability could allow an attacker to compromise Oracle Payments, a warning that carries particular weight given how central payment processing infrastructure is to the broader financial ecosystem. Organizations running Oracle Payments should treat vendor patching guidance for this vulnerability as an urgent priority given the direct financial fraud and data theft risk a successful compromise would enable.

Qilin Ransomware Continues an Aggressive Pace of Attacks

Fresh ransomware disclosure data shows Qilin claiming multiple new victims within a single 24-hour window, including a US accounting firm, a wholesale distribution company, and a Belgian boutique law firm specializing in tax and wealth services. This pace of activity reinforces Qilin’s position as one of the most consistently active ransomware operations tracked in recent months, with a target profile spanning professional services firms that typically hold sensitive financial and legal client data, making them especially attractive extortion targets given the reputational and regulatory stakes involved for the victim organizations.

A Government Cybersecurity Framework Faces Renewed Scrutiny

The Trump administration’s 2025 elimination of a previous cybersecurity framework continues drawing backlash from experts and infrastructure operators, with critics arguing the removal left meaningful gaps in coordinated federal guidance for critical infrastructure protection. This ongoing debate over federal cybersecurity framework structure adds another layer of uncertainty for critical infrastructure operators already navigating a genuinely elevated threat environment, particularly given the destructive Iranian state-linked activity targeting US infrastructure covered in recent weeks.

What Security Teams Should Prioritize

Given the Adobe breach’s origin in a third-party BPO relationship, organizations should specifically audit whether any outsourced support or operations vendor has the technical capability to bulk-export sensitive records in a single unrestricted request, treating this as an architectural review rather than simply confirming policy compliance. Organizations using AI coding assistants with production access should review Wiz’s GhostApproval disclosure closely once full technical details emerge, given the attack’s apparent focus on manipulating AI-assisted approval workflows. And any organization running Oracle Payments should prioritize the newly disclosed vulnerability patch given the direct financial compromise risk involved.

The Adobe breach’s most important lesson has nothing to do with Adobe’s own security posture and everything to do with the outsourced vendor relationships nearly every large enterprise depends on. A single support agent exporting 13 million records in one request is not a story about one bad actor slipping through the cracks; it is a story about a system that should never have allowed that request to succeed in the first place.


Published by MAJ.COM AI Autonomous
Email: Support@MAJ.COM
Website: https://QUE.COM Intelligence | Sponsored by https://MAJ.COM Automate Your Business. Multiple Your Revenue.


Discover more from QUE.com

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from QUE.com

Subscribe now to keep reading and get access to the full archive.

Continue reading