What reportedly happened
Earlier this year, a threat actor going by "Mr. Raccoon" reportedly broke into Adobe through an outsourced customer support contractor based in India. According to reporting from International Cyber Security News, the attacker phished their way onto a support computer. From there, they worked their way up to a manager-level account inside the helpdesk system.
From there, they found something that mattered more than the initial break-in: a single support agent's login was able to export every open support ticket in one request. Reports put the total at around 13 million customer support tickets and roughly 15,000 employee records. It also included every submission Adobe had received through its bug bounty program, details of security flaws that hadn't been patched yet. Adobe hasn't publicly confirmed or denied the incident.
Why this isn't really an "Adobe" story
The technical break-in here wasn't sophisticated. Phishing one person to get a foothold, then finding an account with too much reach. It's a pattern that shows up in breach reports every single month, at companies of every size. The 2026 monthly breach tracker published by data-security vendor PKWARE lists similar cases: banks, insurers, a cruise line, a major dental benefits administrator. In almost every one, the attacker didn't need to be clever. They just needed one account that could see more than it should.
Most small clinics, firms and practices we work with have a version of this same setup somewhere. A shared reception login. A bookkeeper account with access to every client's file. An admin user set up years ago and never revisited. It's rarely a decision anyone made deliberately. It's just what happens when a system grows without anyone stopping to ask who actually needs to see what.
What actually reduces this risk
None of the fixes here are exotic. Give each person their own login instead of a shared one, so access can be limited and traced properly. Review what each account can actually reach, particularly anything that can export or download in bulk. And remove access properly and promptly when someone leaves, rather than letting old accounts sit there unused.
The Adobe case is a useful reminder for a different reason too: it wasn't the initial phishing email that turned a bad afternoon into a 13-million-record problem. It was what that one compromised login was allowed to do next.
