Adobe

High

About 152 million Adobe IDs sat in the October 2013 credential file — emails, usernames, poorly encrypted passwords, and plaintext hints. Check whether your address is in that file, then treat any reused password as the first job.

152.4M
Records exposed
2013
Year
4
Data types
Free
To check
Check if you were affected — free

Quick answer — was Adobe breached?

Yes. Adobe was breached in October 2013. This catalog row is about 152 million accounts with email addresses, usernames, encrypted passwords, and plaintext password hints. A match means your address appeared in that credential file. Check if you were affected.

What happened in the Adobe data breach?

In October 2013 Adobe disclosed a break-in that first sounded like a few million customer IDs and encrypted payment cards. Within days, a circulating file showed on the order of 150 million Adobe IDs, usernames, email addresses, encrypted passwords, and plaintext password hints. This catalog row lists about 152.4 million records. The passwords were encrypted with a reversible scheme — not one-way hashed — so identical passwords produced identical ciphertext.

Researchers did not need Adobe’s encryption key to recover a large share of the passwords. They counted how often each ciphertext appeared, matched the most common blobs to the most common passwords, and used the unencrypted hints as extra clues. Those recovered passwords were then useful anywhere the same login had been reused. Adobe also said attackers obtained source code for products including Acrobat, ColdFusion, and some Photoshop code.

Adobe told Krebs on Security it had notified about 38 million active users whose valid encrypted passwords were taken, and that it reset passwords for every Adobe ID it believed was involved — active or not. A later U.S. class action ended with an undisclosed payment to users and about $1.1 million in plaintiffs’ attorney fees. Encrypted payment-card records were part of the original company disclosure; they are not listed in this catalog row’s data types. Learn more about what a data breach means for you.

Why was the Adobe breach so dangerous?

Researchers did not need Adobe’s encryption key to recover a large share of the passwords. They counted how often each ciphertext appeared, matched the most common blobs to the most common passwords, and used the unencrypted hints as extra clues. Those recovered passwords were then useful anywhere the same login had been reused. Adobe also said attackers obtained source code for products including Acrobat, ColdFusion, and some Photoshop code.

Yes, if that 2013 Adobe password was ever reused and has not been changed. The file is old, widely studied, and still useful for credential stuffing. A unique Adobe password plus an authenticator-app second factor is what ages this incident out of your life. Resetting Creative Cloud today does not retire the same string on email or shopping sites.check whether your email was exposed in this breach.

What data was stolen in the Adobe breach?

Email addresses Password hints Passwords Usernames

Email addresses — used for phishing attacks and credential stuffing against your other accounts

Password hints — can be used to access your accounts directly or cracked to reveal your actual password

Passwords — can be used to access your accounts directly or cracked to reveal your actual password

Usernames — used to build profiles and target you with personalised scams

Timeline of the Adobe breach

3 October 2013

Adobe discloses a breach: nearly 3 million encrypted customer payment-card records and an undetermined number of Adobe IDs

October 2013

A large users file circulates — on the order of 150 million IDs, emails, encrypted passwords, and plaintext hints

Late October 2013

Adobe tells Krebs it confirmed about 38 million active users with valid encrypted passwords taken, and that it reset involved Adobe IDs

November 2013

Public analysis of ciphertext frequency and plaintext hints shows large numbers of passwords recoverable without the encryption key

August 2015

A U.S. class action is dismissed after an undisclosed settlement; Adobe is ordered to pay about $1.1 million in plaintiffs’ attorney fees

2013–2026

Recovered Adobe passwords remain in stuffing lists; leftover reused passwords from the file still unlock other sites

Is the Adobe breach still dangerous in 2026?

Yes, if that 2013 Adobe password was ever reused and has not been changed. The file is old, widely studied, and still useful for credential stuffing. A unique Adobe password plus an authenticator-app second factor is what ages this incident out of your life. Resetting Creative Cloud today does not retire the same string on email or shopping sites.

Email addresses and password hints from 2013 do not expire as phishing material. Unique passwords and two-factor authentication are the work. Learn how long stolen data stays dangerous.

Why did “encrypted” Adobe passwords still get recovered?

Hashing a password is meant to be one-way. Encrypting a password is reversible if you have the key — and even without the key, a weak mode can leak patterns. Adobe used a symmetric cipher in a way that made the same password look the same every time. Security writers at the time, including Troy Hunt and contemporaneous cryptography write-ups, treated that as the core mistake.

Plaintext hints made the puzzle easier. A hint such as a pet’s name or a street does not decrypt the blob by itself. It shrinks the guess list. Combined with frequency counts across 150 million rows, researchers recovered enormous numbers of working passwords without ever stealing a master key.

Krebs also reported Adobe’s first disclosure of nearly 3 million encrypted customer credit-card records, and later Adobe’s figure of about 38 million active IDs with valid encrypted passwords. This page follows the catalog row you can look up: emails, usernames, passwords, and hints. It does not claim we hold a separate card file.

  • Encryption here was not hashing. Same password, same ciphertext.
  • Hints were stored in the clear next to those blobs.
  • A match on this page is a credential incident. Fix reuse first.

What does an EmailLeaked Adobe match mean?

If your address is in the 2013 credential file, EmailLeaked shows a named Adobe match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2013 dump, and we do not crawl hidden markets live.

A match is not proof someone is inside your Creative Cloud account this week. It is evidence that the address — and typically a password blob and hint from that era — appeared in a file that has been public for years. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.

If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker. For whether Adobe the company is reasonable to use now, see Is Adobe safe after the data breach?.

What to do if your email was in the Adobe breach

1

Confirm the match and what was listed

Run the email check if you need the named incidents in one list. This Adobe row lists emails, usernames, passwords, and password hints. That is the password playbook.

Check this email — free
2

Treat any reused password as public

Change the password on Adobe and on every site that shared it — starting with email. Then check whether that password appears in known leaks without sending the password itself.

3

Turn on two-factor authentication

Start with email, then your Adobe ID. An authenticator app is stronger than a text-message code. A stuffing bot that has the 2013 password still fails if the second factor is not SMS sitting on a leaked phone number.

4

Follow the after-breach playbook

Use the first-hour and 24-hour lists, then the password playbook. Walk the account security checklist so recovery email, sessions, and leftover logins get a pass.

Open the after-breach playbook
5

Compare how public checkers differ

A second lookup does not change the 2013 file. It can show you how different public indexes present the same named incident.

Read the checker comparison
6

Close Adobe if you no longer use it

Deletion does not unsay the 2013 dump. It stops an old Creative Cloud login and leftover billing from sitting around. Use the official close steps, then lock the inbox that still recovers other accounts.

How to delete your Adobe account

Frequently asked about the Adobe breach

What happened in the Adobe data breach?
In October 2013 attackers copied a large Adobe customer file. This catalog row is about 152 million records with email addresses, usernames, encrypted passwords, and plaintext password hints. Adobe first disclosed nearly 3 million encrypted payment-card records and later said about 38 million active IDs with valid encrypted passwords were involved.
Why were Adobe passwords recovered if they were encrypted?
Adobe stored passwords with reversible encryption in a mode where the same password always produced the same ciphertext. Researchers counted repeated blobs, matched them to common passwords, and used the unencrypted hints. They did not need Adobe’s key to recover a large share of the file.
Was credit card information in this catalog row?
Adobe’s October 2013 disclosure included encrypted debit and credit-card records for a smaller set of customers — Krebs reported nearly 3 million. Adobe said it had no indication of unauthorized activity on those IDs. This lookup row’s listed data types are emails, usernames, passwords, and hints, not cards.
What were the password hints and why did they matter?
Users could store a short reminder next to the encrypted password. Those reminders were in the clear. Combined with ciphertext frequency, they let researchers narrow guesses without a cryptographic break. Hints are still useful to phishers as conversation bait.
How does EmailLeaked show an Adobe match?
As a named row in the email checker, using industry-standard breach data sources. This explainer is the plain-English layer: 2013 credentials, typically emails and passwords, and the next step is killing password reuse. We do not claim exclusive ownership of the file.
I stopped using Adobe after 2013 — should I still act?
Yes, if you reused that password anywhere and have not changed it. The email–password pairs are still in stuffing toolkits. Change every leftover reuse, then use a unique password and two-factor authentication.

How this breach page is reviewed

Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.

Was your email in this breach?

Check if your email appeared in the Adobe breach and 1033+ other known breaches — free, instant, no signup.

Check my email — free

No signup · Under 2 seconds · Never stored

Was my email hacked?

Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.

Check my email now — it's free

No signup required · Results in under 5 seconds · Your data is never stored