A threat actor using the alias "Mr. Raccoon" has allegedly breached Adobe support systems through a third-party Indian BPO contractor and claims to have stolen a large cache of sensitive data. According to unverified reports and social media posts, the actor first compromised a contractor employee with a malicious email delivering a remote access trojan, then expanded access by phishing the employee’s manager. The attacker says the intrusion exposed more than 13 million support ticket records, roughly 15,000 employee records, internal documents, Adobe’s Microsoft SharePoint environment, and submissions from Adobe’s HackerOne bug bounty program.
The reports further allege the actor abused overly permissive ticket export functionality that allowed bulk extraction of support data in a single request, raising concerns about phishing, identity theft, and exposure of unpublished vulnerability disclosures. The incident, if confirmed, would represent a significant third-party supply chain compromise affecting Adobe’s support operations. Adobe had not publicly confirmed or denied the claims at the time the reports were published.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Google Threat Intelligence Group reported that UNC6783 is targeting business process outsourcing providers to steal corporate Zendesk support tickets and access downstream victims using phishing, helpdesk manipulation, fake Okta pages, and remote access malware. GTIG assessed UNC6783 may be linked to the Raccoon persona associated with attacks on multiple BPOs, including the unconfirmed Adobe-related claim.
Google Threat Intelligence Group reported that UNC6783, potentially linked to the Raccoon persona, targeted several dozen high-value companies by exploiting BPOs, helpdesks, and support workflows. After stealing data through phishing, spoofed Okta pages, device enrollment abuse, and occasional remote access malware, the actor sent Proton Mail ransom notes as part of data-theft extortion operations.
Researchers from vx-underground said the alleged Adobe breach appeared plausible but may have been confined to the helpdesk environment rather than Adobe's full corporate network. The reporting also cited analyst suspicion that initial access may have involved a remote access trojan delivered by malicious email.
At the time the claims were reported, Adobe had not publicly confirmed or denied the alleged incident. Coverage emphasized that the breach details remained unverified pending an official response.
Unverified reports said a threat actor calling himself 'Mr. Raccoon' claimed to have compromised Adobe support operations through an Indian BPO contractor. The alleged haul included 13 million support tickets, about 15,000 employee records, access to Adobe SharePoint and HackerOne data, and internal documents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcego.theregister.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceaustinlarsen.me
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.