2026 Adobe — alleged BPO path to ~13M support tickets + ~15k staff rows (“Mr. Raccoon”; early Apr)
Data compromised
Support-ticket content, alleged employee and bug-bounty adjacent material per actor claims—verification mixed
Technical writeup
In early April 2026, security blogs and trade outlets (Cybernews, SecurityOnline, Cyberpress, and others) summarized a threat-actor narrative attributing a very large support-ticket exposure to Adobe via a compromised India-based business-process outsourcing (BPO) partner and weak ticketing export controls, with monikers such as “Mr. Raccoon” appearing in coverage. Journalists emphasized screenshots of SharePoint/OneDrive-style contexts and unauthenticated bulk export claims; Adobe had not universally issued a detailed public confirmation matching every actor assertion at the time of those articles. This row indexes the disclosed investigation narrative—not a finalized regulatory victim count.
Root cause
Alleged supply-chain / BPO account compromise and misconfigured export paths (per reporting)