About 152 million Adobe IDs sat in the October 2013 credential file — emails, usernames, poorly encrypted passwords, and plaintext hints. Check whether your address is in that file, then treat any reused password as the first job.
Quick answer — was Adobe breached?
Yes. Adobe was breached in October 2013. This catalog row is about 152 million accounts with email addresses, usernames, encrypted passwords, and plaintext password hints. A match means your address appeared in that credential file. Check if you were affected.
What happened in the Adobe data breach?
In October 2013 Adobe disclosed a break-in that first sounded like a few million customer IDs and encrypted payment cards. Within days, a circulating file showed on the order of 150 million Adobe IDs, usernames, email addresses, encrypted passwords, and plaintext password hints. This catalog row lists about 152.4 million records. The passwords were encrypted with a reversible scheme — not one-way hashed — so identical passwords produced identical ciphertext.
Researchers did not need Adobe’s encryption key to recover a large share of the passwords. They counted how often each ciphertext appeared, matched the most common blobs to the most common passwords, and used the unencrypted hints as extra clues. Those recovered passwords were then useful anywhere the same login had been reused. Adobe also said attackers obtained source code for products including Acrobat, ColdFusion, and some Photoshop code.
Adobe told Krebs on Security it had notified about 38 million active users whose valid encrypted passwords were taken, and that it reset passwords for every Adobe ID it believed was involved — active or not. A later U.S. class action ended with an undisclosed payment to users and about $1.1 million in plaintiffs’ attorney fees. Encrypted payment-card records were part of the original company disclosure; they are not listed in this catalog row’s data types. Learn more about what a data breach means for you.
Why was the Adobe breach so dangerous?
Researchers did not need Adobe’s encryption key to recover a large share of the passwords. They counted how often each ciphertext appeared, matched the most common blobs to the most common passwords, and used the unencrypted hints as extra clues. Those recovered passwords were then useful anywhere the same login had been reused. Adobe also said attackers obtained source code for products including Acrobat, ColdFusion, and some Photoshop code.
Yes, if that 2013 Adobe password was ever reused and has not been changed. The file is old, widely studied, and still useful for credential stuffing. A unique Adobe password plus an authenticator-app second factor is what ages this incident out of your life. Resetting Creative Cloud today does not retire the same string on email or shopping sites.check whether your email was exposed in this breach.
What data was stolen in the Adobe breach?
Email addresses — used for phishing attacks and credential stuffing against your other accounts
Password hints — can be used to access your accounts directly or cracked to reveal your actual password
Passwords — can be used to access your accounts directly or cracked to reveal your actual password
Usernames — used to build profiles and target you with personalised scams
Timeline of the Adobe breach
3 October 2013
Adobe discloses a breach: nearly 3 million encrypted customer payment-card records and an undetermined number of Adobe IDs
October 2013
A large users file circulates — on the order of 150 million IDs, emails, encrypted passwords, and plaintext hints
Late October 2013
Adobe tells Krebs it confirmed about 38 million active users with valid encrypted passwords taken, and that it reset involved Adobe IDs
November 2013
Public analysis of ciphertext frequency and plaintext hints shows large numbers of passwords recoverable without the encryption key
August 2015
A U.S. class action is dismissed after an undisclosed settlement; Adobe is ordered to pay about $1.1 million in plaintiffs’ attorney fees
2013–2026
Recovered Adobe passwords remain in stuffing lists; leftover reused passwords from the file still unlock other sites
Is the Adobe breach still dangerous in 2026?
Yes, if that 2013 Adobe password was ever reused and has not been changed. The file is old, widely studied, and still useful for credential stuffing. A unique Adobe password plus an authenticator-app second factor is what ages this incident out of your life. Resetting Creative Cloud today does not retire the same string on email or shopping sites.
Email addresses and password hints from 2013 do not expire as phishing material. Unique passwords and two-factor authentication are the work. Learn how long stolen data stays dangerous.
Why did “encrypted” Adobe passwords still get recovered?
Hashing a password is meant to be one-way. Encrypting a password is reversible if you have the key — and even without the key, a weak mode can leak patterns. Adobe used a symmetric cipher in a way that made the same password look the same every time. Security writers at the time, including Troy Hunt and contemporaneous cryptography write-ups, treated that as the core mistake.
Plaintext hints made the puzzle easier. A hint such as a pet’s name or a street does not decrypt the blob by itself. It shrinks the guess list. Combined with frequency counts across 150 million rows, researchers recovered enormous numbers of working passwords without ever stealing a master key.
Krebs also reported Adobe’s first disclosure of nearly 3 million encrypted customer credit-card records, and later Adobe’s figure of about 38 million active IDs with valid encrypted passwords. This page follows the catalog row you can look up: emails, usernames, passwords, and hints. It does not claim we hold a separate card file.
- Encryption here was not hashing. Same password, same ciphertext.
- Hints were stored in the clear next to those blobs.
- A match on this page is a credential incident. Fix reuse first.
What does an EmailLeaked Adobe match mean?
If your address is in the 2013 credential file, EmailLeaked shows a named Adobe match the same way it shows any other named incident. The row is a lookup against industry-standard breach data sources. We do not claim an exclusive copy of the 2013 dump, and we do not crawl hidden markets live.
A match is not proof someone is inside your Creative Cloud account this week. It is evidence that the address — and typically a password blob and hint from that era — appeared in a file that has been public for years. A miss is a snapshot of the records we can search today. We do not keep the address you type into the checker. Hosting logs and a privacy-oriented analytics beacon can still record that the page was visited.
If you want the response order in one place, use what to do after a data breach. If you want to test a reused password without sending the full password, use the password leak checker. For whether Adobe the company is reasonable to use now, see Is Adobe safe after the data breach?.
What to do if your email was in the Adobe breach
Confirm the match and what was listed
Run the email check if you need the named incidents in one list. This Adobe row lists emails, usernames, passwords, and password hints. That is the password playbook.
Check this email — freeTreat any reused password as public
Change the password on Adobe and on every site that shared it — starting with email. Then check whether that password appears in known leaks without sending the password itself.
Turn on two-factor authentication
Start with email, then your Adobe ID. An authenticator app is stronger than a text-message code. A stuffing bot that has the 2013 password still fails if the second factor is not SMS sitting on a leaked phone number.
Follow the after-breach playbook
Use the first-hour and 24-hour lists, then the password playbook. Walk the account security checklist so recovery email, sessions, and leftover logins get a pass.
Open the after-breach playbookCompare how public checkers differ
A second lookup does not change the 2013 file. It can show you how different public indexes present the same named incident.
Read the checker comparisonClose Adobe if you no longer use it
Deletion does not unsay the 2013 dump. It stops an old Creative Cloud login and leftover billing from sitting around. Use the official close steps, then lock the inbox that still recovers other accounts.
How to delete your Adobe accountFrequently asked about the Adobe breach
What happened in the Adobe data breach?
Why were Adobe passwords recovered if they were encrypted?
Was credit card information in this catalog row?
What were the password hints and why did they matter?
How does EmailLeaked show an Adobe match?
I stopped using Adobe after 2013 — should I still act?
How this breach page is reviewed
Breach pages are built from structured breach records and reviewed for practical risk guidance by EmailLeaked. Risk labels reflect exposed data types and are intended to help readers prioritise action.
Sources
Last updated: September 2026
Other major breaches
Was your email in this breach?
Check if your email appeared in the Adobe breach and 1033+ other known breaches — free, instant, no signup.
Check my email — freeWas my email hacked?
Check if your email is compromised in seconds. Free, private, no signup. Scan millions of breach records across 1034+ known breaches.
Check my email now — it's freeNo signup required · Results in under 5 seconds · Your data is never stored