On March 1, 2012, FBI Director Robert Mueller said in a speech: “There are only two types of companies: those that have been hacked and those that will be”. The hack of Adobe’s internal database and its exposure on hacking forums affiliated with cybercriminals sits well with this statement and can mean only one thing – the worst is yet to come.
It all began in early October 2013, when Adobe reported the breach of more than three million customer accounts, including email addresses and password-identifying hints. This number has now been reassessed as approximately 150 million account details that have been released online, just waiting to be exploited and misused. We have talked to almost a hundred entities (governments, corporates, and individuals) and shared with them exposed data pertaining to them.
Very few have acted on the information. Most replies resembled: “What’s this? I haven’t heard of this. Why should I care?”; “I don’t recall ever having signed up for their service”; “Heard of that – isn’t this Adobe’s problem?”; “So they have some email addresses, so what?”. I assume you get the picture. However, not one CISO has refused to hear us out, meaning that at least they recognize the importance of the leaked data. This indicates two things: first, there is a need for an intelligence mechanism to alert these organizations. And second, there is a lack of awareness regarding the threats represented by this incident.
The consequences for the short-term could be identity theft, attempts to takeover email accounts, credit card theft (since those details were also stolen), infecting computer systems via spear-phishing attacks and using the infected machines to launch a massive APT campaign. We strongly recommend that the exposed accounts be dealt with promptly, and we further advise that the account owners be contacted, advised of the breach and warned of the likelihood of their being targeted by cybercriminals. They should therefore heighten their level of alertness, refuse to open attachments from unknown entities under any circumstances and change their passwords immediately.
Moreover, we estimate that users who left their credit card details on Adobe’s website will be vulnerable to financial fraud in the short and medium-term, and we recommend that they take immediate steps to cancel their credit cards and have new ones issued. But if that were not enough bad news – and believe me it is – the attackers also succeeded in stealing the source code for several Adobe products.
Adobe’s Acrobat Reader, for example, is installed on most PC’s and company computers in the world. The theft of the source code enables the execution of the following actions: Studying the code, finding a backdoor and exploiting it to infiltrate computers and companies worldwide; Exploiting the exposed products’ encrypted algorithms in order to monitor and collect information on PDF files across the network; Utilizing the source code to make and spread copies, ostensibly authorized by Adobe, containing Trojan horses. The Adobe hack, which is probably the largest in history, might be considered the Stuxnet of the cybercrime domain. This, combined with the lack of intelligence and low awareness of the possible dangers, makes it a lot easier for cybercriminals to exploit.
The Adobe breach brings the FBI Director’s warning closer to reality, as he predicted that in the future we will live in a world where there remains only one type of company: those that have been hacked and will be hacked again. The only question which remains to be seen is weather organization will develop the appropriate intelligence and response mechanism to cope with future breaches.
***
Gilad Zahavi works as a Cyber Intelligence Team Leader at Terrogence
