Back to Blog
critical severity October 04, 2013 · 3 min read

Adobe — 153 Million Accounts, and a Password Scheme That Became a Crossword (2013)

If you have an account with Adobe, here’s what’s now in circulation.

Adobe did not hash its passwords. It encrypted them with 3DES in ECB mode, which produces identical output for identical input — and then leaked the plaintext password hints alongside. The two together let researchers read passwords off the dump like a crossword.

Repeating identical ciphertext blocks beside plaintext hints

What happened

In October 2013, 152,445,165 Adobe accounts were breached. Each record contained an internal ID, a username, an email address, an encrypted password and — the detail that made this breach famous — a password hint stored in plain text.

Caught in this breach?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

The mistake was using encryption at all

Passwords are supposed to be hashed: transformed by a one-way function so that even the company storing them cannot read them back. Adobe instead encrypted them, with Triple DES in ECB mode. Encryption is two-way by design, so anyone who obtained the key could read every password directly.

Nobody needed the key. ECB — Electronic Codebook — has the property that identical plaintext always produces identical ciphertext. Every account that used the same password produced the same encrypted block, in a dump of 153 million rows. That turns the dataset into a frequency-analysis puzzle: the most common block is almost certainly the most common password.

And then the hints. The plaintext hints were attached to those blocks, so every user who wrote something like "my dog's name" was contributing a clue about a password shared with everyone else holding the same ciphertext. Researchers, including analyses by Sophos and commentary from Bruce Schneier, recovered large portions of the password set by cross-referencing repeated blocks against pooled hints — no key required.

Why this one keeps mattering

Adobe accounts were not optional for a whole profession. Anyone who used Photoshop, Illustrator, InDesign or Acrobat between the mid-2000s and 2013 had one, frequently registered with a work address and frequently shared across a studio or team. It is one of the few breaches on this list where the affected population is defined by occupation rather than by pastime.

Because so much of the password set was recovered in readable form, this dump became foundational training data for password-guessing tools. Its influence outlived the accounts by a wide margin: the patterns it revealed shaped how cracking software prioritises candidates to this day.

The identity-chain implication

Password hints are, in effect, leaked answers to security questions. "Mother's maiden name", "street I grew up on", "first pet" — the hint field collected exactly the facts that account-recovery flows still use to verify identity, and published them in the clear.

That is why this breach reaches beyond Adobe. A recovered hint does not just reveal an Adobe password; it can answer the recovery question guarding an email account, a bank or a domain registrar more than a decade later, because none of those facts ever changed.

What to do now

What You Should Do

  1. Change any password resembling your 2013 Adobe one — the scheme leaked passwords in recoverable form, not merely hashed ones
  2. Change your security-question answers wherever the hint you wrote in 2013 would still answer them, and use random strings rather than true facts
  3. Check work as well as personal addresses — Adobe accounts were overwhelmingly registered professionally
  4. Enable 2FA on your Adobe account and on the email address behind it
  5. Never fill in an optional password-hint field again; this breach is the reason the pattern was abandoned

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Were you a Adobe customer?
Adobe is one breach. Your email is probably in others.
152.4M accounts accounts were exposed here. Check whether yours is one — and find every other leak tied to the same address, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Critical
Disclosed October 04, 2013
Last reviewed July 22, 2026
Affected 152.4M accounts
Data exposed Email addressesUsernamesPasswordsPassword hints
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email