Lucian Constantin
CSO Senior Writer

Adobe confirms breach of Connectusers.com forum database, shuts down website

news
Nov 14, 20122 mins

Adobe is in the process of resetting the passwords of all Connectusers.com forum users

Adobe has shut down Connectusers.com, a community forum site for users of its Adobe Connect Web conferencing platform, because the site’s user database was compromised.

On Tuesday, a hacker named “ViruS_HimA” claimed that he hacked into “one of Adobe’s servers” and copied a database containing email addresses, password hashes and other information of over 150,000 Adobe customers, partners, and employees.

[ Learn how to greatly reduce the threat of malicious attacks with InfoWorld’s Insider Threat Deep Dive PDF special report. | Stay up to date on the latest security developments with InfoWorld’s Security Central newsletter. ]

To support his claim, the hacker published a limited set of records for users with email addresses ending in adobe.com, .mil, and .gov.

“As soon as we became aware of the hacker’s post, we launched our investigation, which (based on the information leaked by the hacker) led us to determine that the hacker appears to have compromised the Connectusers.com forum site,” said Wiebke Lips, Adobe’s senior manager of corporate communications, Wednesday via email.

The hacker leaked 644 records, but he claimed to have accessed the entire forum database, Lips said. “The forum has a total of about 150,000 registered users.”

“We are in the process of resetting the passwords of impacted Connectusers.com forum members and will reach out to those members with instructions on how to set up new passwords once the forum services are restored,” Lips said.

The forum site was taken offline Tuesday evening, said Guillaume Privat, director of Adobe Connect, Wednesday in a blog post. “It does not appear that any other Adobe services, including the Adobe Connect conferencing service itself, were impacted,” he said.

Privat recommended that users should follow password best practices and use different log-in credentials across different services. However, as other data leaks have shown in the past, a lot of users don’t do this, which could allow hackers to break into their accounts on many other websites.

Based on an analysis of the leaked data, the password hashes — encrypted versions of the passwords — stored in the compromised Adobe database had been generated with MD5, a cryptographic hash function that’s known to be insecure, said Tal Beery, a security researcher at security firm Imperva, via email. This means that they can easily be cracked to recover the original passwords, he said.

Lucian Constantin

Lucian Constantin writes about information security, privacy, and data protection for CSO. Before joining CSO in 2019, Lucian was a freelance writer for VICE Motherboard, Security Boulevard, Forbes, and The New Stack. Earlier in his career, he was an information security correspondent for the IDG News Service and Information security news editor for Softpedia.

Before he became a journalist, Lucian worked as a system and network administrator. He enjoys attending security conferences and delving into interesting research papers. He lives and works in Romania.

You can reach him at lucian_constantin@foundryco.com or @lconstantin on X. For encrypted email, his PGP key's fingerprint is: 7A66 4901 5CDA 844E 8C6D 04D5 2BB4 6332 FC52 6D42

More from this author