Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
On November 10, 2016, attorneys general from 15 U.S. states announced a $1 million settlement with Adobe Systems over the company’s handling of its 2013 data breach. The states alleged that Adobe failed to use reasonable safeguards for customer information and did not promptly detect malicious activity. The agreement required security measures including separating payment-card data from public-facing servers, tokenization, ongoing risk assessments, penetration testing and employee training.
This was a multistate state-attorneys-general settlement—not a federal enforcement action or a new settlement. It also was separate from a private class-action settlement Adobe reached in 2015.
What happened in Adobe’s 2013 breach?
Adobe discovered the intrusion in September 2013 after noticing that a hard drive on an application server was nearly full. Its investigation found that unauthorized parties had accessed customer information and Adobe source code, and had attempted to decrypt encrypted customer payment-card numbers.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Adobe said there was no evidence that unencrypted payment-card numbers had been taken. That distinction matters: the breach involved an attempt to decrypt protected card data, but the available reporting does not establish that attackers obtained usable, unencrypted card numbers.
#1 Best Overall
Contemporaneous reporting said Adobe initially identified about 38 million affected customers. It also cited estimates of more than 150 million compromised records. Those are different measures: a record count is not necessarily a count of unique people, so it would be misleading to describe the latter figure as 150 million customers.
What did the states allege?
The attorneys general alleged that Adobe failed to take reasonable steps to protect customers’ personal information and failed to detect malicious activity promptly. Their concerns included weaknesses that allowed attackers to reach customer and payment-related data. These were allegations resolved through a settlement; the reporting does not establish a court finding that Adobe was liable or that it admitted wrongdoing.
What were the settlement terms?
Adobe agreed to pay $1 million and adopt or strengthen specified security practices. The payment was to be made to attorneys general as designated by Connecticut’s Attorney General’s Office, which led the investigation. The reported terms do not describe the $1 million as a fund for direct payments to individual customers.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteConnecticut was reported to receive $135,095.71. Of that amount, $25,000 was designated for the Department of Consumer Protection’s consumer privacy protection guaranty and enforcement account; the remainder went to the state’s General Fund. The available account does not provide a complete allocation for all participating states, so it should not be assumed that each received an equal share.
The 15 participating states
- Arkansas
- Connecticut
- Illinois
- Indiana
- Kentucky
- Maryland
- Massachusetts
- Minnesota
- Mississippi
- Missouri
- North Carolina
- Ohio
- Oregon
- Pennsylvania
- Vermont
What security measures did Adobe agree to?
- Separate payment-card data from public-facing servers. Segmentation is intended to make it harder for an attacker who compromises an internet-facing system to move into an environment holding sensitive payment information.
- Use tokenization in payment processing. Tokenization substitutes a token for a card number, reducing the usefulness of exposed data. It does not, by itself, protect other customer information or eliminate the possibility of a breach.
- Conduct continuing risk assessments. Assessments can identify changing technical and organizational weaknesses, but their value depends on tracking and addressing the findings.
- Perform penetration testing. Testing can reveal exploitable weaknesses, but it is periodic and cannot guarantee that a system is secure.
- Provide employee security training. Training can help address risks such as phishing, credential misuse and delayed incident reporting; it complements rather than replaces technical safeguards.
These measures describe the controls reported as settlement requirements. They should not be read as proof that Adobe later maintained compliance with every requirement or that the controls prevented subsequent incidents.
Was this the only financial consequence?
No. Adobe had also reached a private class-action settlement in 2015 involving affected users. Contemporaneous reporting described the settlement amount as undisclosed and said Adobe had agreed to pay about $1.2 million in legal fees. That private case was separate from the states’ $1 million agreement; the figures should not be combined as if they were one settlement or treated as a direct customer-reimbursement total.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why the settlement is relevant
The case illustrates that a breach can draw regulatory scrutiny over both prevention and detection, even where the company reported no evidence that unencrypted payment-card numbers were exfiltrated. It also shows that a resolution can require operational security changes, not just a monetary payment. The agreement’s existence does not establish the precise technical cause of the breach, a definitive count of unique victims, or the effectiveness of Adobe’s later security practices.
For the contemporaneous account of the announcement, allegations, state list and reported terms, see SecurityWeek’s coverage of the Adobe settlement.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

