Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

15 States Reach $1 Million Settlement With Adobe Over 2013 Breach

By TheFinanceBase Team3 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On November 10, 2016, attorneys general from 15 U.S. states announced a $1 million settlement with Adobe Systems over the company’s handling of its 2013 data breach. The states alleged that Adobe failed to use reasonable safeguards for customer information and did not promptly detect malicious activity. The agreement required security measures including separating payment-card data from public-facing servers, tokenization, ongoing risk assessments, penetration testing and employee training.

This was a multistate state-attorneys-general settlement—not a federal enforcement action or a new settlement. It also was separate from a private class-action settlement Adobe reached in 2015.

What happened in Adobe’s 2013 breach?

Adobe discovered the intrusion in September 2013 after noticing that a hard drive on an application server was nearly full. Its investigation found that unauthorized parties had accessed customer information and Adobe source code, and had attempted to decrypt encrypted customer payment-card numbers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Adobe said there was no evidence that unencrypted payment-card numbers had been taken. That distinction matters: the breach involved an attempt to decrypt protected card data, but the available reporting does not establish that attackers obtained usable, unencrypted card numbers.

Contemporaneous reporting said Adobe initially identified about 38 million affected customers. It also cited estimates of more than 150 million compromised records. Those are different measures: a record count is not necessarily a count of unique people, so it would be misleading to describe the latter figure as 150 million customers.

What did the states allege?

The attorneys general alleged that Adobe failed to take reasonable steps to protect customers’ personal information and failed to detect malicious activity promptly. Their concerns included weaknesses that allowed attackers to reach customer and payment-related data. These were allegations resolved through a settlement; the reporting does not establish a court finding that Adobe was liable or that it admitted wrongdoing.

What were the settlement terms?

Adobe agreed to pay $1 million and adopt or strengthen specified security practices. The payment was to be made to attorneys general as designated by Connecticut’s Attorney General’s Office, which led the investigation. The reported terms do not describe the $1 million as a fund for direct payments to individual customers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connecticut was reported to receive $135,095.71. Of that amount, $25,000 was designated for the Department of Consumer Protection’s consumer privacy protection guaranty and enforcement account; the remainder went to the state’s General Fund. The available account does not provide a complete allocation for all participating states, so it should not be assumed that each received an equal share.

The 15 participating states

  1. Arkansas
  2. Connecticut
  3. Illinois
  4. Indiana
  5. Kentucky
  6. Maryland
  7. Massachusetts
  8. Minnesota
  9. Mississippi
  10. Missouri
  11. North Carolina
  12. Ohio
  13. Oregon
  14. Pennsylvania
  15. Vermont

What security measures did Adobe agree to?

  • Separate payment-card data from public-facing servers. Segmentation is intended to make it harder for an attacker who compromises an internet-facing system to move into an environment holding sensitive payment information.
  • Use tokenization in payment processing. Tokenization substitutes a token for a card number, reducing the usefulness of exposed data. It does not, by itself, protect other customer information or eliminate the possibility of a breach.
  • Conduct continuing risk assessments. Assessments can identify changing technical and organizational weaknesses, but their value depends on tracking and addressing the findings.
  • Perform penetration testing. Testing can reveal exploitable weaknesses, but it is periodic and cannot guarantee that a system is secure.
  • Provide employee security training. Training can help address risks such as phishing, credential misuse and delayed incident reporting; it complements rather than replaces technical safeguards.

These measures describe the controls reported as settlement requirements. They should not be read as proof that Adobe later maintained compliance with every requirement or that the controls prevented subsequent incidents.

Was this the only financial consequence?

No. Adobe had also reached a private class-action settlement in 2015 involving affected users. Contemporaneous reporting described the settlement amount as undisclosed and said Adobe had agreed to pay about $1.2 million in legal fees. That private case was separate from the states’ $1 million agreement; the figures should not be combined as if they were one settlement or treated as a direct customer-reimbursement total.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the settlement is relevant

The case illustrates that a breach can draw regulatory scrutiny over both prevention and detection, even where the company reported no evidence that unencrypted payment-card numbers were exfiltrated. It also shows that a resolution can require operational security changes, not just a monetary payment. The agreement’s existence does not establish the precise technical cause of the breach, a definitive count of unique victims, or the effectiveness of Adobe’s later security practices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the contemporaneous account of the announcement, allegations, state list and reported terms, see SecurityWeek’s coverage of the Adobe settlement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.