The company did not find it first. About a week before the announcement, Brian Krebs and Alex Holden of Hold Security came across a forty-gigabyte hoard of source code sitting on a server used by criminals — ColdFusion and Adobe Acrobat, compiled and uncompiled — and took it to Adobe. The notice went up on 3 October 2013 over the name of Brad Arkin, the company's chief security officer, who said afterwards that what he had been shown had steered the investigation in a new direction. Three dates are usually collapsed into one here and should not be. The code appears to have been taken in mid-August; an alert about an application server's disk filling up in September led to the discovery; the disclosure came on 3 October.

The first figure Adobe gave was 2.9 million customers whose names, encrypted card numbers, expiry dates and order details had been reached, with the company saying it did not believe decrypted card numbers had been removed. It did not hold. On 29 October a spokeswoman, Heather Edell, told KrebsOnSecurity that the attackers had obtained Adobe IDs and encrypted passwords for "approximately 38 million active users". By then a 3.8-gigabyte archive named users.tar.gz had been posted on AnonNews carrying more than 150 million username and password pairs, and a second file held Photoshop source code, which Adobe confirmed had been accessed in part. A fortnight earlier, credentials belonging to PR Newswire customers had turned up on the same servers.

What made the file a permanent artefact was how the passwords had been kept. They were not hashed. They were encrypted with Triple DES in electronic codebook mode, in eight-byte blocks, under a single key used for every account — so identical passwords produced identical ciphertext for every person who chose them, and the block boundaries gave away the length. Beside each record sat that user's own password hint, unencrypted. Jeremi Gosney of Stricture Consulting Group worked out the hundred commonest passwords in roughly three hours; close to two million accounts had used 123456. On 4 November the xkcd strip Encryptic drew the wreckage as a crossword, which was the point: no cracking was required, only reading.

The endings came slowly and were much smaller than the breach. A class action filed in California in November 2013 survived Adobe's motion to dismiss before Judge Lucy Koh and settled in August 2015, the customer terms undisclosed, with $1.2 million going to the plaintiffs' lawyers in fees and costs. On 10 November 2016 fifteen state attorneys general announced that Adobe had settled with them for $1 million; the Massachusetts attorney general's account described intruders compromising a public-facing web server and using it to reach others on the network. Have I Been Pwned loaded the dataset on 4 December 2013 and still lists 152.4 million accounts, which is the number that turned password reuse from an argument into a lookup.

Also that month · 1–2 October

The laptop left open

Ross Ulbricht was arrested on the afternoon of Tuesday 1 October 2013 at the Glen Park branch of the San Francisco Public Library. Two agents staged a quarrel behind him; when he turned, a third lifted the laptop out from under his hands, still unlocked, and a flash drive was used to copy what was on it before anything could be closed or encrypted. Silk Road went dark the next day behind a seizure banner. The trail that led there was older and duller than the arrest: a forum account called altoid had promoted the site in its first weeks and later posted a message carrying Ulbricht's own Gmail address. He was convicted on 4 February 2015 of running a continuing criminal enterprise and of narcotics, money-laundering and computer-hacking conspiracies, and sentenced on 29 May 2015 to double life imprisonment plus forty years without parole. The FBI's account of how it located the server — a leak through the site's CAPTCHA — was doubted by researchers at the time and never settled. On 21 January 2025 President Donald Trump granted him a full and unconditional pardon.

Also that month · 12–30 October

A smiley face on a slide

On 12 October Craig Heffner published his reverse engineering of several D-Link routers: any request whose user-agent string read xmlset_roodkcableoj28840ybtide reached the administrative interface without a password. Read backwards, the tail of that string is edit by 04882 joel backdoor. Several model families shared the firmware; fixes appeared only in December. Between 22 and 24 October php.net served an altered userprefs.js that pushed visitors at an exploit kit, and Google's Safe Browsing service blacklisted the site before the project confirmed two servers compromised. On 30 October Barton Gellman and Ashkan Soltani reported in the Washington Post that the NSA, with GCHQ, was collecting from the private fibre links between Google's and Yahoo's data centres under a programme called MUSCULAR — 181,280,466 records in a month. One document was a hand-drawn sketch of where the public internet met the Google cloud, marked to show that encryption was added and removed at that point, a smiley face beside it. David Drummond, Google's chief legal officer, said the company was "outraged"; the NSA said it was a foreign intelligence agency pursuing valid foreign targets. Encryption of those internal links was announced within days.

India desk · October 2013

Fifth on the map, and quiet about it

India had been told, in late September, roughly what had been done to it. The Hindu, working with Glenn Greenwald on documents from Edward Snowden, reported that the NSA had listed India among its priority targets and had used techniques codenamed Lifesaver and Vagrant — one imaging hard drives, the other lifting what was on a screen — against India's embassy in Washington and its mission to the United Nations. The external affairs ministry spokesman, Syed Akbaruddin, called the reports disconcerting and said they would be raised with Washington. Boundless Informant material published by the Guardian in June had already placed India fifth by volume of data collected, on the Centre for Internet and Society's reading of 13 June 2013; the external affairs minister, Salman Khurshid, had defended the programme when that reporting appeared, saying it was "not scrutiny and access to actual messages" but computer analysis of patterns of calls and emails, and so "not snooping". Through October, while other capitals protested loudly, Delhi added almost nothing.

Part of the reason sat at home. The Central Monitoring System, announced in 2009 and rolled out state by state from April 2013, was designed to let the state intercept telephone and internet traffic directly, without going through the operators; nine central agencies were empowered to intercept, and there was no privacy statute to set against any of it. What India did do was narrow: on 30 August 2013 the electronics and information technology secretary, J Satyanarayana, said five hundred thousand officials would be moved off Gmail onto National Informatics Centre accounts, because "Gmail data of Indian users resides in other countries as the servers are located outside". Nothing in Indian law that October obliged anyone to tell an Adobe customer in Pune that their password hint was public. That came in 2022 by direction, in CERT-In's six-hour rule, and in 2023 by statute, in the DPDP Act.

AI Tech desk · October 2013

A Billion Euros for the Brain

Europe began the month by committing to simulate the thing nobody could yet describe. The Human Brain Project started on 1 October 2013 as one of the European Commission's two Future and Emerging Technologies flagships, with a headline budget of a billion euros over ten years, half from the Commission and half from national and private sources, and a stated aim of building research infrastructure for brain science, cognitive neuroscience and brain-inspired computing. What it delivered over the decade that followed was atlases, simulation tools and shared infrastructure rather than the simulated brain its launch implied, and the gap between the two became a standing argument about how to fund ambitious science. The month's other move was small and commercial: on 23 October Yahoo bought LookFlow, a handful of engineers working on image recognition, folded them into Flickr and said it would build a deep-learning group around them. Google's fuller account of the embedding method it had released in July also appeared on arXiv on 16 October.

Digital Guard desk · October 2013

What Cisco Got With Sourcefire

Cisco completed its purchase of Sourcefire on 7 October 2013, a deal announced in July and worth about $2.7 billion. What it bought was mostly network equipment — the FirePOWER appliances and Snort, the intrusion detection system Martin Roesch had written and Sourcefire had been built around — but it also included two pieces of the endpoint: ClamAV, the open-source scanner Sourcefire had taken on in 2007, and FireAMP, the agent that had come out of the Immunet acquisition in 2011. Roesch became chief architect of Cisco's security group, and the Sourcefire research team was folded, the following year, into what Cisco named Talos. Three weeks later, on 28 October, the FBI's Internet Crime Complaint Center issued a public service announcement about CryptoLocker, the file-encrypting ransomware that had appeared in September; an agent could remove it and still leave every document unreadable. FireAMP is sold today as Cisco Secure Endpoint, and the problem that announcement described set the endpoint industry's agenda for the decade that followed.

⏳ Time capsule — October 2013

  • The United States federal government shut down on 1 October for sixteen days, with about 800,000 employees furloughed indefinitely; it reopened after the Continuing Appropriations Act, 2014 was signed shortly after midnight on 17 October.
  • On 11 October the Norwegian Nobel Committee gave the Peace Prize to the Organisation for the Prohibition of Chemical Weapons, for its work to eliminate chemical weapons.
  • On the night of 12 October Cyclone Phailin came ashore near Gopalpur in Odisha; more than 550,000 people had been moved off the coast in Odisha and Andhra Pradesh beforehand, the largest such evacuation in India in twenty-three years, and 46 people died.
  • On 27 October the Indian Grand Prix was run at the Buddh International Circuit in Greater Noida; Sebastian Vettel won and took his fourth consecutive title. No Indian Grand Prix has been held since.
Where it stands today — 2026

Still in the wordlists

Thirteen years on, the October 2013 file is still doing work. It sits in Have I Been Pwned, in the wordlists auditors run against new systems, and in the credential-stuffing sets behind the same argument this archive returns to in May 2015 and May 2016: a password given to one company has been given to every company the same person uses. The settlements were the small part of it. What changed was storage. Encrypting a password reversibly, under one key, in a mode that repeats, became the textbook example of what not to do; per-user salts and a deliberately slow hash are now the floor, and the user-supplied password hint — the field that did most of the damage here — has quietly disappeared from sign-up forms.

The rest of the month aged into practice as well. Private links between a provider's own data centres are encrypted as a matter of course in 2026, a change Google and Yahoo announced within weeks of the MUSCULAR reporting and the rest of the industry copied; unencrypted internal transit would now be written up as a finding rather than a design. Ulbricht's open laptop became the fixed illustration in every operational-security lecture, and seizure technique was rebuilt around the assumption that a running machine is the only version investigators will ever get — a point untouched by the pardon of 21 January 2025. And in India the distance between an incident and anyone being told closed by direction in 2022 and by statute in 2023.