In early 2026, one of the world’s largest software companies, Adobe was reportedly breached. The attackers didn’t smash through a firewall or crack a clever piece of code. They sent an email. One person clicked. And that single click began a chain of events that allegedly exposed around 13 million customer records.
It’s a striking reminder of something we tell our clients often: the front line of your security isn’t your technology. It’s your people, and the people your suppliers rely on too.
What actually happened
The attacker, operating under an alias, never touched the software company’s own systems directly. Instead, they targeted a third-party support contractor the company had hired to handle customer service.
It unfolded in stages. A phishing email was sent to one employee at that contractor. Opening it silently installed a hidden tool that gave the attacker control of the employee’s computer. From there, the attacker studied how that person worked, then used their identity to send a convincing email to their manager. The manager was fooled too, and that second compromise handed over the deeper access needed to reach the customer support system. Once inside, a weakness in that system let the attacker quietly download millions of records without setting off any alarms.
No advanced hacking. No exotic software. Just a carefully exploited chain of human trust.
What was exposed
According to the attacker, the stolen information included roughly 13 million customer support tickets, containing names, email addresses, phone numbers and the full content of people’s support conversations. The company has not officially confirmed the breach, but independent security researchers believe it is genuine and that anyone who had contacted the company’s support could be affected.
Here’s why that matters beyond the company itself. All those names, emails and conversation details become raw material for the next round of attacks. A criminal who knows you recently raised a billing query can send you a perfectly timed, convincing fake email about it. One breach feeds the next.
The lesson most businesses miss
The instinct is to read a story like this and think, “that’s a big company problem.” It isn’t. The attack succeeded precisely because it didn’t target the big company’s defences. It targeted a smaller contractor in the chain.
Your business sits in the same kind of web. Your bookkeeper, your payroll provider, your IT support, your software vendors, all of them touch your data, and any one of them clicking the wrong link can become your problem. Your security is only as strong as the weakest link connected to it.
And the entry point is almost always the same: a person, under time pressure, clicking before they think.

What protects you
You can’t unplug your staff or your suppliers from email. What you can do is train people to recognise the bait, and test that training so it sticks.
That’s why we run ongoing phishing awareness training and simulated phishing tests for the clients we manage. We send our own safe, controlled “fake” phishing emails so that staff learn to spot the real thing, in an environment where a wrong click is a lesson, not a disaster. Over time, the click rate drops and the whole organisation gets harder to fool.
If a member of your team has ever been caught by one of our simulations, that is the system working exactly as intended. Far better that they learn from us than from a criminal.
Where does your business stand?
If you don’t currently run any phishing training or simulation, your team has never been tested against the exact tactic that breached a global software company. That’s a gap worth closing before someone else finds it.