Nitro PDF suffers massive data breach, exposing Microsoft, Google, Amazon documents

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

UPDATE: Nitro has provided TechRadar Pro with a statement, included below. Sam Chandler, Nitro Founder and CEO, added, "Several media articles published in the past 24 hours contain a number of factual inaccuracies regarding this incident. The relevant database does not contain copies of user or customer documents. Documents are stored in a separate database in a different location. There is currently no established evidence that this separate database has been compromised. We are providing updates on the incident on our security page.”

The Australian company behind one of the best PDF editors, Nitro PDF has suffered a data breach that may have impacted several other well-known organizations.

As reported by BleepingComputer, Nitro PDF is used by over 10 thousand business customers, including the likes of Google, Apple, Microsoft, Case and Citibank, and 1.8m licensed users. However, the company also offers a cloud service that can be used by customers to share documents with coworkers as well as with employees at other organizations.

In an advisory published on the investor relations section of its site, Nitro Software informed its customers that it had suffered a “low impact security incident” though no sensitive financial data was impacted, saying:

“Nitro's investigation into the incident remains ongoing. There is no evidence currently that any sensitive or financial data relating to customers has been impacted or that any information has been misused. Nitro has elevated its monitoring and security protocols and has not identified any further malicious activity connected to the incident.”

Nitro Software data breach

Although Nitro Software claims that no sensitive financial data was lost as a result of the breach, the cybersecurity firm Cyble has revealed to BleepingComputer that the company's user and document databases as well as 1TB of documents allegedly stolen from the company are being sold online in a private auction starting at $80,000.

According to Cyble, the user credential database table contains 70m user records which contain the email addresses, full names, bcrypt hashed passwords, titles, company names, IP addresses and other system data from Nitro Software's customers.

For instance, the database reportedly contains 17,137 documents from Amazon, 6,405 from Apple, 137,285 from Citi, 32,153 from Google and 2,390 from Microsoft. There is also a great deal of information related to financial reports, M&A activities, NDAs and product releases included in the database.

"Nitro continues to investigate an isolated security incident involving limited access to a Nitro database by an unauthorised third party," Nitro told TechRadar Pro in a statement.

"The incident database does not contain any user or customer documents, which are hosted in a separate database in a different location."

"The incident database is primarily used for service logging purposes related to Nitro’s popular free online document conversion services."

"Usage of Nitro’s free document conversion services does not require users to create an account or become a Nitro customer. Users are required to provide an email address – converted files are delivered to the email address provided – and common email domains are frequently entered and will show up in these logs."

"For clarity, the email domains in these logs do not constitute Nitro ‘customers’ or ‘accounts’, and the logs do not contain any documents."

"There is currently no established evidence that any sensitive or financial data relating to customers has been compromised. There is no impact to Nitro Pro or Nitro Analytics."

"Nitro’s environment was fully secured immediately after the incident was identified. While the incident database does not contain sensitive or financial information, and passwords are highly encrypted, we are communicating with customers and have implemented a password reset as a precautionary measure."

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)