Created page regarding Nitro Pro's 2020 data breach incident
 
No edit summary
 
(12 intermediate revisions by 7 users not shown)
Line 1: Line 1:
'''Nitro Pro''' is a [[Portable Document Format]] (PDF) editing application<ref>{{cite web |title=Nitro Pro 12 review: A better document workflow |url=https://www.pcworld.com/article/3278587/software/nitro-pro-12-pdf-editor-review.html |access-date=31 October 2018 |website=PC Magazine}}</ref> and electronic signature software.<ref>{{Cite web |date= |title=Nitro PDF Pro |url=https://studentit.unimelb.edu.au/software/nitro-pdf-pro |access-date=August 15, 2024 |website=The University of Melbourne}}</ref>
{{Stub}}
{{ProductCargo
|ArticleType=Product
|Category=Software
|Company=Nitro Software
|Description=
|InProduction=Yes
|Logo=Nitro Pro logo.png
|ProductLine=
|ReleaseYear=2018
|Website=https://www.gonitro.com/
}}
 
'''Nitro Pro''' is a Portable Document Format (PDF) editing application<ref>{{Cite web |last=Ansaldo |first=Michael |title=Nitro Pro 12 review: A better document workflow |url=https://www.pcworld.com/article/3278587/software/nitro-pro-12-pdf-editor-review.html |website=PCWorld |date=9 Jul 2018 |access-date=31 Oct 2018 |url-status=deviated |archive-url=http://web.archive.org/web/20180729061555/https://www.pcworld.com/article/3278587/software/nitro-pro-12-pdf-editor-review.html |archive-date=29 Jul 2018}}</ref> and electronic signature software.<ref>{{Cite web |author= |title=Nitro PDF Pro |url=https://studentit.unimelb.edu.au/software/nitro-pdf-pro |website=The University of Melbourne |date= |access-date=4 Mar 2026 |url-status=live |archive-url=http://web.archive.org/web/20251004224257/https://studentit.unimelb.edu.au/software/nitro-pdf-pro |archive-date=4 Oct 2025}}</ref>


==Background==
==Background==
{{Placeholder box|Claimed to be used by over 10 thousand business customers and 1.8 million licensed users, Nitro is an application used to create, edit, and sign PDFs and digital documents. As part of their service offering, Nitro offers a cloud service used by customers to share documents with coworkers or other organizations involved in the document creation process.
Claimed to be used by over 10 thousand business customers and 1.8 million licensed users, Nitro is an application used to create, edit, and sign PDFs and digital documents. As part of their service offering, Nitro offers a cloud service used by customers to share documents with co-workers or other organizations involved in the document creation process. A massive data breach suffered by the Nitro PDF service impacts many well-known organizations, including [[Google]], [[Apple]], [[Microsoft]], [[Chase]], and [[Citibank]].<ref name=":0">{{Cite web |last=Abrams |first=Lawrence |title=Massive Nitro data breach impacts Microsoft, Google, Apple, more |url=https://www.bleepingcomputer.com/news/security/massive-nitro-data-breach-impacts-microsoft-google-apple-more/ |website=BleepingComputer |date=26 Oct 2020 |access-date=4 Mar 2026 |url-status=live |archive-url=http://web.archive.org/web/20260128094434/https://www.bleepingcomputer.com/news/security/massive-nitro-data-breach-impacts-microsoft-google-apple-more/ |archive-date=28 Jan 2026}}</ref>
 
In April 2023 Nitro Pro (NTO) was de-listed from the Australian Stock Exchange<ref name="NitroDelisting">{{Cite web |author= |title=Nitro Software Delisting |url=https://stocklight.com/stocks/au/delisted?code=NTO |website=stocklight |date=18 Apr 2023 |access-date=4 Mar 2026 |url-status=live |archive-url=http://web.archive.org/web/20251004224255/https://stocklight.com/stocks/au/delisted?code=NTO |archive-date=4 Oct 2025}}</ref> when the company was purchased by Ellerston Capital.<ref name="NitroInvestment">{{Cite web |author= |title=Ellerston JAADE's Investment in Nitro |url=https://ellerstoncapital.com/news/ellerston-jaade-new-investment-nitro/ |website=Ellerston Capital |date=8 May 2023 |access-date=4 Mar 2026 |url-status=live |archive-url=http://web.archive.org/web/20251110110626/https://ellerstoncapital.com/news/ellerston-jaade-new-investment-nitro/ |archive-date=10 Nov 2025}}</ref>
 
==Consumer impact summary==
{{Ph-C-CIS}}
 
==Incidents==
This is a list of all consumer-protection incidents related to this product. Any incidents not mentioned here can be found in the [[:Category:{{PAGENAME}}|{{PAGENAME}} category]].


A massive data breach suffered by the Nitro PDF service impacts many well-known organizations, including Google, Apple, Microsoft, Chase, and Citibank.}}
===Massive data breach (''2020'')===
In September 2020, the Nitro PDF service suffered a massive data breach which exposed over 70 million unique e-mail addresses. Cyber-security intelligence firm Cyble has told BleepingComputer that a threat actor is selling the user and document databases, as well as 1TB of documents, that they claim to have stolen from Nitro Software's cloud service. Cyble states that the 'user_credential' database table contains 70 million user records containing email addresses, full names, bcrypt hashed passwords, titles, company names, IP addresses, and other system-related data.<ref name=":0" />


==Incident==
====Nitro's response====
{{Placeholder box|In September 2020, the Nitro PDF service suffered a massive data breach which exposed over 70 million unique email addresses. The breach also exposed names, bcrypt password hashes and the titles of converted documents. The data was provided to HIBP by dehashed.com.
On 21 October 2020, Nitro Software issued an advisory to the Australia Stock Exchange, stating that they were affected by a "low impact security incident" but that no customer data was impacted. Despite Nitro's advisory, the data breach exposed names, bcrypt password hashes and the titles of converted documents. The data was provided to HIBP by dehashed.com.<ref>{{Cite web |author= |title=Nitro |url=https://haveibeenpwned.com/breach/Nitro |website=Have I Been Pwned |date=2020 |access-date=4 Mar 2026 |url-status=live |archive-url=http://web.archive.org/web/20260222162541/https://haveibeenpwned.com/Breach/Nitro |archive-date=22 Feb 2026}}</ref>


Cybersecurity intelligence firm Cyble has told BleepingComputer that a threat actor is selling the user and document databases, as well as 1TB of documents, that they claim to have stolen from Nitro Software's cloud service. Cyble states that the 'user_credential' database table contains 70 million user records containing email addresses, full names, bcrypt hashed passwords, titles, company names, IP addresses, and other system-related data.}}
===Perpetual license deactivation (''2025'')===
In June 2025, customers that had bought a perpetual license for Version 12 and older suddenly found themselves receiving an error message informing them their license was expired. Attempts to use their serial numbers to activate would return an error stating that the number did not exist. When this was brought up on Nitro's support forum, an employee shared the following in response on 13 June 2025:<ref>{{Cite web |last=Capiral |first=Joseph |title=Nitro Pro is no longer supported + Serial Number not found for activation |url=https://community.gonitro.com/topic/22064-nitro-pro-is-no-longer-supported-serial-number-not-found-for-activation/ |website=Nitro |date=13 Jun 2025 |access-date=4 Mar 2026 |url-status=live |archive-url=http://web.archive.org/web/20251004224255/https://community.gonitro.com/topic/22064-nitro-pro-is-no-longer-supported-serial-number-not-found-for-activation/ |archive-date=4 Oct 2025}}</ref>
<blockquote>To maintain the highest standards of security and performance, we can no longer support legacy versions of Nitro PDF Pro. These older versions are not patched for security vulnerabilities and may expose your organization to risk.<br />


===Nitro's response===
To make your upgrade as seamless as possible, we are offering our Nitro PDF Standard subscription plan at more than 70% off the regular price, with this discounted rate locked in for three years.<br />
{{Placeholder box|On October 21st, Nitro Software issued an advisory to the Australia Stock Exchange, stating that they were affected by a "low impact security incident" but that no customer data was impacted.


Despite Nitro's advisory, the data breach exposed names, bcrypt password hashes and the titles of converted documents. The data was provided to HIBP by dehashed.com.}}
By upgrading, you’ll gain access to the latest versions of Nitro PDF Pro for Windows, Mac, and iOS, along with new web-based and AI-powered tools to enhance your document workflows.  Upgrading to a current release ensures you benefit from the latest features, performance enhancements, and security protections.<br />
==Lawsuit==
{{Placeholder box|If applicable, add any information regarding litigation around the incident here.


===Claims===
For additional information or to redeem the discounted upgrade offer, please go to our Upgrade Portal and enter your 18-digit serial number.<br />
Main claims of the suit.


===Rebuttal===
<nowiki>https://www.gonitro.com/support/upgrade</nowiki><br />
The response of the company or counterclaims.


===Outcome===
Upon completing your Nitro Pro purchase, you will receive an email with instructions for setting up your Nitro account and using the full suite of Nitro products.<br />
The outcome of the suit, if any.}}


Thank you.</blockquote>


==Consumer response==
Additionally, Nitro Pro issued the following statement regarding their perpetual licenses:<ref>{{Cite web |author= |title=Upgrade to Nitro Pro |url=https://help.gonitro.com/support/upgrade |website=Nitro |date= |access-date= |url-status=deviated |archive-url=http://web.archive.org/web/20250905150142/https://help.gonitro.com/support/upgrade |archive-date=5 Sep 2025}}</ref>
{{Placeholder box|Summary and key issues of prevailing sentiment from the consumers and commentators that can be documented via articles, emails to support, reviews and forum posts.}}
<blockquote>Nitro is transitioning to a subscription licensing model. All Nitro PDF Pro for Windows perpetual licenses will be deactivated by December 31, 2025. You will receive an email notification prior to deactivation. You can upgrade up to 20 perpetual licenses to a subscription now, regardless of the deactivation date.</blockquote>


Those that refused to upgrade to a subscription-based plan were no longer able to use the product.
==See also==
*[[Nitro Software]]
*[[Retroactively amended purchase]]


==References==
==References==
{{reflist}}
{{Reflist}}
 
{{Placeholder box|[[mw:Help:VisualEditor/User_guide#Editing_categories|Add a category]] with the same name as the product, service, website, software, product line or company that this article is about.


The "Incidents" category is not needed.}}
[[Category:{{PAGENAME}}]]
[[Category:Nitro Software]]
[[Category:Products]]