Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

After Cyberattack, eBay Recommends Password Change

After Cyberattack, eBay Recommends Password Change

NEW YORK – US online giant eBay said Wednesday cyberattackers broke into its database containing customer passwords and other personal data in what could be one of the biggest breaches of its kind.

After Cyberattack, eBay Recommends Password Change

NEW YORK – US online giant eBay said Wednesday cyberattackers broke into its database containing customer passwords and other personal data in what could be one of the biggest breaches of its kind.

The California company said it was notifying its customers, urging them to change passwords to protect themselves.

An eBay statement said the database was compromised between late February and early March and “included eBay customers’ name, encrypted password, email address, physical address, phone number and date of birth.”

But it added that it “did not contain financial information or other confidential personal information.”

An eBay spokeswoman said the attack did not affect data from PayPal, the finance and payments unit of the company, noting that such details are stored separately.

“For the time being, we cannot comment on the specific number of accounts impacted,” spokeswoman Kari Ramirez said in an email.

“However, we believe there may be a large number of accounts involved and we are asking all eBay users to change their passwords.”

Advertisement. Scroll to continue reading.

One of Largest Breaches

Potentially impacting eBay’s 128 million active users globally, the attack could be one of the largest targeting a retailer, and comes just months after US giant Target disclosed a breach that may have affected more than 100 million.

The company said it detected “compromised employee log-in credentials” about two weeks ago and began an investigation.

“Cyberattackers compromised a small number of employee log-in credentials, allowing unauthorized access to eBay’s corporate network,” it said in a statement.

eBay “is aggressively investigating the matter and applying the best forensics tools and practices to protect customers,” it said, noting it was working with law enforcement and security experts.

“Information security and customer data protection are of paramount importance to eBay Inc, and eBay regrets any inconvenience or concern that this password reset may cause our customers,” it added.

“We know our customers trust us with their information, and we take seriously our commitment to maintaining a safe, secure and trusted global marketplace.”

Crooks ‘Wandered Around’

Paul Ducklin at the British security firm Sophos said the incident appeared to be a major security breach.

“It seems that the crooks didn’t just prise loose the database file with some kind of database command injection,” he said in a blog post.

“Crooks had broken in and wandered around.”

The announcement came amid some confusion. The company appeared to post an initial statement, then removed it before issuing a news release, said London-based security consultant Graham Cluley.

“Let’s hope the rest of the company’s response to this security incident runs a little smoother,” he said in a blog post.

Simon Crosby at the California-based security firm Bromium said the eBay and Target attacks are similar to other intrusions where a single device can be compromised, allowing hackers access to the entire network.

“The quickest way into your cloud is through a compromised client, a PC or another device where a user has full credentials,” he told AFP.

“That is a lot easier than trying to break into the cloud,” said Crosby, whose firm sells software that isolates devices from the networks.

Target has been dealing with the fallout from its massive data breach since news was disclosed in December.

Earlier this month, chief executive Gregg Steinhafel announced he was stepping down.

In its fourth-quarter report, Target booked a $17 million net charge for the breach, but warned it could not estimate future costs that might stem from claims for customer losses and payments for civil litigation and investigations.

A survey released Wednesday by the security firm Trustwave said it identified 691 breaches across 24 countries in 2013, with the number of incidents up 53.6 percent over 2012.

“In the majority of cases we investigated, attackers targeted payment card data,” the report said.

“A global, thriving underground provides for quick monetization of stolen data — no matter where the victim or attacker resides. As long as criminals can make money by stealing data and selling that sensitive information on the black market, we don’t expect data compromises to subside.”

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Incident Response

Microsoft has rolled out a preview version of Security Copilot, a ChatGPT-powered tool to help organizations automate cybersecurity tasks.