eBay's Corporate Network Hacked


Userlevel 7



(Source: CNET)

 
eBay has seen better mornings. According to numerous reports, such as this one from CNET, the company has confirmed that hackers breached their corporate network and compromised a database that contained user passwords. eBay is urging all users to change their passwords although they don't believe that any financial information has been accessed.

"The statement follows an odd stream of events this morning when eBay-owned PayPal posted a blog entitled 'eBay, Inc. to Ask All eBay users to Change Passwords.' The blog post included nothing but the title, but quickly hit the Web after it was retweeted dozens of times. The blog post was then taken down from PayPal's site, causing even more confusion for users of the online auction house."


Click the aforementioned link for the full story.

 
 

11 replies

Userlevel 7
Badge +56
Thanks Yegor I changed my password just in case!
 
Daniel 😉
Userlevel 7
Badge +54
Thank you Yegor. When I was in a few hours the news was just coming out and was then a bit sketchy.
Userlevel 7
Badge +54
Here's a quick breakdown on the situation that can be shared in-house

On Wednesday, eBay issued an advisory to users stating that passwords will need to be changed, after a database containing user information was compromised. When a company this large reports a security incident, it has the tendency to turn into a FUD-fueled news cycle.

In the event that people within your organization have questions, here's an overview of the incident, with some additional details you can use when discussing the situation.

How did this happen?

According to eBay, attackers compromised employee log-in credentials. This gave the attackers access to the corporate network and the systems on it.

As is the case with most attacks that result in credential theft, the attackers likely used a socially-based attack of some kind. The best bet is Phishing. However, eBay isn't discussing how the credentials were compromised, so it could be Phishing, or it could be malware. The public may never know.
 
Full Article
Userlevel 7
Badge +62
😠 Really again! I suppose I need a password generator because I'm running out of ideas for another new password. This is getting ridicoulous!! Ebay/PayPal!
 
Thank You for the post Jasper!!;) And Yegor!!
 
 
Userlevel 7
Yegor and Jasper, many thanks for posting!
Userlevel 7
Badge +54
Posted on 22 May 2014 at 12:15, by James Temperton
 
Passwords, email addresses and physical addresses of millions of eBay users have been stolen by hackers. We explain what you need to do and questions eBay has to answer following this catastrophic security breach.
While eBay has confirmed no financial information has been compromised, the attack is still very bad news for your online security. Here's what you need to do right now:
 
Full Article
Userlevel 7
Thanks Jasper.  I'm just glad I've never really used either one.
Userlevel 7
Badge +62
Yes Thankyou again ...I do use this site a lot!! 😞
Userlevel 7
I've heard of it only yesterday morning. I was at the lab all day. I changed the password in the evening.

@
Use LastPass or WSA-I/WSA-C's LastPass based password manager. The 'Security Check' tool of LastPass tells me which websites are compromised. So you can always have a peace of mind.:)
Userlevel 7
Badge +62
Thanks @  (Use LastPass or WSA-I/WSA-C's LastPass based password manager. The 'Security Check' tool of LastPass tells me which websites are compromised. So you can always have a peace of mind.)

Sounds like a plan!
Cheers,
Userlevel 7
Badge +54
May 27th, 2014, 14:51 GMT · By Gabriela Vatu
 
 
If you’re an eBay user, you’ve certainly heard by now of the massive data breach that put in danger some 145 million people. The company has been advising users to change their passwords if they’re among the many affected and emails have been sent over the past few days.

Since phishing attacks are aplenty, you should be careful what links you access and know how to detect the good emails from the scams.

First of all, eBay’s email reads “Important – eBay Password Reset Required” in the subject line and the message comes from ebay@reply1.ebay.com.

The lengthy email explains the situation eBay is in and why it’s necessary to change your password, while being signed by Devin Wenig, eBay marketplaces president.
 
Full Article

Reply