Don’t do SECURITY. Do business SECURELY.

eBay asks 145 million users to change passwords after cyber attack

eBay said attackers had used stolen employee credentials to access a database containing customer names, encrypted passwords, and contact details.

Online marketplace eBay asked its users to change their passwords after attackers compromised a database containing customer information. The company had around 145 million active users at the time.

What happened

  • Attackers obtained a small number of employee log-in credentials, giving them access to eBay’s corporate network between late February and early March 2014.
  • The compromised database held names, encrypted passwords, email and postal addresses, phone numbers, and dates of birth.
  • eBay said it had no evidence that financial or payment card information was taken, and that PayPal data was stored separately.
  • The intrusion was detected around two weeks before it was announced, prompting criticism about the delay.

Why it mattered

The breach was one of the largest by number of accounts at the time and showed how compromised staff credentials can open the door to customer data.

Lessons for organisations

Organisations should enforce multi-factor authentication for staff access to internal systems, monitor for unusual use of privileged accounts, and notify affected customers promptly once a breach is confirmed. Password resets should be paired with advice to change reused passwords on other services.

Sources: CBS News, The Washington Post

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights