728_header.jpg (23748 bytes)
Google  Web AuctionBytes  

Home
Subscribe
Blog
Letters to Editor  
EcommerceBytes
Podcasts
Forums
Merchant Directory
AuctionBytes TV
ABU Back Issues

Sponsor

COOL TOOLS

Calendar
eBay Fee Calculator
Collectors' Links
eBay Promo History
Bookshelf
Fraud Resources
Auction Site Fees
Auction Management
Payment Services
Storefronts Chart
Sniping Chart
Email List Hosting
Consignment Services
Drop-Off Store Laws
Ecommerce Resources
Photo Tips
Marketing Inserts
Yellow Pages
Classifieds

AUCTIONBYTES

Our Writers
Write For Us
Partners
Press
Advertising
About Us
Link To Us

Auctionbytes-NewsFlash, Number 1628 - September 25, 2007 - ISSN 1539-5065      | Next Story

eBay Shuts Trust & Safety Board after Credit Card Numbers Exposed
By Ina Steiner
AuctionBytes.com
September 25, 2007
Reading AuctionBytes: eBay Shuts Trust & Safety Board after Credit Card Numbers Exposed

eBay shut down an entire discussion board devoted to Trust & Safety issues after someone began posting confidential user information. Someone using multiple User IDs began listing information purported to be eBay users' private and financial data on the Trust & Safety discussion board. Mark, a user who says he posts regularly on the board, said he noticed the problem at 8:50 am Eastern on Tuesday and called his eBay representative about 20 minutes later after he saw the posts remained. He said it took about an hour for the posts to be removed, and minutes later, the entire board was taken down.

The person posted using several IDs that look like they had been hijacked from legitimate users. The subject line of each thread began with the letters "Wheeeeeeeeeeeeeeeeeeeee" followed by six numbers.

Mark said regular users who were posting on the board while the incident was taking place suspected that eBay may have been hacked, and he said some believed it was a scammer named Vladuz that has tormented eBay in the past. eBay has denied that Vladuz has ever hacked into its system (http://www.auctionbytes.com/cab/abn/y07/m02/i22/s03).

AuctionBytes was able to view the forum and several posts before they were removed. While most data looked like it could have been obtained through phishing campaigns, the posts also included fields labeled "Id verified" and "Store" along with a time-date stamp of the user registration. The accuracy of the information has not been verified by AuctionBytes.

Update 9/25/07 3:20 pm Eastern:
eBay spokesperson Nichola Sharpe said Tuesday afternoon that posts made on the Trust & Safety board early this morning contained name and contact information for 1,200 eBay members and called the person posting the information a "malicious fraudster." She said the incident was not the result of a security breach from eBay and could have been obtained as part of an account takeover.

Sharpe said the credit card information contained in the posts were not associated with financial information on file for those users at eBay or PayPal. The company is in the process of proactively contacting members by phone, "so that if the information is valid somehow - regardless how this fraudster acquired the information - these members can take the steps they need to take to protect themselves."

eBay has temporarily blocked community access to the Trust and Safety discussion forum, Sharpe said, and informed the community of the incident via the eBay Chatter blog (http://www.ebaychatter.com/the_chatter/2007/09/trust-safety-fo.html).

"Our Trust and Safety team is continuing to closely monitor this situation," Sharpe said.

Meanwhile, users are spooked by the posts and some are critical of eBay's response. A YouTube member going by the name of "cappnonymous" posted a video showing the eBay Trust & Safety board posts, titling the submission, "ebaY Major Hack AttacK! User's Data Posted On Ebay T&S Bd" (http://www.youtube.com/watch?v=_q9m2iFsz9M).

NOTE: Please check back during the day as we will update this story as it develops.

Also see the AuctionBytes blog:
http://tinyurl.com/24xssx

Email this story to a friend.

Subscribe to the AuctionBytes Email newsletter

AddThis Social Bookmark Button

| Next Story

Related Stories
  • eBay Addresses Vladuz Hacking Incident - February 22, 2007, Issue #1480
  • He's Baaack - Vladuz 'Hacker' Taunts eBay - February 23, 2007, Issue #1481
  • Vladuz 'Captcha Populator' Tool Doesn't Worry eBay, Mozilla - March 06, 2007, Issue #1488
  • eBay Auction Listing Swings Remain a Mystery - March 12, 2007, Issue #1492
  • Romanian Hacker Vladuz Makes Another eBay Housecall - March 14, 2007, Issue #1494
  • Scammers Use eBay's Message System to Troll for Victims - March 16, 2007, Issue #1496
  • FBI Cites Role in Arrest Related to Off-eBay Fraud - March 27, 2007, Issue #1503
  • Consumer Reports Releases Results of eBay Survey - July 03, 2007, Issue #1574
  • Spammers Harvest eBay Sellers' Email Addresses - August 21, 2007, Issue #1604
  • eBay Denies Security Breach after User Information Exposed - September 26, 2007, Issue #1630
  • eBay, PayPal and Yahoo Collaborate to Fight Phishing - October 04, 2007, Issue #1635
  • eBay Explains Security Hole Used by Hacker - October 09, 2007, Issue #1638
  • Hacker Email Address Used in Previous eBay Scams? - October 09, 2007, Issue #1638
  • eBay Hacker 'Vladuz' Arrested in Romania - April 18, 2008, Issue #1772



  • Discuss this story in our forums.

    Ecommerce Podcasts

    Site Index
    Copyright 1999-2009. Steiner Associates LLC. All rights reserved. Privacy Policy.