CHINA TOPIX

11/23/2024 01:48:03 pm

Make CT Your Homepage

eBay Recommends Password Reset After Hacking Attack

eBay

(Photo : Reuters / Robert Galbraith) A placard advertising an eBay app for Apple is shown in San Francisco, California, April 22, 2009.

eBay had asked its 145 million users to change their passwords after the online marketplace became the victim of a cyber hacking that affected a database with its encrypted passwords and other user data.


The compromised database did not include any financial details, the e-commerce giant said. A spokeswoman also said passwords for the site's PayPal payments network were not affected, The Wall Street Journal wrote.

Like Us on Facebook

Still, a password reset was encouraged because some PayPal users use the same combination of name and password with their eBay account.

Hackers did not gain access to the actual passwords of the users because they were encrypted. This rendered the passwords temporarily unusable, according to Gartner Inc cybersecurity analyst Avivah Litan.

The California-based firm said the cyberattack happened between late February and early March but was only detected a couple of weeks ago. The hackers were able to enter the corporate network using compromised login details of the company, eBay explained.

The breached database includes passwords, email addresses, home addresses, birthdates, and phone numbers. For users who use the same username and password combination on other websites, eBay encouraged them to also reset those those passwords.

The eBay cyberattack is the latest to be launched by cybercriminals who have recently been aiming for usernames and passwords for popular websites. Litan also said credit card and Social Security data are also being targeted in this trend.

Once the criminals expose the username and password of a user, they try to see if the same combination is being used for their bank accounts. So far, no group has taken credit for the eBay hacking, Litan added.

Based on tests, eBay said the breach does not appear to lead to any unauthorized user activity or any access to financial information. The e-commerce site said it users' financial data are encrypted and stored separately.

Furthermore, eBay added that the data breach is not linked to the "Heartbleed" flaw recently discovered by security researchers in encryption tools, which could be exploited to gain access to login credentials.

Real Time Analytics