Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
eBay: At LEAST 1,200 User Accounts Hacked, CC and Other Details Posted
#1
http://www.theregister.co.uk/2007/09/25/...published/


Hackers brazenly posted sensitive information including home addresses and phone numbers for 1,200 eBay users to an official online forum dedicated to fraud prevention on the auction site.

The information - which also included user names and email, and possibly their credit card numbers and three-digit CVV2 numbers - was visible for more than an hour to anyone visiting the forum. The miscreants appeared to create a script that caused each user to log in and post information associated with the person who owned the account. The script spit out about 15 posts per minute, starting around 5:45 a.m. California time.

An eBay spokeswoman said the posts were most likely the result of account takeovers and not of a security breach on eBay. She also said the credit card numbers contained in the posts were not those eBay or PayPal had on file for those users. eBay representatives have begun contacting all users whose information was posted to head off any further fraud and to learn more about the attack.

A list of compromised screen names is available here:
http://shenemanfamily.com/comp.html

eBay's response:
http://www.ebaychatter.com/the_chatter/2...ty-fo.html
Reply
#2
I'm not on the list so I'm happy.
Reply
#3
Reports are that the CC data was not correct. That is, the numbers may have been valid (it's not difficult to generate valid CC numbers), but the numbers did not belong to the people listed.
Reply
#4
If anyone has any concerns, please just send me your Ebay screen name, password and your current creedit card information along with billing address, and I will personally verify your security for safety. I will also upgrade your Ebay account to have double security new bit type encryption.

Please respond ASAP or your bank account will be frozen.

Steve R.

Ebay security headquarters
steveR@yahoo.uk
Reply
#5
Why would they have the CVV2 codes? I thought the merchant verified this with the bank for each transaction?
Reply
#6
Which one of you goes by the eBay handle, "they_call_me_*ice*nuts* "???
Reply
#7
We had our account hacked about a year and a half ago. Someone listed a MacBook Pro
around midnight. It took about 3 hours to get it pulled and all the passwords changed with
everything connected to the account, eBay, Paypal and the email address passwords.
eBay actually called the house to verify who we were.
[Image: 1Tr0bSl.jpeg]
Reply
#8
Some great screen names on there:

cripplethumbs
klingon_master
mgshaft69
sassy_pearls
soulbomber
they_call_me_*ice*nuts*
Reply
#9
What Stavs said.
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)