Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Ebay Hacked! - Credit Cards, Bank Accounts posted on T & S
eBay discussion Board ^ | Sept 35, 2007 | zekemcalister

Posted on 09/26/2007 7:25:05 AM PDT by publana

http://forums.ebay.com/db2/thread.jspa?threadID=1000565444&start=0

Ebay was hacked today. Users complete credit card information was being posted today on eBay's Trust and Safety board including name, cc number, CCV, paypal info, etc. It took eBay over 90 minutes to finally pull down the Trust & Safety server to remove the publicly posted information. If you have an eBay or PayPal account, you might want to monitor the above link.


TOPICS: Business/Economy; Extended News
KEYWORDS: ebay; paypal; phishing; socialengineering; spoofing; trustsafety
Navigation: use the links below to view more comments.
first 1-5051-71 next last

1 posted on 09/26/2007 7:25:08 AM PDT by publana
[ Post Reply | Private Reply | View Replies]

To: publana

I hope my info wasn’t posted.


2 posted on 09/26/2007 7:29:43 AM PDT by LilAngel (Pray)
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana

OMG!..............


3 posted on 09/26/2007 7:30:31 AM PDT by Red Badger (ALL that CARBON in ALL that oil & coal was once in the atmosphere. We're just putting it back!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: beyondashadow

ebay hack ping - not good!


4 posted on 09/26/2007 7:30:38 AM PDT by whatexit
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana
September 35?

Actually, it was hacked yesterday. I was following some of the threads--ebay apparently is claiming that the credit card information does not match the user names that were published. They still haven't issued a formal statement to users.
5 posted on 09/26/2007 7:30:52 AM PDT by rightwingintelligentsia (You know a liberal has lost the argument when he calls you a Nazi.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana

Thanks for posting...I have no way of verifying if any of my information has gone out there, eBay darn well better let me know if it has.

If anyone suspects their information is compromised, they should put a fraud alert on their bank and credit card accounts, or at least monitor them for the next few days.


6 posted on 09/26/2007 7:32:34 AM PDT by DaveLoneRanger ("Being normal is not necessarily a virtue. It rather denotes a lack of courage.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana

bttt


7 posted on 09/26/2007 7:32:56 AM PDT by firewalk
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana
Holy cow..I lost my CC last week and had to have the account canceled. There is a God.

BTW...I had a guy with a middle eastern accent calling from Britain try to buy a car from me a few months back, outside the usual protection of the ebay service. Be careful people.

8 posted on 09/26/2007 7:33:02 AM PDT by Earthdweller (All reality is based on faith in something.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: DaveLoneRanger

http://shenemanfamily.com/comp.html

A list of posted IDs with credit card information.


9 posted on 09/26/2007 7:33:10 AM PDT by publana (Build the fence!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: publana

If cc info was in paypal, how would hacking ebay get that info?

Or do some people put cc info into ebay itself?


10 posted on 09/26/2007 7:33:53 AM PDT by dinoparty
[ Post Reply | Private Reply | To 1 | View Replies]

To: dinoparty

ebay owns paypal


11 posted on 09/26/2007 7:35:54 AM PDT by Dr. Sivana ((Not a newbie, just wanted a new screen name))
[ Post Reply | Private Reply | To 10 | View Replies]

To: publana

bttt


12 posted on 09/26/2007 7:36:17 AM PDT by BlabItGrabIt (He Became Poor, So WE Might Be Rich :))
[ Post Reply | Private Reply | To 1 | View Replies]

To: dinoparty

Seller fees can be paid with a credit card.


13 posted on 09/26/2007 7:37:18 AM PDT by Your Nightmare
[ Post Reply | Private Reply | To 10 | View Replies]

To: publana

Curious. I wonder whether there is any connection to this:

Yesterday I got an email saying I needed to update my Paypal credit card information. It gave a link to click on.

While I do have a Paypal account, it is inactive and I seldom use it. I don’t even have a credit card listed on it.

I never click on those email links, as I am always suspicious of them. I go to the webpage by typing in the address in the browser or using a ‘real’ url link in my bookmarks/favorites.


14 posted on 09/26/2007 7:37:19 AM PDT by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana

funny. i just went to ebay without using your link, and could not find anything about this. i never use supplied links to any web site involving passwords/financials - I enter the url myself.


15 posted on 09/26/2007 7:37:19 AM PDT by camle (keep your mind open and somebody will fill it full of something for you)
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana

I went and checked it out, but I cant see a list of users who were compromised. I understand that they wouldn’t want to leave the actual CCs listed, but they should leave up a list of the affected users.


16 posted on 09/26/2007 7:37:22 AM PDT by TChris (Governments don't RAISE money; they TAKE it.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dinoparty

Don’t you put cc info into ebay when you are a seller? It’s been a while since I sold anything.


17 posted on 09/26/2007 7:37:47 AM PDT by mmichaels1970
[ Post Reply | Private Reply | To 10 | View Replies]

To: TomGuy
Yesterday I got an email saying I needed to update my Paypal credit card information

I doubt this is related. I manage mail servers for my company and we get these sorts of things all the time. SPOOFING or PHISHING emails are very common and hard to fight. You are doing the right thing however when you use the "real" url.
18 posted on 09/26/2007 7:40:22 AM PDT by mmichaels1970
[ Post Reply | Private Reply | To 14 | View Replies]

To: BlabItGrabIt

I have an eBay account but no Paypal account. Should I be worried?


19 posted on 09/26/2007 7:40:23 AM PDT by wastedyears (George Orwell was a clairvoyant.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: wastedyears

Post #9 may be a start.


20 posted on 09/26/2007 7:40:58 AM PDT by mmichaels1970
[ Post Reply | Private Reply | To 19 | View Replies]

To: publana
This doesn't quite pass the smell test.

From whence cometh your info?

There are almost as many scam emails for eBay and/or PayPal as there are Nigerians.

Did this "Alert" come via an email?

21 posted on 09/26/2007 7:41:22 AM PDT by N. Theknow (Kennedys: Can't drive, can't fly, can't ski, can't skipper a boat; but they know what's best for us)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dinoparty

Should I contact PayPal, as they have the CC info.


22 posted on 09/26/2007 7:42:38 AM PDT by gathersnomoss (General George Patton had it right.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: TomGuy
Tom - any time you get an E-Mail like this - automatically forward it to spoof@paypal.com.

Almost 100% of the time is a phishing E-Mail.

23 posted on 09/26/2007 7:42:49 AM PDT by Enterprise (Those who "betray us" also "Betray U.S." They're called DEMOCRATS!)
[ Post Reply | Private Reply | To 14 | View Replies]

To: TChris

bump


24 posted on 09/26/2007 7:43:10 AM PDT by carton253 (And if that time does come, then draw your swords and throw away the scabbards.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: TomGuy

TomGuy,

You should forward the email to:

spoof@paypal.com

The are working hard to try to track down and stop all the phishing and spoofing.


25 posted on 09/26/2007 7:43:56 AM PDT by lkco
[ Post Reply | Private Reply | To 14 | View Replies]

To: publana

Ping to self for monitoring. My name is not on the list, per post #9, but I wonder if Ebay will make any kind of formal announcement about the breach. Seems like they are obligated to do so to help their customers combat the fraud.


26 posted on 09/26/2007 7:46:19 AM PDT by Virginia Ridgerunner ("Si vis pacem para bellum")
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana
more info
27 posted on 09/26/2007 7:48:20 AM PDT by andyssister
[ Post Reply | Private Reply | To 1 | View Replies]

To: camle

Google news search on ebay + hacked shows several news articles about it.

http://news.google.com/news?hl=en&ned=us&q=ebay+hacked&btnG=Search+News


28 posted on 09/26/2007 7:48:22 AM PDT by TomGuy
[ Post Reply | Private Reply | To 15 | View Replies]

To: N. Theknow
From whence cometh your info?

Publana posted the address from the ebay forum. There are over a thousand replies, none that I saw said it was phony. The early posts are from numerous people frsytrated because ebay did not pull the page immediately.
29 posted on 09/26/2007 7:48:27 AM PDT by Dr. Sivana ((Not a newbie, just wanted a new screen name))
[ Post Reply | Private Reply | To 21 | View Replies]

To: N. Theknow

More here.

http://www.pcpro.co.uk/news/126335/hackers-post-ebay-customer-details-on-forums.html


30 posted on 09/26/2007 7:48:57 AM PDT by eyedigress
[ Post Reply | Private Reply | To 21 | View Replies]

To: stylecouncilor

ping


31 posted on 09/26/2007 7:49:34 AM PDT by windcliff
[ Post Reply | Private Reply | To 1 | View Replies]

To: DaveLoneRanger

If you didn’t do any buying on ebay yesterday, then you’re not in danger anyway.

It probably wasn’t a hack, but a data transfer error. That’s why it took so long to terminate.


32 posted on 09/26/2007 7:51:15 AM PDT by editor-surveyor (Turning the general election into a second Democrat primary is not a winning strategy.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: N. Theknow
His info came from http://forums.ebay.com/db2/thread.jspa?threadID=1000565444&start=0. I checked it out and it looks to be a legitimate scare. However, it's possible that this was more of an attack on ebay's credibility than on its users. Just a suspicion, but it is possible that somebody did, in fact, hack a bunch of ebay user names, and then post them with phoney cc info to give the appearance that ebay had been completely hacked, when only some account userid's had been taken. I'll read the forum some more to see if anybody can actually confirm that THEIR cc info was actually correctly listed in the hack.
33 posted on 09/26/2007 7:51:27 AM PDT by mmichaels1970
[ Post Reply | Private Reply | To 21 | View Replies]

To: publana

ugh. my name is not on the list but im going to assume it’s been taken. time to call my credit card company.


34 posted on 09/26/2007 7:52:27 AM PDT by minus_273
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana
>Ebay was hacked today

Don't they run Linux?!
Don't bad things only happen
to Windows servers?!
35 posted on 09/26/2007 7:54:53 AM PDT by theFIRMbss
[ Post Reply | Private Reply | To 1 | View Replies]

To: minus_273

It was 1200 names running from a script every 15 minutes on their safety forum.

http://www.channelregister.co.uk/2007/09/25/ebay_account_details_published/


36 posted on 09/26/2007 7:55:48 AM PDT by eyedigress
[ Post Reply | Private Reply | To 34 | View Replies]

To: dinoparty

“If cc info was in paypal, how would hacking ebay get that info?

Or do some people put cc info into ebay itself?”

Ebay now owns PayPal.

But neither one will ever send you an e-mail asking for updated information because any information you entered when you registered is kept indefinately, unless you go directly to their website and update it yourself.

ANYTIME you get any e-mail claiming it is from either Ebay or PayPal, go directly to their websites and check whether you have any new ‘messages’ there. If you don’t, then the E-mail is nothing more than ‘Phish’ mail trying to get your credit card and account information.

Copy the entire email and send it to Ebay, or ignore it and block the senders address.


37 posted on 09/26/2007 7:56:04 AM PDT by Bigh4u2 (Denial is the first requirement to be a liberal)
[ Post Reply | Private Reply | To 10 | View Replies]

To: TomGuy
Yesterday I got an email saying I needed to update my Paypal credit card information. It gave a link to click on.

I often get those emails and I don't even have a PayPal or eBay account. *delete*delete*delete*

38 posted on 09/26/2007 7:59:06 AM PDT by girlscout
[ Post Reply | Private Reply | To 14 | View Replies]

To: N. Theknow

It happened. The main suspect is Vladuz, a well known cracker of Eastern European origin (Russian, Romanian).

Ebay is making phone calls to the affected ID’s, but at this time there is no evidence that the credit information was accurate or valid. The cracker looks to have been trying to create negative publicity and anxiety in the user base. Great way to start the “sell” season.

Ebay claims it was not hacked, but that the information came from phished accounts.

It was announced in the obscure eBay Chatter (eBay usually releases bad news this way) and also discussed in the AuctionBytes blog and several private forums for professional ebay sellers.

Ebay shut down the Trust and Safety forum and scrubbed references to it from many of the other ebay forums they host, as per their usual sweep it under the rug and hope it goes away SOP.


39 posted on 09/26/2007 7:59:41 AM PDT by Valpal1 ("I know the fittest have not survived when I watch Congress on CSPAN.")
[ Post Reply | Private Reply | To 21 | View Replies]

To: admin; Sidebar Moderator

I can’t believe you pulled this from breaking news. That is the only way that I learned of this extremely important information. Please put it back in breaking. I does matter a lot to some people. Ebay certainly isn’t forthcoming with the info.


40 posted on 09/26/2007 8:02:19 AM PDT by UnsinkableMollyBrown
[ Post Reply | Private Reply | To 37 | View Replies]

To: publana

for later


41 posted on 09/26/2007 8:03:24 AM PDT by JDoutrider
[ Post Reply | Private Reply | To 1 | View Replies]

To: mmichaels1970

My account isn’t there.


42 posted on 09/26/2007 8:07:02 AM PDT by wastedyears (George Orwell was a clairvoyant.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: UnsinkableMollyBrown; admin

Keep this up in breaking, please.


43 posted on 09/26/2007 8:10:09 AM PDT by sarasota
[ Post Reply | Private Reply | To 40 | View Replies]

To: publana

From reading the entire ebay thread, I’ve seen multiple stories come out from eBay. Knowing eBay, I don’t have much faith in any of their stories. I hope it’s a hoax, but I cancelled my credit cards, notified my bank, and changed all passwords just in case.


44 posted on 09/26/2007 8:11:00 AM PDT by publana (Build the fence!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: N. Theknow

No, it didn’t come via email. It came from an eBay discussion board (did the link not work?) where users sat and watched the information being posted.


45 posted on 09/26/2007 8:13:41 AM PDT by publana (Build the fence!)
[ Post Reply | Private Reply | To 21 | View Replies]

To: publana

I just changed paypal password,here’s a bump.


46 posted on 09/26/2007 8:18:27 AM PDT by fatima (Baby alert,Baby Ava arrived 6-29-07 at 3 PM-she is 10 pounds:))
[ Post Reply | Private Reply | To 44 | View Replies]

To: publana

Bump


47 posted on 09/26/2007 8:19:26 AM PDT by painter (Oval Office, Fred. Might be something you ought to think about.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: publana

Ah, yes, paying by check....


48 posted on 09/26/2007 8:19:45 AM PDT by the OlLine Rebel (Common sense is an uncommon virtue.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: lkco

One thing I’ve seen with some of these links, they use scripts to try to overlay official ebay links, especially the ebay login page link, onto your address bar. When your screen comes up, it will almost look as if it’s the official ebay site, address and all.

Just to add to your info.


49 posted on 09/26/2007 8:20:39 AM PDT by kenth
[ Post Reply | Private Reply | To 25 | View Replies]

To: publana

OK We are not on that list.


50 posted on 09/26/2007 8:20:54 AM PDT by fatima (Baby alert,Baby Ava arrived 6-29-07 at 3 PM-she is 10 pounds:))
[ Post Reply | Private Reply | To 9 | View Replies]


Navigation: use the links below to view more comments.
first 1-5051-71 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson