123ArticleOnline Logo
Welcome to 123ArticleOnline.com!
ALL >> Computers >> View Article

How Bad Is The Ebay Breach? Here Are The Stats

Profile Picture
By Author: Skyhighnetworks
Total Articles: 54
Comment this article
Facebook ShareTwitter ShareGoogle+ ShareTwitter Share

eBay announced today that hackers had infiltrated their systems and stolen the passwords of 145 million users. In addition to account passwords, hackers obtained names, email addresses, birthdates, physical addresses and phone numbers.

Was financial information compromised?

According to eBay, the breach did not include credit card numbers or financial information from PayPal, which is owned by eBay. (For the latest from eBay, visit their blog.)

That being said, eBay users are now particularly subject to phishing attacks. Reason being is that criminals will have access to personal information that could help them trick an unsuspecting eBay user into sharing additional information or clicking on a malicious link.

How the breach was discovered

Mark Carges, eBay’s Chief Technology Officer, said the company discovered the breach after noticing several unusual behaviors on the company network. Essentially, eBay detected anomalies (activities statistically separated from normal behavior) in their network usage. It’s worth noting that Skyhigh uses a similar strategy to identify ...
... security breaches at customers, but instead of looking for anomalies in the network usage within an enterprise, we look for anomalies in all data leaving your enterprise.

Upon investigating, Carges and the FBI discovered that hackers had learned employee passwords and used their credentials to access internal systems, starting in as far back as February.

The question enterprises are now asking is, “How bad is it?”

How bad is it?
In terms of breadth – this breach has widespread reach. Our data shows that 99% of companies have employees who are using eBay, and doing so from work. Even more, the average Fortune 2000 company has just approximately 15,800 employees using eBay.

In terms of impact to corporate Security, this breach does not have the impact of the Heartbleed vulnerability or even XP’s end of support. Reason being is that most eBay users visit the service exclusively for personal reasons and do not store sensitive corporate data within the service.

That being said, employees often use the same password across Cloud Security services. According to a recent study by Joseph Bonneau, from the University of Cambridge, 31% of passwords are re-used. This is critical because it means that hackers can use eBay credentials to guess the login/password information of other corporate cloud services. Applying the 31/100 ratio from the study across the average 15,800 eBay users per company shows that approximately 4,900 employees per company have passwords to other cloud services that could be guessed using compromised eBay credentials.

Attackers could also conduct phishing attacks that could compromise their devices and put corporate data at serious risk. For this reason we advise eBay customers to change all of their credentials for all cloud services if they match those used in eBay.

In addition, Skyhigh continuously analyzes cloud service usage and will alert customers of any unusual behavior that may indicate a breached account.

Author :
Skyhigh Networks, the Cloud Security Services company, enables companies to embrace Cloud Security Services with appropriate levels of security, compliance, and governance while lowering overall risk and cost. With customers in financial services, healthcare, high technology, media, manufacturing, and legal verticals, the company was a finalist for the RSA Conference 2013 Most Innovative Company award and was recently named a "Cool Vendor" by Gartner, Inc. Headquartered in Cupertino, Calif., Skyhigh Networks is led by an experienced team and is venture-backed by Greylock Partners and Sequoia Capital. For more information, visit us at http://www.skyhighnetworks.com/ or follow us on Twitter@skyhighnetworks.

Total Views: 513Word Count: 572See All articles From Author

Add Comment

Computers Articles

1. Modern Software At Scale: A Practical Guide To Microservice Development
Author: Tech Gazebos

2. The Financial Cost Of Ignoring Computer Repairs: A Westlake Case Study
Author: Arun Singh

3. Cloud Computing Companies In India | Cloud Hosting Service Providers In India | Sathya Technosoft
Author: Sathya Technosoft

4. Embedded Systems Advantages And Disadvantages
Author: Embeddedhash

5. Why Essae Pos Machines Are Ideal For Retail Growth
Author: pbs

6. Best Wordpress Development Companies In India For Business Growth
Author: Web Panel Solutions

7. How Enterprises Leverage It Consulting Companies In The Usa For Cybersecurity
Author: Abiel

8. Cash Drawer Security Tips For Retailers | Prime Poskart
Author: prime poskart

9. Successful Vb6 Migration And Upgrade
Author: Tech Gazebos

10. Soluzioni Complete Per La Stampa In Ufficio: Assistenza, Noleggio E Manutenzione Professionale
Author: Mihai Filip

11. Cheap Vps Hosting & Dedicated Server Solutions – Fast, Secure & Affordable | Rackoona
Author: Rackoona

12. Reliable Temperature Monitoring Solutions Enhancing Drug Safety And Freezer Storage Compliance By Tempgenius
Author: Chris Miller

13. Spark Matrix™: Evaluating Security Information And Event Management (siem) Solutions For Scalable And Intelligent Security Operations
Author: Umangp

14. How To Get In Touch With Bellsouth Customer Service By phone?
Author: frank rayan

15. Bca In Cyber Security Online: Curriculum, Labs, And 2025 Modules
Author: UniversityGuru

Login To Account
Login Email:
Password:
Forgot Password?
New User?
Sign Up Newsletter
Email Address: