100 fake eBay listings put users' privacy at risk

Innocent users' accounts being used to post malicious listings

Ebay Logo

More than 100 eBay listings have been identified as malicious by the online auction site, leading customers to reveal their personal details including payment information.

A number of customers contacted the BBC to tell them they had tried to warn eBay about the issues reported last week, but eBay had not addressed them as quickly as they should have.

The listings in questions appeared normal, but custom Javascript and Flash content contained in them allowed hackers to redirect users to a fake website that looked legitimate but actually allowed them to siphon off user details including credit card details.

The listings were posted by many innocent eBay users whose accounts had been hijacked by the hackers and forwarded the bidders to a page that said eBay was trying to update the innocent user's details, asking for payment information including card details and in some cases, account numbers and sort codes.

Those whose accounts were being used to perform the attacks were receiving emails congratulating them on the sale of their items, which they had not even put up for sale in the first place.

eBay said: "Account takeovers generally occur as a result of a user disclosing their IDs or password. Unfortunately, it is a common practice of criminals to exploit well-known, trusted brand names like eBay to attract consumers and then lure them to a fake website or into other fraudulent situations."

The company continued: "Many of our sellers use active content like Javascript and Flash to make their eBay listings perform better.

"We have no current plans to remove active content from eBay. However, we will continue to review all site features and content in the context of the benefit they bring our customers as well as overall site security."

Featured Resources

Defeating ransomware with unified security from WatchGuard

How SMBs can defend against the onslaught of ransomware attacks

Free download

The IT expert’s guide to AI and content management

How artificial intelligence and machine learning could be critical to your business

Free download

The path to CX excellence

Four stages to thrive in the experience economy

Free download

Becoming an experience-based business

Your blueprint for a strong digital foundation

Free download

Recommended

The benefits and drawbacks of flash storage in 2021
flash storage

The benefits and drawbacks of flash storage in 2021

14 Sep 2021
IBM FlashSystem 5000 and 5200 for mid-market enterprises
Whitepaper

IBM FlashSystem 5000 and 5200 for mid-market enterprises

9 Jul 2021
Nigerian cyber criminals target Texas unemployment system
cyber security

Nigerian cyber criminals target Texas unemployment system

27 May 2021
Qnap TS-h2490FU QuTS hero edition review: Smash hit flash
network attached storage (NAS)

Qnap TS-h2490FU QuTS hero edition review: Smash hit flash

18 May 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
Citrix mulling potential sale after tumultuous 2021
mergers and acquisitions

Citrix mulling potential sale after tumultuous 2021

15 Sep 2021
Zoom: From pandemic upstart to hybrid work giant
video conferencing

Zoom: From pandemic upstart to hybrid work giant

14 Sep 2021