100 fake eBay listings put users' privacy at risk

Innocent users' accounts being used to post malicious listings

Ebay Logo

More than 100 eBay listings have been identified as malicious by the online auction site, leading customers to reveal their personal details including payment information.

A number of customers contacted the BBC to tell them they had tried to warn eBay about the issues reported last week, but eBay had not addressed them as quickly as they should have.

The listings in questions appeared normal, but custom Javascript and Flash content contained in them allowed hackers to redirect users to a fake website that looked legitimate but actually allowed them to siphon off user details including credit card details.

The listings were posted by many innocent eBay users whose accounts had been hijacked by the hackers and forwarded the bidders to a page that said eBay was trying to update the innocent user's details, asking for payment information including card details and in some cases, account numbers and sort codes.

Those whose accounts were being used to perform the attacks were receiving emails congratulating them on the sale of their items, which they had not even put up for sale in the first place.

eBay said: "Account takeovers generally occur as a result of a user disclosing their IDs or password. Unfortunately, it is a common practice of criminals to exploit well-known, trusted brand names like eBay to attract consumers and then lure them to a fake website or into other fraudulent situations."

The company continued: "Many of our sellers use active content like Javascript and Flash to make their eBay listings perform better.

"We have no current plans to remove active content from eBay. However, we will continue to review all site features and content in the context of the benefit they bring our customers as well as overall site security."

Featured Resources

Key considerations for implementing secure telework at scale

Identifying the security risks and advanced requirements of a remote workforce

Download now

The State of Salesforce 2020

Your guide to getting the most from Salesforce

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Rethink your cybersecurity strategy for the new world

5 steps to secure the enterprise and be fit for a flexible future

Download now

Recommended

Russia hacked Liam Fox's personal email to steal trade documents
phishing

Russia hacked Liam Fox's personal email to steal trade documents

4 Aug 2020
British teenager charged over Twitter hack
hacking

British teenager charged over Twitter hack

3 Aug 2020
Mid-year report says vulnerabilities up 22% in 2020
hacking

Mid-year report says vulnerabilities up 22% in 2020

30 Jul 2020
BlackRock banking Trojan targets Android apps
trojans

BlackRock banking Trojan targets Android apps

27 Jul 2020

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

3 Aug 2020
How to use Chromecast without Wi-Fi
Mobile

How to use Chromecast without Wi-Fi

4 Aug 2020
How do I fix the Windows 10 Start Menu if it's frozen?
operating systems

How do I fix the Windows 10 Start Menu if it's frozen?

3 Aug 2020