[outages] eBay password changes -- were they attacked?

outages at maz.nu outages at maz.nu
Tue Apr 5 11:59:25 EDT 2016


> On 5 Apr 2016, at 16:51, DJ Anderson via Outages <outages at outages.org> wrote:
> When I inquired about it I was told that the password I was using was found on some leaked password list and due to that they had set a temporary password to protect my account. 

Late last year I worked on an abuse report (filed by eBay) where a customer server was hosting an eBay phishing page.  Despite the fact they were all meant to be emailed directly to the hackers, a bit of digging found the list of email addresses (and passwords) that had been captured by the phishing page.  eBay probably did exactly as above when we provided them with that list: changed passwords and contacted affected users.

Unless "we've changed your password and are contacting you to let you know" is the next level of the phishing scam ;-)

Marek Isalski




More information about the Outages mailing list