eBay hack: Offer of Malaysian account details not authentic (Update 2)
- Leaked sample of predominantly Malaysian debts purportedly supplied as evidence
- eBay denies info is actual, still urges clients to alternate passwords

[Article updated with eBay statement to DNA]
FOLLOWING the disclosure through online marketplace eBay this week that hackers had gained get admission to to the non-public facts of clients, gives to sell the information have surfaced with a pattern of 12,000 debts, predominantly Malaysian, being provided as evidence. However, eBay denied the information is true.
"In reaction to your question, the published lists we have checked to this point aren't proper eBay bills. We nonetheless inspire users to go to eBay to change passwords," a spokesman advised Digital News Asia (DNA) via email.
The spokesman said more information is to be had at the organization's blog and entreated users to refer to its FAQs.
eBay first publicly disclosed a breach on Wednesday (May 21), mentioning that it discovered the hack approximately weeks ago and that the database was compromised between late February and early March.
It did not expose how tons of the facts inside became copied, but the breach impacts doubtlessly all of its 233 million customers worldwide.
There are as a minimum half of a dozen such gives to promote the stolen records circulating, each with a distinct contact e-mail and Bitcoin deal with to ship the cryto-foreign money to, with fees starting from zero.5BTC to one.453BTC (approx. US$257.74 to US$748.98 at modern trade fee).
One provide to promote told the ones interested in acquiring the whole list to transfer bitcoins (BTC) to an address and consists of a link to a downloadable file containing a sample of the leaked information as proof of the provide’s legitimacy.
With the description “pattern sell off of 12 663 customers from apac location”, approximately 10,000 users are from Malaysia according to individuals of the nearby tech community who alerted Digital News Asia (DNA) to their discovery.
Once downloaded, the CSV record consists of a listing of names in conjunction with names, addresses, phone numbers, and password hashes, which may be decrypted to reveal the facts.
A technology consultant based totally in Kuala Lumpur, Derek Chong, referred to that humans purporting to be selling the eBay unload were “spreading quite a bit within the previous few hours genuinely” (overdue Thursday night time).
“I reckon there’s a truthful hazard the ones are faux as the timing's lousy convenient. I imply, in the event that they had them for 2 weeks and sat on them till the day after eBay publicizes the leak, it doesn’t make any experience,” he stated when asked approximately the legitimacy of the declare.
“It’s probable just scammers trying to get people to ship them bitcoins. I just wonder where they got the Malaysian person information from,” he introduced.
Security expert and freelance IT solutions issuer @sniiffit echoed Chong’s scepticism at the legitimacy of the offer.
“The quantity he's asking is a piece a good deal, and with an example that I have to brute force myself? EBay has been in enterprise for a long time; if I managed to get a unload in their database, I’d as a substitute have it blown all out within the open rather than trying to sell it.
“But then again, everyone has unique motivations to their actions. As it stands, we will’t confirm the authenticity of the dataset, eBay will have to be the one to do this,” he delivered.
The hacked database contained records which include names, electronic mail addresses, delivery dates, encrypted passwords, physical addresses, and speak to numbers.
According to a New York Times file, eBay said that there was no indication that the attackers obtained economic information which include credit and debit card numbers or gained get admission to to purchaser bills at PayPal.
However, despite eBay reporting no proof of fraudulent hobby that would be connected to the breach, protection experts have said that the stolen facts should nevertheless be used for identity robbery.
Related Stories:
Heartbleed pierces OpenSSL, exposing sixty six% of Net to attack
APAC organisations and consumers to pay dearly for security breaches
PDPA: Need for mandatory statistics breach notification; SMBs prone
Companies unprepared for information privacy risks
For greater technology news and the modern day updates, comply with us on Twitter, LinkedIn or Like us on Facebook.