Breach report
RetaileBay
Hackers raid eBay in historic breach, access 145M records
Attackers used stolen employee logins to reach an eBay database holding records on roughly 145 million users, prompting the marketplace to ask its entire user base to reset passwords in one of the largest breaches of its era.
Reported by CNBC
Records exposed
145M
145 million user accounts
Scale vs. largest on file
- When
- 2014
- How they got in
- Compromised employee login credentials
- Sector
- Retail
On May 21, 2014, eBay disclosed that hackers had broken into a corporate database containing user records and urged all of its users to change their passwords. The online marketplace said the intrusion took place between late February and early March 2014 and was discovered in early May. The compromised database held information on about 145 million accounts, making it one of the largest breaches ever disclosed by a U.S. company at that point, second only to Adobe's 2013 incident by account count.
According to eBay, the attackers obtained login credentials belonging to a small number of employees, which gave them access to the corporate network and ultimately to the user database. The company did not publicly detail how the employee credentials were stolen. It brought in outside forensic investigators, including Mandiant, to examine the incident.
The stolen data included customer names, encrypted passwords, email addresses, physical addresses, phone numbers and dates of birth. eBay said the database did not contain financial information such as credit card numbers, and that PayPal data, stored separately on encrypted systems, was not affected. The company said it had found no evidence of unauthorized activity on user accounts, but recommended that users who had reused their eBay password on other sites change it there as well.
The disclosure drew criticism for its timing and communication. Roughly two weeks passed between discovery and public notice, and early messaging was confusing, with a notice briefly appearing on a PayPal site before eBay's formal announcement. Several U.S. state attorneys general, including those in Connecticut, Florida and Illinois, said they would examine the company's handling of the incident, and European data protection regulators also raised questions. The breach landed as eBay was already under pressure from activist investors over its PayPal business.
The eBay incident illustrated how the theft of a handful of staff credentials can expose data on a vast customer base when internal systems lack segmentation and strong authentication. It also reinforced a durable lesson for consumers: even encrypted passwords can eventually be cracked, so reusing a password across services multiplies the damage of a single breach. The episode helped push large platforms toward multifactor authentication for both employees and customers.