View all newsletters
Receive our newsletter - data, insights and analysis delivered to you

How the eBay data breach could affect 99% of companies

Skyhigh Networks’ data shows the average Fortune 2000 Company has 15,800 employees who use eBay.

By Ben Sullivan

Following the announcement from eBay that it suffered a data breach that has affected 145 million users, Skyhigh Networks, a cloud security firm, has said that 99% of companies have employees who use eBay.

The hackers infiltrated eBay’s systems and managed to gain access to the passwords and personal information of 145 million eBay accounts, including names, email addresses, birthdates, physical addresses and phone numbers.

Skyhigh Networks said that the implications from this attack have significant security cosequences for businesses.

Charlie Howe, Skyhigh Networks EMEA director, said: "A breach of this magnitude will inevitably have an impact on businesses, how could it not? In the case of eBay, because it’s so incredibly popular, it’s the sheer number of companies that may be affected that’s most alarming. Businesses need to take notice of this threat – it’s not just about your personal account."

Furthermore, the cloud security firm’s data suggests that the average Fortune 2000 Company has approximately 15,800 employees using eBay, demonstrating the breadth of the breach.

"Most eBay users do visit the service exclusively for personal reasons, and are unlikely to store sensitive corporate data within the service, which means that the impact of this breach in terms of corporate security will be dismissed by many. It’s a dangerous game to play, however, especially since many people will fail to heed eBay’s warnings and change their passwords.

Content from our partners
Scan and deliver
GenAI cybersecurity: "A super-human analyst, with a brain the size of a planet."
Cloud, AI, and cyber security – highlights from DTX Manchester

"Employees often use the same password across several cloud services and research from the University of Cambridge suggests that as many as 31 percent of passwords are re-used. What are the odds that employees up and down the country are using the same password on eBay as they are on their corporate cloud services? I’d say it’s pretty high, a certainty almost."

EBay have issued an advisory to its users recommending a change of password. There are over 14 million active eBay accounts in the UK, with the global user count adding up to nearly 233 million.

Matt Middleton-Leal, UK regional director at CyberArk security firm, said: "Protecting privileged accounts should be top priority for any business, not least because perimeter security is clearly failing. The way in for these malicious attacks is through the inside and, as such, protection needs to start here – at the heart of the organisation.

"Monitoring and controlling these powerful accounts every time they’re used is paramount to mitigating the impact of an inside breach. Businesses must start better protecting their assets and critical to this is securing the privileged accounts which form the primary vehicle for so many successful attacks."

In a statement, eBay said the database was breached between late February and Early March. PayPal said that its service has not been affected and customers’ financial information is safe.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.