Russian Web site offered eBay account info for $5
Scope of problem 'would make the hair on your neck stand on end'
IDG News Service - EBay Inc. helped to shut down a Russian Web site this week that was offering to sell stolen customer account information for as little as $5 each.
Armed with an eBay customer's log-in and password, a fraudster could post items for sale, collect payments and then never deliver the goods. The site was also offering to sell a handful of PayPal accounts.
Security vendor Sunbelt Software detected the site Tuesday and reported it to eBay, which worked with the local ISP (Internet service provider) to have it taken off-line, an eBay spokeswoman confirmed. She couldn't say how many user accounts were offered for sale or whether any customers' accounts had been misused.
The site probably collected the information through phishing attacks or a Trojan horse virus that plants keylogging software on users' PCs, said Alex Eckelberry, president of Sunbelt, in Clearwater, Fla.
Attempts to harvest and sell such information are fairly widespread, he said. "It would make the hair on your neck stand on end if you knew," he said.
The site, at ebayseller.cc, was inaccessible Friday morning, but Eckelberry posted screen captures in his blog that appeared to show account information for sale from customers in the U.K., Germany and Australia.
The site preferred accounts that were used infrequently, meaning a user would take longer to notice any suspicious activity, and asked a higher price for accounts with good feedback ratings. Prices ranged from $5 to $25 per account.
"We're in contact with law enforcement to track down the perpetrators and we're going to vigorously pursue this investigation to ensure they are prosecuted," the eBay spokeswoman said.
A check on the Whois database showed the Web site was registered on Dec. 2, 2005, allegedly to a company in Cypress, Calif. There was no reply Friday at the phone number provided, although the site's creator would be unlikely to use real contact information.
EBay reiterated its guidelines for customers to avoid having their data stolen: Be extremely wary of e-mail that ask you to update personal account information, download eBay's toolbar with software that detects fraudulent eBay and PayPal sites and report suspicious e-mail.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Cybercrime and Hacking White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Cybercrime and Hacking Webcasts