EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/ebay-breach-2014
290/430

File EL-0141HighResolvedData Breach / Credential Theft

eBay Data Breach (2014)

Also filed as eBay Account Compromise · eBay Credential Theft

The 2014 eBay data breach involved the unauthorized exfiltration of credentials belonging to approximately 145 million user accounts. The compromised data included usernames, hashed passwords, and associated personal identifying information (PII). This incident highlighted the vulnerability of large e-commerce platforms to large-scale credential harvesting.

  • #ebay
  • #data-breach
  • #credential-theft
  • #2014
  • #pii
  • #account-compromise
Notoriety7/10
Event
1 Feb 2014
Disclosed
1 Feb 2014
Target
eBay Inc.
Scale
145.0M people
Status
Resolved

01Summary

The breach occurred when threat actors gained access to a database containing vast amounts of user account information from eBay's platform. The attackers primarily targeted credentials, which included usernames and passwords, many of which were stored using hashing algorithms. While eBay stated that passwords were hashed, the sheer volume of records and the nature of the data made the accounts susceptible to credential stuffing attacks. The data was subsequently sold or used on dark web marketplaces, facilitating identity theft and account takeover attempts. The incident prompted significant industry-wide discussions regarding password hashing standards and the necessity of multi-factor authentication (MFA) for e-commerce platforms.

02Background

Prior to 2014, e-commerce platforms were increasingly reliant on user-provided credentials, making them prime targets for cybercriminals. The growing volume of online transactions meant that a single breach could expose millions of users' private data. This incident served as a major wake-up call for the industry regarding data security best practices.

03Key revelations

  1. 01The sheer scale of the compromised user base, affecting over 145 million accounts.
  2. 02The vulnerability of hashed passwords to offline brute-forcing and rainbow table attacks.
  3. 03The necessity for e-commerce platforms to implement robust, modern authentication standards.

04Technical analysis

The breach was characterized by the exfiltration of a large database dump. The attackers likely exploited a vulnerability in the database access layer or an internal API endpoint. The primary goal was bulk credential harvesting, suggesting the attackers had sufficient access to query large swathes of user records. The data was valuable because it allowed for targeted attacks against users who reused passwords across multiple services.

Attack vector
Database vulnerability / Internal system compromise
Attack method
Credential Harvesting / Data Exfiltration
Initial access
Exploitation of internal system vulnerability
Lateral movement
Database access
Exfiltration
Bulk data transfer
Malware type
Stealer

Vulnerabilities exploited

  • Database Access Vulnerability

MITRE ATT&CK techniques

  • T1552

05Threat actor

The perpetrators were likely professional criminal groups specializing in large-scale data theft. Their focus on credentials suggests a sophisticated understanding of the value of identity data for subsequent financial fraud and account takeover.

Aliases

  • Credential Thieves

MITRE groups

  • T1078

Attribution sources

  • Security Researchers
  • Media Reports

06Victims and impact

Countries affected

  • United States
  • Global

07Data exposed

Data types

  • Usernames
  • Hashed Passwords
  • PII (Email addresses, names)

Notable documents

  • Compromised User Database Dump

08Financial damage

Damage estimate is difficult to quantify, but included costs of remediation, legal fees, and potential identity theft losses.

09Timeline

  1. 2013-12-01Initial unauthorized access to internal systems begins
  2. 2014-02-01Breach discovered and publicly disclosed

10Reaction and fallout

Public reaction

The public reaction was one of alarm, leading to increased awareness of the risks associated with password reuse. Consumers began adopting password managers and prioritizing unique, strong passwords for every online service.

Political impact

The incident contributed to a growing regulatory push globally for stronger data protection laws, influencing subsequent legislation like GDPR.

11Legal

eBay faced class-action lawsuits and regulatory scrutiny, leading to mandated improvements in their data security infrastructure and customer notification protocols.

Civil lawsuits

  • Class-action lawsuits filed by affected users

12Aftermath

Policy changes

  • Industry-wide adoption of stronger password hashing algorithms (e.g., Argon2, bcrypt)
  • Increased emphasis on Multi-Factor Authentication (MFA) implementation

Regulatory changes

  • Stricter adherence to data breach notification laws (e.g., GDPR principles)

Security improvements

  • Mandatory MFA implementation for high-value accounts
  • Implementation of rate limiting and behavioral analysis to detect credential stuffing

13Significance and legacy

Significance

This breach is a landmark case demonstrating the massive scale of credential harvesting in the e-commerce sector. It shifted the industry focus from merely protecting data at rest to actively managing user authentication and promoting unique password usage.

Legacy

The legacy of the 2014 eBay breach is the accelerated adoption of modern authentication standards across the digital economy. It solidified the industry understanding that password security is a shared responsibility between the platform and the user.

14Disclosure and media

Authentication
Industry analysis and public disclosure

Media partners

  • Reuters
  • The Hacker News

Publishing organisations

  • Security Researchers

15Field notes

  1. 01The breach highlighted the danger of password reuse, a practice that remains a major security risk today.
  2. 02The incident contributed to the early push for industry standards like OAuth and MFA.

16Resolution

eBay implemented significant security upgrades, including mandatory MFA options and enhanced database encryption, to mitigate future risks.

17Sources

Official documents

  • eBay Security Advisory Reports

References

  1. [1]Major cybersecurity news outlets reports (2014)
  2. [2]Industry security whitepapers
Fact sheetEL-0141

Dates

Event
1 Feb 2014
Started
1 Dec 2013
Ended
1 Feb 2014
Discovered
1 Feb 2014
Disclosed
1 Feb 2014
Ongoing
No

Target

Organisation
eBay Inc.
Type
Corporation
Sector
E-commerce
Country
United States

Actor

Type
Criminal Gang
Motivation
Financial gain through identity theft and account takeover
Arrested
No
Convicted
No

Data

People
145,000,000
Records
145,000,000
Volume
145 million records
Sensitivity
Confidential
Published
No
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.