The encyclopedia · Software & IT · Operational decision · 2014
eBay's 2014 breach exposed 145M users — and the company waited three months to tell them
In 2014, hackers stole 145M eBay user records using employee credentials. eBay discovered it in May but didn't notify users until the press broke the story.
eBay · 2014-05
What happened
In early 2014, hackers used stolen employee credentials to access eBay's corporate network and exfiltrated a database containing approximately 145 million user records — names, addresses, phone numbers, dates of birth and encrypted passwords.
eBay discovered the breach in early May 2014 but did not publicly disclose it until May 21, after the story was reported by tech media. The three-week gap between discovery and disclosure was criticized, and eBay was accused of delaying notification to assess the damage before going public.
eBay urged all users to change their passwords. The case illustrated how employee credentials can be the weakest link in a large organization's security, and how the delay between discovery and disclosure erodes user trust more than the breach itself.
Why it happened
- Hackers used stolen employee credentials to access eBay's network.
- 145M user records were stolen.
- eBay discovered the breach in early May but did not disclose until May 21.
- The three-week delay between discovery and disclosure was criticized.
The lesson
Employee credentials are the weakest link. eBay's breach started with a stolen login, not a sophisticated exploit. The three-week delay eroded trust more than the breach itself.
Aftermath
eBay reset passwords and strengthened its authentication systems. The case contributed to the broader adoption of multi-factor authentication in enterprise environments.
Sources
spotted an error? The club wants to know.
More like this
PayPal bought Honey for $4B — then the coupon app stole creators' affiliate commissions
Coupang's 2025 breach: 34M accounts exposed by a former employee's data key
Okta's support engineer was screen-shared into — and 366 customers were breached
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.