100 fake eBay listings put users' privacy at risk
Innocent users' accounts being used to post malicious listings


More than 100 eBay listings have been identified as malicious by the online auction site, leading customers to reveal their personal details including payment information.
A number of customers contacted the BBC to tell them they had tried to warn eBay about the issues reported last week, but eBay had not addressed them as quickly as they should have.
The listings in questions appeared normal, but custom Javascript and Flash content contained in them allowed hackers to redirect users to a fake website that looked legitimate but actually allowed them to siphon off user details including credit card details.
The listings were posted by many innocent eBay users whose accounts had been hijacked by the hackers and forwarded the bidders to a page that said eBay was trying to update the innocent user's details, asking for payment information including card details and in some cases, account numbers and sort codes.
Those whose accounts were being used to perform the attacks were receiving emails congratulating them on the sale of their items, which they had not even put up for sale in the first place.
eBay said: "Account takeovers generally occur as a result of a user disclosing their IDs or password. Unfortunately, it is a common practice of criminals to exploit well-known, trusted brand names like eBay to attract consumers and then lure them to a fake website or into other fraudulent situations."
The company continued: "Many of our sellers use active content like Javascript and Flash to make their eBay listings perform better.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We have no current plans to remove active content from eBay. However, we will continue to review all site features and content in the context of the benefit they bring our customers as well as overall site security."

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Adobe releases third unscheduled Flash security update
News Software giant forced to act following discovery of flaw affecting video sharing site Dailymotion
By Clare Hopping
-
eBay UK users warned of cross-site scripting attacks in listings
News Online auction site falls victim to hackers who've tampered with listings to steal users' login details
By Caroline Donnelly
-
FBI allegedly used browser vulnerability to target child abuse ring
News American intelligence agency operation reportedly leads to Irish extradition.
By Jane McCallion
-
Hitachi unveils ‘industry first’ 25nm SSD
News The storage giant brings single-level cell NAND flash to enterprise storage.
By Jennifer Scott
-
Adobe focuses on cross-platform app development
News Adobe appeals to developers with cross-platform app tools.
By Paul Briden
-
Adobe tops security risk list
News Acrobat Reader leads the pack as the most risky PC vulnerability.
By Paul Briden
-
Web firm accused of spying on children
News Class action claims widget tracks users' online habits through Flash cookies.
By Martin James
-
Adobe slams Jobs’ blog as a ‘smokescreen’
News The chief executive of Adobe has hit back against Steve Jobs’ blog post, calling the accusations a smokescreen covering the real issue.
By Jennifer Scott