Hacked eBay accounts give rise to conspiracy theories

Roswell, the Kennedys and a hacker named Vladuz


Eagle-eyed conspiracy buffs have pounced on a recent rash of compromised eBay user accounts as proof of a mile-wide hole in the auctioneer's front lines, giving new life to a theory that could one day rival the intrigue surrounding Roswell UFO crashing and Kennedy assassinations.

Details remained sketchy, and of course, eBay managers have assembled the requisite wall of plausible deniability, but here's what we've pieced together so far: Over the past few days, several dozen eBay auctions - many selling pricey items such as Cartier Tank watches - have been hijacked by crooks who append legitimate auctions with notes suggesting would-be buyers contact a Gmail account for a special, "buy-it-now" discount. (Our initial Google search, trolling for tell-tale signs of the scam, returned 73 results; those numbers thinned over the next several hours, presumably, as the tired souls in eBay's security group pulled down offending pages.)

An eBay spokesman says all indications suggest that the accounts were compromised through plain-vanilla phishing techniques, in which unwitting users fall prey to spoofed emails and give passwords to their attackers. End of story, right?

Not quite. While the more timid among us would be tempted to agree with the company's party line, a chorus of eBay critics say there is something much more nefarious going on. They argue the episode is the latest proof of the existence of back door that has been built into the company's corporate network, allowing an attacker or a cadre of attackers to siphon login credentials and other confidential information from the site's users.

Who's in the Hoody?

Suspicions of a cover-up date back at least to December, when according to a post on The Auction Guild, a reader named Jack reported that his eBay account had been hijacked by crooks who were using it to sell BAPE Hoody shirts. On at least two occasions - once from a work PC, the other from his fire-walled home network - Jack retook control of his account and changed the passwords and other settings. Each time, the attacker was able to regain access.

"In trying to analyze what was going on, it appeared that the hijacker or hijackers had to have access to accounts independent of passwords, and have the ability to set account parameters so the legit account holder would not know what was going on," the Auction Guild posting theorizes. "If this is so, it either points to someone working inside eBay, or to a security hole so big, you can drive a tractor trailer through it."

A month later, Auction Guild was back, this time with evidence that a Romanian hacker going by the name Vladuz had developed and was circulating a sophisticated tool that reads confidential information residing on eBay's internal network, allowing attackers free reign of virtually any account and a trove of information that could be used in phishing attacks. A screen shot on another blog known to be hostile to eBay also purports to show Vladuz having gained the credentials of an eBay customer service representative on a public forum. "How about you start arguing in English?" the hacker taunts the crowd. "So I can laugh at you."

eBay spokesman Hani Durzy acknowledges that the hacker was able to gain access to a "single-digit number" of email accounts reserved for customer service employees, but he insists those accounts were maintained by servers that are entirely separate from the network where customer databases and confidential corporate information are stored. eBay officials know the identity of Vladuz and have alerted US and Romanian officials of his deeds, Durzy says.

But like any plausible denial, Durzy's is accompanied by a cloak of secrecy that officials say is necessary to maintain security, but that conspiracy theorists insist is designed to keep the lie alive. One such detail being kept under wraps is how Vladuz managed to gain the credentials of an eBay employee in the first place, or how officials can be sure the intruder never gained access to more sensitive parts of eBay's network.

Even more suspicious, according to AuctionBytes, is the recent removal of a link from an eBay forum that exposed account holders' names, addresses, and user names and passwords. Indeed, eBay officials appeared to have purged an entire forum thread where conspiracy theorists were discussing the vast cover up. (A capture of a more recent thread can be found here.

Not quite as compelling a plot as The X-files or Oliver Stone's JFK. But with all the round and round, we get the feeling this one may have more staying power. ®

Similar topics


Other stories you might like

  • Stolen university credentials up for sale by Russian crooks, FBI warns
    Forget dark-web souks, thousands of these are already being traded on public bazaars

    Russian crooks are selling network credentials and virtual private network access for a "multitude" of US universities and colleges on criminal marketplaces, according to the FBI.

    According to a warning issued on Thursday, these stolen credentials sell for thousands of dollars on both dark web and public internet forums, and could lead to subsequent cyberattacks against individual employees or the schools themselves.

    "The exposure of usernames and passwords can lead to brute force credential stuffing computer network attacks, whereby attackers attempt logins across various internet sites or exploit them for subsequent cyber attacks as criminal actors take advantage of users recycling the same credentials across multiple accounts, internet sites, and services," the Feds' alert [PDF] said.

    Continue reading
  • Big Tech loves talking up privacy – while trying to kill privacy legislation
    Study claims Amazon, Apple, Google, Meta, Microsoft work to derail data rules

    Amazon, Apple, Google, Meta, and Microsoft often support privacy in public statements, but behind the scenes they've been working through some common organizations to weaken or kill privacy legislation in US states.

    That's according to a report this week from news non-profit The Markup, which said the corporations hire lobbyists from the same few groups and law firms to defang or drown state privacy bills.

    The report examined 31 states when state legislatures were considering privacy legislation and identified 445 lobbyists and lobbying firms working on behalf of Amazon, Apple, Google, Meta, and Microsoft, along with industry groups like TechNet and the State Privacy and Security Coalition.

    Continue reading
  • SEC probes Musk for not properly disclosing Twitter stake
    Meanwhile, social network's board rejects resignation of one its directors

    America's financial watchdog is investigating whether Elon Musk adequately disclosed his purchase of Twitter shares last month, just as his bid to take over the social media company hangs in the balance. 

    A letter [PDF] from the SEC addressed to the tech billionaire said he "[did] not appear" to have filed the proper form detailing his 9.2 percent stake in Twitter "required 10 days from the date of acquisition," and asked him to provide more information. Musk's shares made him one of Twitter's largest shareholders. The letter is dated April 4, and was shared this week by the regulator.

    Musk quickly moved to try and buy the whole company outright in a deal initially worth over $44 billion. Musk sold a chunk of his shares in Tesla worth $8.4 billion and bagged another $7.14 billion from investors to help finance the $21 billion he promised to put forward for the deal. The remaining $25.5 billion bill was secured via debt financing by Morgan Stanley, Bank of America, Barclays, and others. But the takeover is not going smoothly.

    Continue reading

Biting the hand that feeds IT © 1998–2022