Home U.S. Coin Forum

Can someone explain how an ebay account is hijacked?

I just received an email from an ebayer in my "ask seller a question" He pointed out to me to paste a site because he saw a similar item that I was selling. This site was flagged by internet explorer as a known phising website. I got the warning not to precede to the website. Has this ever happened to any of you ebay sellers? I just wonder if I preceded to that phising website if they could automatically infiltrate my computer. The ebayer who sent me the email has about 12 feedback all positive. The item I am selling is now bid up to multi-thousands of dollars.

Comments

  • flaminioflaminio Posts: 5,664 ✭✭✭
    Did it come in your email, or in your My eBay? Email is completely spoofable, and it's unlikely anything in the email was legitimate.

    If the phishers have figured out how to scam via My eBay, life gets a little more complicated.
  • It happens all the time. If I ever get a message from Ebay in my e-mail, I automatically go to My Ebay messages and if it's not there, the e-mail is a phishing scam, which I then report to Ebay at Spoof@ebay.com.
    Cheryl........."She was not quite what you would call refined. She was not quite what you would call unrefined. She was the kind of person that keeps a parrot." - Mark Twain

    Cher-Wood Forest Aviary

    image

    POTD - May 26, 2005
  • morgansforevermorgansforever Posts: 8,501 ✭✭✭✭✭
    Something similar happened to me recently. I was logged into ebay, cleaning up clutter in my messages, when a page appeared asking me for username and password. Turns out it was a redirct link, which collects sign in data. The key here is not to sign in, and type the complete url in the address bar. I did send ebay the complete url, no response yet.

    morgans
    World coins FSHO Hundreds of successful BST transactions U.S. coins FSHO
  • morgansforevermorgansforever Posts: 8,501 ✭✭✭✭✭
    <<It happens all the time. If I ever get a message from Ebay in my e-mail, I automatically go to My Ebay messages and if it's not there, the e-mail is a phishing scam, which I then report to Ebay at Spoof@ebay.com.>>


    Good info. image
    World coins FSHO Hundreds of successful BST transactions U.S. coins FSHO
  • pf70collectorpf70collector Posts: 6,840 ✭✭✭
    This was in both my ask seller a question and my messages folder on ebay. Its a very high profile item I am selling.


  • Seems these clowns can now redirect you by using the "ask a seller a question" feature. That way it shows up in "My Messages" like it's legit. It's not and I wouldn't try doing the copy and paste. I am sure it's totally bogus!!

    Larry
    Dabigkahuna
  • pf70collectorpf70collector Posts: 6,840 ✭✭✭
    I never entered the phising site, but if I did I was just wondering if they could get access to my computer. Should I report this ebayer who sent the message to ebay?
  • robertprrobertpr Posts: 6,862 ✭✭✭


    << <i>I never entered the phising site, but if I did I was just wondering if they could get access to my computer. Should I report this ebayer who sent the message to ebay? >>



    That depends on what browser you're using and how tightly bolted down you have the security. If they have an activeX script running that does an automatic install of something, they could.
  • pf70collectorpf70collector Posts: 6,840 ✭✭✭
    How is an ebay account hijacked?
  • robertprrobertpr Posts: 6,862 ✭✭✭


    << <i>How is an ebay account hijacked? >>



    Typically, an email looking like it is from eBay is mass sent out to thousands of email addresses. The email directs the recipient to click on a link and log in to ebay. The email will be something looking like a question from another eBayer, an "official" request to update account information, a link to information, or some other excuse. The point is, the email will try to get someone to click a link to go to "ebay" (or to "paypal")

    The site the link sends the person to looks just like ebay, but it's not. Once the person tries to log in using their ebay name and password, the information is recorded and the scammers use that to log in to ebay, change the password, and go to town. They may change the address to which paypal payments are sent, or just take cash check or money order. They put up auctions, all bogus, on the hijacked account, and wait for the money to start rolling in.
  • pf70collectorpf70collector Posts: 6,840 ✭✭✭
    thanks robertpr. Wasn't sure how this was done.
  • I got a similar thing and it was in my Ebay messages as well. I reported it a few minutes ago and added the user "prjppparks0wk9" to my blocked bidder list.
  • I got one of those today, and it was in my ebay messages. Exactly the same as described by OP, except different user. I clicked on the user feedback...no activity in over a year

    FloridaBill
  • notwilightnotwilight Posts: 12,864 ✭✭✭
    The e-mail you recieved did not come from the referenced e-bayer. The scammer just picked his ID as an identity to represent.

    Clicking on the link almost certainly caused no problem. I click on them all the time and my spyware/virus software never finds anything there. What they wanted you to do is to log into their fake site. Logging in would give them your id and password. That's the hijack. If you're at all worried change your password.

    I got one of these tonight. I contacted the ebay ID that it supposedly came from and made him aware. he thanked me. I forwarded the e-mail to spoof@ebay.com with a note that I had made the 3rd party aware of the scam.

    -Jerry
  • BochimanBochiman Posts: 25,790 ✭✭✭✭✭
    Yes,

    I got something like that, last month, and it was in the ebay system as well.
    I posted about it when it happened.

    I've been told I tolerate fools poorly...that may explain things if I have a problem with you. Current ebay items - Nothing at the moment

  • notwilightnotwilight Posts: 12,864 ✭✭✭
    If it comes through the ebay system then they are using a hijacked account to send out their phishing messages to hijack more accounts. --Jerry
  • pf70collectorpf70collector Posts: 6,840 ✭✭✭
    ebay sent me a message about me receiving an email outside of ebay. SP NOTICE: eBay Ask Seller a Question or Contact eBay Member Alert" I replied about receiving this email from this ebayer in question. Told them to investigate though I did block this ebayer as a precaution.
  • IrishMikeIrishMike Posts: 7,737 ✭✭✭
    Just two days ago I got a phising email from paypal wanting me to log into their site and update. I don't even have a paypal account. Lately someone has been sending out purported email from Comcast. You go to that page and not only do they want your credit card number but they ask for you pin # too. I've received this notice 3 times and Comcast has yet to even alert its customers of this.
  • jmski52jmski52 Posts: 23,956 ✭✭✭✭✭
    I get PayPal update requests all the time. I don't use PayPal. These guys should be taken out, literally.
    Q: Are You Printing Money? Bernanke: Not Literally

    I knew it would happen.
  • My account was hijacked yesterday. I got on my pc about 3PM to retrieve mail and I had 55 notifications of ebay posting of items to sell. I logged into ebay and was denied access to my account due to incorrect login info. Checked my paypal account, credit cards & check acct linked to PP and they seemed OK.
    I never open emails nor access links that I am not absolutely positive of what they are or who they are from. I run all the latest norton firewall/anti-virus software, so I think I'm protected pretty well....evidently not.
    I contacted ebay live help via my wife's ebay account and, surprise to me, they responded almost immediately.
    Ebay deleted all the bogus auctions and suspended my account. They told me, via e-mail, how to re-instate the account and reset the password. It all worked fne.
    I have no clue how my logon/password got hijacked. Just have to be cautious than ever I guess
  • I think I am done with Ebay personally.

    Plenty of better places to buy coins.

Leave a Comment

BoldItalicStrikethroughOrdered listUnordered list
Emoji
Image
Align leftAlign centerAlign rightToggle HTML viewToggle full pageToggle lights
Drop image/file