← Case Files · The Breach Files

2014 · Marketplace

eBay, 2014: 145 million users and a notice nobody saw

Case file · 4 min read · Published 14 September 2026

People affected
145 million user records
When it happened
Late February – early March 2014, discovered in May
Made public
21 May 2014
How they got in
Compromised credentials belonging to a small number of eBay employees, used to reach the internal network
Attributed to
Never publicly attributed
What it cost
No major regulatory fine; a multi-state investigation closed without penalty

What was exposed: Names · Email addresses · Physical addresses · Phone numbers · Dates of birth · Encrypted passwords

The eBay breach is remembered less for how it happened than for how it was announced. A hundred and forty-five million people needed to change a password, and a large number of them found out from the news.

What happened

Some time in late February or early March 2014, attackers obtained login credentials belonging to a small number of eBay employees. eBay never said how — phishing was the widely assumed route and the company did not confirm it. With those credentials the attackers had a position on the corporate network, and from there they reached a database containing user records.

They were not detected for roughly two months. eBay discovered the compromise in early May and disclosed on 21 May, saying that 145 million records had been accessed: names, email addresses, postal addresses, phone numbers, dates of birth and encrypted passwords.

What made this an unusually clean example of a familiar problem is that no exploit was necessary at any point. Employee credentials worked. The internal network trusted anyone holding them. The user database was reachable from that network. Each of those three conditions was normal in 2014 and each of them is the thing that zero-trust architecture was subsequently designed to remove.

"No financial data was taken" is a sentence worth distrusting. It is almost always true and almost always beside the point. Card numbers are revocable, insured, and replaced within a week. A name, postal address, telephone number and date of birth can be revoked by nobody. They are the raw material for account recovery attacks, for convincing phone fraud, and for building a profile that connects to every other breached dataset — and they were, in this case, taken for a population the size of Russia.

The announcement

The disclosure itself was fast by the standards of 2014 — two weeks or so from discovery. The execution was not. The initial public statement appeared where users were not looking. Email notifications took days to reach everyone. The password reset prompt did not appear consistently on login. Journalists testing the site in the hours after the announcement found they could still sign in without being asked to change anything.

For an incident whose entire remediation depends on hundreds of millions of people performing one action, this is not a communications footnote. The difference between a well-run reset and a badly run one is measured in how many reused passwords stay live on other websites afterwards — and credential stuffing attacks in the following years drew on precisely that gap.

eBay also gave no detail about how the passwords were protected. "Encrypted" is not a specification. Whether a password is protected by a modern, deliberately slow hashing function or by something trivially reversible changes the advice by an order of magnitude, and users were given no basis to judge.

The timeline

  1. Late February – early March 2014 — Employee credentials are compromised and the user database is accessed.
  2. Early May 2014 — eBay detects the intrusion during a routine review of anomalous account activity.
  3. 21 May 2014 — Public disclosure; 145 million records confirmed as accessed. Users are asked to change passwords.
  4. 22 – 23 May 2014 — Criticism of the rollout mounts as notifications lag and reset prompts fail to appear for many users.
  5. Mid-2014 — The UK ICO and a group of US state attorneys general open investigations.
  6. 2014 – 2015 — Investigations conclude without significant penalties, in a pre-GDPR regime with limited enforcement powers.

What it changed

It demonstrated the value of practising the announcement. Incident response plans of the era covered containment, forensics and legal notification. They rarely covered the mechanics of forcing a password reset across a platform serving hundreds of millions of people, which turned out to be a substantial engineering problem that nobody had rehearsed.

It made "encrypted passwords" an unacceptable disclosure. The industry norm shifted towards naming the algorithm and work factor. Companies that use modern password hashing now say so explicitly, because after 2014 vagueness was widely read as an admission.

Internal network trust started to erode. The pattern — steal an employee credential, inherit the network's trust, walk to the database — recurs in almost every case file on this site. eBay is one of the clearest early examples at scale, and the architectural answer that emerged, treating every request as untrusted regardless of origin, was a direct response to exactly this.

It fed the credential stuffing era. eBay, LinkedIn, Adobe, MySpace and Yahoo between them put billions of email-and-password pairs into circulation in a handful of years. The combination lists that dominate breach data today were assembled from these events, and the attacks they enable still work whenever someone has reused a password.

If you had an eBay account then

  1. If you ever reused that password, it is still circulating. The specific risk is not eBay; it is the other account where the same password still works.
  2. Check the address against a breach search. Twelve-year-old exposure still determines which phishing lists you are on.
  3. Date of birth is the quiet one. It is a standard identity verification question and it was in this file for 145 million people.
  4. Turn on two-factor authentication on marketplace accounts. A hijacked seller or buyer account with genuine history is worth far more to a fraudster than a new one, which is why old accounts are targeted specifically.

Checked against every breach on record, against public breach data only. Your address is not sent to us as a form and is not stored — it is handed straight to the lookup tool in your own browser. See the privacy policy.

Questions people ask

Was financial data stolen from eBay?

No. PayPal was a separate company operationally at the time, on separate infrastructure, and eBay stated repeatedly that payment data was unaffected. That was true and it was also used to make the breach sound smaller than it was. Name, address, phone number, date of birth and email for 145 million people is a better identity fraud dataset than a card number, because none of it can be cancelled.

Were eBay passwords cracked?

eBay described the passwords as encrypted and never published the algorithm used, which meant nobody outside could assess how much protection that offered. In the absence of that detail the safe assumption for users was that the passwords would eventually be recoverable, and anyone who had reused an eBay password elsewhere needed to change it everywhere — which is exactly what the company should have said plainly.

Why was eBay criticised for its response?

The intrusion happened in late February or early March and was discovered in early May, and eBay disclosed on 21 May. When it did, the announcement went out awkwardly: a post appeared on the PayPal blog, the password reset prompt did not reach many users promptly, and there was no email to some account holders for days. For an event requiring 145 million people to take an action, the delivery of the message was the whole job.

Should I still worry about the eBay breach?

Not about the password, if you changed it. The durable exposure is the combination of full name, postal address, phone number and date of birth, which is still a working identity package twelve years later and still appears in combined data sets sold today.

Sources

Read next

Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.

← All case files Breach archive →