Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

9/24/2010
03:27 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Alleged Phishers Who Targeted eBay Employees Arrested

Romanian authorities apprehend men suspected of using stolen credentials to access eBay client database

Romanian officials have arrested three men suspected of phishing some 3,000 eBay employees for their user names and passwords, according to published reports.

The men -- Liviu Mihail Concioiu, 22; Vladut Nnicolae (a.k.a "Calu"), 24; and Ardelean Calin Pavel, 25 -- reportedly waged the phishing attacks, according to a report on the site Internet Scammers. The attacks began last year.

The suspects used the stolen credentials to access internal eBay files, including a database of eBay clients and their transactions. Concioiu, the alleged ringleader, is suspected of setting up phishing sites in order to hack into the accounts of about 1,200 eBay users, according to the Associated Press.

Gary Warner, director of research in computer forensics at the University of Alabama, blogged today that the attackers were able to successfully steal the credentials of six of the 3,000 eBay employees. "We don't know how many gave up their passwords, but the criminal only tried to use six of them. The VPN site he was imitating was protected with a two-factor authentication solution, so any passwords gathered had to be used immediately due to the rotating 'secureId' style token," Warner wrote in his post.

The men withdrew some $400,000 from Italian bank accounts. eBay worked with Romanian and U.S. authorities on the case for over a year, and Romanian police used search warrants at the homes of four other suspects in the case.

Meanwhile, eBay released this statement about the case: "The Romanian authorities' arrest of Liviu Mihail Concioiu and his conspirators is a great victory in the global fight against Internet fraud. eBay's internal investigations team has been working closely with Romanian and U.S. law enforcement on this investigation since May of 2009, and we are confident that the evidence will link these individuals to a series of online attacks and organized criminal activity."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-38095
PUBLISHED: 2021-08-05
The REST API in Planview Spigit 4.5.3 allows remote unauthenticated attackers to query sensitive user accounts data, as demonstrated by an api/v1/users/1 request.
CVE-2021-32598
PUBLISHED: 2021-08-05
An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability In FortiManager and FortiAnalyzer GUI 7.0.0, 6.4.6 and below, 6.2.8 and below, 6.0.11 and below, 5.6.11 and below may allow an authenticated and remote attacker to perform an HTTP request splitting...
CVE-2021-32603
PUBLISHED: 2021-08-05
A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and services on the system via specifically crafte...
CVE-2021-3539
PUBLISHED: 2021-08-04
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.
CVE-2021-36801
PUBLISHED: 2021-08-04
Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.