On May 2014, eBay announced that in a breach of the company’s database between late February and early March, hackers obtained several of their employees login credentials (FT.Com, 2014).
Data breach is the successful retrieval of sensitive information by an individual, group, or software system (Pollard, Turban, &Wood, G, 2018). This gave the hackers access to the names, addresses, telephone numbers, email addresses and passwords of its 128m active users (FT.Com, 2014).
EBay responded to the attack by only asking its active users to reset their passwords. Additionally, eBay was criticized at that time for a lack of communicating informing its users and poor implementation of the password-renewal process (Ragan, 2014). The cost was unreachable somehow, but there was a decline in user activity on eBay which is understandable.
As a business manager, a company needs to assume that all other security measures may fail, and the data itself must be a primary focus for protection – usually via encryption (M2 Presswire, 2014). It is critical to note that this protection needs to include all potentially sensitive information and not just financial related data (M2 Presswire, 2014).
If eBay had employed format-preserving encryption to protect the data itself, the attackers would have ended up with unusable encrypted data instead of the current outcome where users’ personal information has now been exposed to an untold number cyber criminals (M2 Presswire, 2014).
Learning from the eBay cyber attack. (2014). FT.Com, Retrieved from https://search-proquest-com/docview/1538915759?
Pollard, C., Turban, E., Wood, G. (2018). Information technology for management: On-demand strategies for performance, growth, and sustainability (11th ed.). Hoboken, NJ: John Wiley & Sons, Inc.
Ragan, S. (2014, May 21). Raising awareness quickly: The eBay data breach. Retrieved February 6, 2019, from https://www.csoonline.com/article/2157782/leadership-management/security-awareness-raising-awareness-quickly-the-ebay-database-compromise.html
Voltage security comment on eBay cyber attack. (2014, May 21). M2 Presswire Retrieved from https://search-proquest- com.