Email This Post Email This Post

eBay, Amazon, and USPS In the News for Security Issues

USPS United States Postal Service

USPS United States Postal ServiceAmazon, eBay, and USPS have received media attention for security issues this month during prime holiday-shopping season. With the reports we’re seeing about online and mobile shopping, it doesn’t appear that people are spooked in general, though it’s difficult to say with any precision what kind of impact these stories have on shopping behavior.

Amazon
Amazon inadvertently disclosed customer email addresses and names due to a technical error that has since been fixed, according to the company. (Oddly, in its letter to those impacted, it said “our website” disclosed the information.)

At least one reader told us how frustrating it was that Amazon wouldn’t provide them with details, and on Thursday, a site called TomsGuide.com reported that Amazon gave some customers gift cards to pacify them.

eBay
A security expert discovered a vulnerability in eBay’s Japanese marketplace, you can read about it on SlashCrypto.org (“HOW I DUMPED EBAY JAPAN’S WEBSITE SOURCE CODE.”) The researcher got added to eBay’s so called hall of fame (“public acknowledgement when reporting a potential security vulnerability”).

Ironically eBay CEO Devin Wenig was in Japan this week, telling Kyodo News he wants eBay to become one of the top Japanese ecommerce sites.

Sponsored Link

USPS
Security expert Brian Krebs has been critical of US Postal Service security especially around its Informed Delivery service for consumers. This month, he wrote about a vulnerability impacting an API tied to its Informed Visibility service for businesses.

“U.S. Postal Service just fixed a security weakness that allowed anyone who has an account at usps.com to view account details for some 60 million other users, and in some cases to modify account details on their behalf,” he wrote. You can find the story on KrebsOnSecurity.com.

Merchants, Be Vigilant
There was also a report that ElasticSearch, a search solution used by some online retailers, experienced a breach. ZDnet‘s headline: “ElasticSearch server exposed the personal data of over 57 million US citizens: Leaky database taken offline, but not after leaking user details for nearly two weeks.” It’s hard to know what merchants can do to prevent such incidents caused by third-party services that help power their websites.

ZDnet has a rather depressing slideshow of the biggest “hacks, leaks, and data breaches” in 2018 by month on this page. Remember to remain on your guard as a buyer and as a seller, even if you get an email with your name and other identifying information. And that applies to phone calls, as well – fraudsters can even spoof caller id.

Ina Steiner on EmailIna Steiner on LinkedinIna Steiner on Twitter
Ina Steiner
Ina Steiner
Ina Steiner is co-founder and Editor of EcommerceBytes and has been reporting on ecommerce since 1999. She's a widely cited authority on marketplace selling and is author of "Turn eBay Data Into Dollars" (McGraw-Hill 2006). Her blog was featured in the book, "Blogging Heroes" (Wiley 2008). Follow her on Twitter at @ecommercebytes and send news tips to ina@ecommercebytes.com.

One thought on “eBay, Amazon, and USPS In the News for Security Issues”

  1. Here in Michigan the USPS was accused of allowing anyone access to the informed delivery service that they have. All someone had to do was check the address and name of the person to see what was going to be delivered that day. If it looked good then the crook just undelivered the mail and got away with it. These people that are so paranoid about where their packages are signed up for the service and not they are getting rip off compliments of the incompentent USPS

Leave a Reply