AuctionBytes Blog
Covering auctions, collectibles and marketplace selling.

AuctionBytes Blog The AuctionBytes Blog has been giving a voice to online merchants since its launch in 2005. Named one of the world's top 30 blogs in 2008 by "Blogging Heroes." Weigh in with your thoughts on the joys and pitfalls of selling online.
Sat Mar 28 2015 16:00:44

Etsy Responds to Reports of Account Mixups

By: Ina Steiner

Sponsored Link

Some Etsy users have reported finding themselves suddenly logged in to someone else's account, giving rise to concerns about security on the site. Etsy spokesperson Nikki Summer sent us a statement today in response to our inquiry:

"We have investigated this thoroughly and have found no evidence of a security breach. Unfortunately, we can't provide further details, as we cannot comment on specific member issues. We will continue to monitor this, as the privacy and security of our community is our utmost priority."

Here is a summary of what we discovered after a user notified us of the reports on Etsy's discussion boards.

Account Logged into a Unknown Account - link
Carrie from curiouscarrie  5:27 pm Feb 24, 2015 EST
This afternoon, after spending some time on Etsy (on my own account), I clicked on my profile picture to reach my conversations...After I clicked on my profile, I was taken to someone else's profile page. This person's account showed up on my computer, without me entering in any information. (I don't even know the person, who's account I had accessed and I had never logged off my own account.) I immediately exited and changed all my information, but thought it should be brought to someone attention.

Store Stat Error - Takes me to Store Set Up - link
Donna Fox from CrowStealsFire  12:30 pm Feb 24, 2015 EST
This is a weird one. I stay logged in on my desktop all the time (Firefox 31.0). I went to check my shop stats and was taken to an error page (I wasn't allowed to view). So I went to the Homepage and it wasn't mine. When I went back to stats, I was greeted with the store set up page with the user name "mybodyisacage" in the url and it asked me to enter in a shop name. (This has nothing to do with me.) I logged out of Etsy, logged back in and all was as it should be. But this is a bizarre error and I wanted to let the techs know.

Got logged onto a stranger's account? - link
Aubrey Campie from Videnda  2:27 pm Mar 10, 2015 EDT
So I was buying some stuff from an Etsy shop, clicked the "Check out button" and it redirected me into editing a listing...for someone elses' shop! At first I thought it was a listing of mine, but it was all in French - and I look up and see I'm logged into some stranger's account - I logged out as quick as I could, cleared all my cookies, but now I am so weirded out by this. Has this happened to anyone else?

Signed in as the wrong person - link
Melissa Clark 1:35 pm Feb 24, 2015 EST
I don't quite understand how this happened, but I was logged in under my name and my shop (BusyBeeBeadSupplies) and all of the sudden my account changed to someone named Melissa Clark. This is very concerning. Have I been hacked? Is this just a glitch? I really need to hear from administration on this one.

Automatically Logged into Strangers Account - link
Lyndsay Kugler from TheLuLuBluShoppe  4:47 pm Mar 25, 2015 EDT
Went to log into Etsy on my NEW phone, never logged in. And it automatically logged me in under someone elses account. It had all of their previous orders and credit card information. I could have easily ordered under their account. This is a HUGE BUG!! It has me scared for my own account! PLEASE ADDRESS THIS ISSUE

Three of the reports were made on February 24th, one on March 10th, and another on March 25th. If you've experienced any such issues, let us know.



Comments (15) | Permalink

Readers Comments

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: DingDong This user has validated their user name.

Sat Mar 28 17:34:53 2015

Doesn't look like a good thing to happen.
Didn't eBay have this problem, too?

Going public.
Removing Betsie from the sellers tool box.
Having access to others sellers account.
I think Etsy has eBayionisis.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: gizmo This user has validated their user name.

Sat Mar 28 19:21:34 2015

Wow. Thats scary.  

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: FREDDY This user has validated their user name.

Mon Mar 30 00:31:13 2015

Sure sounds similar to what ebay does.  Chad and rest of the good ol boys (& girls) just copy ebay. No smarts or imagination of their own. Have a feeling they are destroying a good site just like jd and boys did with ebay.  All about the greed.........

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: Noneya This user has validated their user name.

Mon Mar 30 01:25:51 2015

Interesting - as a seller I'd have expected an email notification about this glitch with a warning to check my account and notify Etsy if I noticed unexpected changers or orders in my account. Nothing. Sad that I'm finding out about this serious breach through ecommercebytes.
Have noticed that when sellers post messages about bugs, half the time the moderators replying either haven't read or understood the initial report and state ''Can't replicate it, sorry'' or request screen shots of the problem, or check mobile site issues using the full web version which is basically a different site.  

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: Watching the Wheels This user has validated their user name.

Mon Mar 30 02:16:03 2015

This isn't the first time that this type of thing has happened. For really interesting reads go back to 2009. Try searching for the Meta Tags fiasco. This was when Etsy had coded ''hand made'' into everybody's listings. They played stupid on that one for a very, very long time, too.

Etsy NEVER admits to their FU's, and will also attempt to get the sellers to believe that it HAD to be something done by the sellers.

I also had listings disappear from my shop once, that was somehow tied into the uploads to Google shopping.

They have always been mediocre, and I don't see that aspect of the corporate culture EVER, EVER CHANGING.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: sundance This user has validated their user name.

Mon Mar 30 02:19:00 2015

Super scary!! They're starting to have "oops" type happenings too much lately.  I'd heard something about this the other day and now I'm not too sure whether I want to keep my shop or not.  If it happens to me, I'll definitely send them screenshots.


Sundance

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: Watching the Wheels This user has validated their user name.

Mon Mar 30 04:34:15 2015

They have ALWAYS had "OOPS". It's like pulling teeth to get them to admit to it.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: A-Non-A-Mouse This user has validated their user name.

Mon Mar 30 05:06:10 2015

Actually, one's credit card and taxpayer ID is not displayed fully in the account settings, but one's monthly sales amounts are. Wouldn't keep the wrong person from altering your account information if they realized it, though, or even someone assuming they were logged into their own and changing it.

I have always had a problem with the live testing that goes on there and this is just a prime example as to why. Having worked with programming client systems, I can definitely attest to the fact that it doesn't have to be done this way. It's not difficult to copy over the processing environment and then load live or dummy data into it to test results of changes to the program. Most companies do it that way for very good reason. Maybe this will convince Etsy to do the same, but somehow I sort of doubt it.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: ebay refugee camp This user has validated their user name.

Mon Mar 30 10:10:57 2015

You should not be able to see your buyers card information, that is encrypted. I am not sure how any seller could see that unless the seller actually typed that in the order information, that would be a no no.
This has not happened to our business as far as I know, I am not running it, but it looks like a hack, sounds like a hack.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: Flying Childers This user has validated their user name.

Mon Mar 30 10:30:45 2015

Typical of the unspeakable arrogance and complete lack of concern for the sellers who have made it possible for Etsy to be the multi-million dollar company it has become. Not only do the powers that be do everything they can to sabotage the sellers, they charge them royally for doing so. The only hope is for some entrepreneur with money and funding to create a new e-commerce site for real handmade artisan goods and fine vintage. Etsy is too busy copying Ebay to go back to that model.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: ignatz This user has validated their user name.

Mon Mar 30 13:44:54 2015

Notice the weasel language etsy used a-la ebay:  "no security breach."

Hey etsy geniuses - no one said there was a "security breach."  But there are LOTS of reports of a BUG IN YOUR CODE causing people to access others' accounts without even trying!

Surely Dickerson, who comes from a technical background, understands the difference between a bug in the code and a security breach.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

This user has validated their user name. by: SparklingSisters

Tue Mar 31 00:32:36 2015

LIGHTBULB!!!  Ahhh, now it makes sense.  I rec’d an order on March 23 (one of the dates in question).  Good thing I always send an order confirmation convo.  The “buyer” wrote back saying she never placed an order from me and to cancel the order.  Very confusing & complicated issue, but finally had to get Etsy involved as the customer was dealing with 2 accounts and was very confused, but now it makes sense.  Etsy never breathed a word of this issue, of course.

I bet someone got into her account in error and placed the order using her information.  On purpose or by error, I may never know.  No one has contacted me saying they’ve not received their order yet.  But if they do, I’ll have an answer as to what happened!!!

Etsy is really starting to scare me!

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: JoB This user has validated their user name.

Tue Mar 31 21:30:47 2015

I had this happen in March 14, 2013. I reported it to Etsy and they were mildly interested, but it really seemed as though they did not believe me.
This is not a new issue for them.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

This user has validated their user name. by: SparklingSisters

Wed Apr 1 01:12:08 2015

I really cannot believe this has been happening for 2 years!  When is Etsy going to step up and realize they have a very bad problem on their hands.  Yes, it may be very intermittent but that doesn't mean it can't be a catastrophe just waiting to happen.

Perminate Link for Etsy Responds to Reports of Account Mixups   Etsy Responds to Reports of Account Mixups

by: LeeLoo This user has validated their user name.

Tue Apr 7 03:05:38 2015

A few more incidents and manifesting themselves in various ways, they are drifting out of the woodwork.
On this thread a seller states that items have been placed in her shopping cart 4 times.
https://www.etsy.com/teams/7720/bugs/discuss/16156070/page/1
5

Etsy
don't seem concerned at all. A usual Canned response is all that is given.
''No problem here folks - move along.''



Login is required to post comments.
To sign in to leave a comment, fill in the form below. If you have not yet signed up for AB Verify, or if you'd like more information, go to the Registration Page
.

Login for AB Verify
Be sure and use your email address and password to log in.

 
Email:
Password:
 
 Forgot Your Password?
 Even though you are signed in with the AuctionBytes Blog, you will have to sign in to the EcommerceBytes blog. But you can sign in with your existing AB Verify info.