The Second Proof That Wasn't There
In 2014, a stolen password reached up to 145 million eBay accounts because nothing else was needed to get past it — and a federal court later ruled that a breach alone, without proof the data was used
In May 2014, eBay told its users something most companies spend enormous effort avoiding having to say: a database holding the personal information of up to 145 million people had been accessed by attackers, and had been sitting open to them since late winter. The database held names, email addresses, physical addresses, phone numbers, dates of birth, and encrypted passwords. It did not hold financial data: credit-card numbers and PayPal credentials lived on separate systems, and PayPal later confirmed its own data was not compromised.
The way in was not a software exploit. Sometime in late February or early March of 2014, according to eBay’s own disclosures, attackers compromised the login credentials of a small number of eBay employees and used them to reach the corporate network. eBay has never publicly identified the method. Secondary security-industry analysis at the time pointed to spear phishing, a targeted version of phishing built from details specific to the person being targeted, convincing enough that they click, respond, or hand over credentials somewhere they shouldn’t. That attribution is analysts reading the pattern from the outside, not something eBay itself confirmed. What is documented is that the stolen credentials worked completely on their own. No second factor was required. A password proves someone was, at some point, trusted with it — not that the person using it right now is the person it was issued to. Multi-factor authentication exists to close that gap, and on the path these attackers took, nothing of the kind stood in the way.
From there, the attackers needed roughly two months to move from the corporate network (where employees check email and use internal tools) to the production database that actually served customers. That interval is what security teams call dwell time: the gap between initial access and detection, and in this case, it is a gap eBay’s own monitoring did not close. The kind of large-scale data movement a breach like this can involve (potentially 145 million records) is exactly what database-activity monitoring and data-loss-prevention systems are built to flag. Something let it go unnoticed: tooling that was missing, mistuned, or not watched closely enough. Even so, the record shows eBay found the compromise on its own terms: about two weeks before its public disclosure on May 21, 2014, tracing an employee credential compromise back to the database it had touched. eBay then required a password reset, brought in outside security help, and reported costs of about $46 million in its next quarterly filing. eBay also described the stolen passwords as “encrypted” — not “hashed,” the more specific term for a one-way function designed to make reversing a password computationally painful. The choice of word left security researchers unable to say, from the outside, how much protection those passwords actually had.
The legal aftermath exposed how unevenly cybersecurity and the law fit together. A class action, Green v. eBay Inc., was filed in July 2014, built on a premise that seems, on its face, obvious: 145 million people’s personal information had been taken, and the company responsible for securing it should answer for that. A federal court dismissed the case in May 2015. Not because the breach hadn’t happened, and not because eBay had been cleared of any failing — the court never ruled on that question at all. It was dismissed for lack of Article III standing: a legal requirement that a plaintiff show a concrete, actual injury, not merely the risk of one. “The mere fact that Plaintiff’s information was accessed during the Data Breach is insufficient to establish injury-in-fact,” Judge Susie Morgan wrote in the order dismissing the case. Without proof the stolen data had actually been used against them (for fraud, for identity theft, for financial loss), the plaintiffs had no case to bring, whatever eBay had or hadn’t done to prevent the breach in the first place.
It also wasn’t eBay’s first time. Six years earlier, in 2008, eBay’s South Korean subsidiary disclosed a breach affecting twenty million users: internal precedent, inside the same corporate family, long before 2014. By early 2014 the Federal Trade Commission had already settled more than fifty data-security enforcement actions against other companies, establishing a working industry baseline for access controls, monitoring, and credential security that wasn’t new or untested. In July 2015, eBay and PayPal completed a split into two independent companies that had been planned before the breach for unrelated business reasons, though the breach became one more argument, among several, for why the businesses should operate apart. A decade later, eBay’s own filings describe a security posture built around specific, named controls — the kind its 2014 disclosures never spelled out. Its most recent annual report points to regular cybersecurity training and phishing-simulation testing for employees, alongside enhanced monitoring and reporting. The threat is the same one it faced in 2014. What eBay now does differently is name the specific controls it runs against it.
**Sources & further reading:**
- eBay Inc., Form 8-K, Exhibit 99.1 press release, filed May 21, 2014 — SEC EDGAR
- eBay Inc., Form 10-Q for Q2 2014 — SEC EDGAR (breach description, cost figures, password-reset scope, 2008 Korea breach figure)
- eBay Inc., Form 10-K for fiscal year 2024 (filed February 27, 2025), Item 1C “Cybersecurity” — SEC EDGAR, accession 0001065088-25-000037 (current security-program controls, incl. employee cybersecurity training and phishing-simulation testing)
- Green v. eBay Inc., No. 14-1688, 2015 WL 2066531 (E.D. La. May 4, 2015) — Order and Reasons, Judge Susie Morgan
- Docket: Green v. eBay Inc., Case No. 2:14-cv-01688, E.D. La. (filed July 2014)
- eBay Inc. newsroom, “eBay Inc. To Ask eBay Users To Change Passwords,” May 21, 2014
