eBay data breach set to be investigated by the ICO
Auction site finds itself at centre of several security investigations in wake of data breach
 
Internet auction site eBay looks set to have its operations probed in the wake of this week's data breach by a slew of data protection experts and regulators.
The website confirmed earlier this week that it had suffered a massive data breach, resulting in the disclosure of the passwords belonging to hundreds of millions of its users.
Details have since emerged that eBay is facing investigations on several fronts about the events that led to the breach taking place.
The US states of Connecticut, Florida and Illinois have already announced plans to join forces to investigate the company's security policies, along with the country's Federal Trade Commission.
An eBay spokesperson said the site is ready and willing to co-operate with any investigations that are carried out into its security strategy.
"We have relationships with and proactively contacted a number of state, federal and international regulators and law enforcement agencies," the spokesperson said.
Meanwhile, UK data protection watchdog, the Information Commissioner's Office (ICO) has confirmed that it's looking into launching its own probe into the breach.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Speaking to Radio 5 Live earlier today, The Information Commissioner Christopher Graham said a full investigation into the breach is justified given that millions of the site's users live in the UK.
However, because eBay's European headquarters are in Luxembourg, the ICO will first need to liaise with that country's data protection officers before it can act.
"When you're taking on a big global player like eBay, you've got to make sure do not get foot faulted and do something that would get you into troubles with the lawyers," Graham explained.
Meanwhile, eBay has denied that data stolen during the breach has been posted on anonymous text-sharing website Pastebin, which is regularly used by hackers to showcase stolen data.
Reports that a data dump from the eBay breach was up for sale for 1.45 bitcoins (447) on Pastebin began circulating yesterday night, but an eBay representative has since confirmed the details are not from "authentic" user accounts.
- 
 Building enduring channel partnerships in a multi-generational IT environment Building enduring channel partnerships in a multi-generational IT environmentIndustry Insights Partners are evolving from sellers to strategic advisors, prioritizing customer outcomes 
- 
 What can AI do to empower those working in the legal sector today, tomorrow, and beyond? What can AI do to empower those working in the legal sector today, tomorrow, and beyond?Supported AI is transforming the legal profession — from streamlining today’s workflows to shaping tomorrow’s strategies. For firms, the choice is clear: embrace trusted AI tools now or risk falling behind in a rapidly evolving landscape 
- 
 23andMe 'failed to take basic steps' to safeguard customer data 23andMe 'failed to take basic steps' to safeguard customer dataNews The ICO has strong criticism for the way the genetic testing company responded to a 2023 breach. 
- 
 AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuseNews The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data 
- 
 “You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims “You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victimsNews Companies need to treat victims with swift, practical action, according to the ICO 
- 
 LinkedIn backtracks on AI training rules after user backlash LinkedIn backtracks on AI training rules after user backlashNews UK-based LinkedIn users will now get the same protections as those elsewhere in Europe 
- 
 UK's data protection watchdog deepens cooperation with National Crime Agency UK's data protection watchdog deepens cooperation with National Crime AgencyNews The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery 
- 
 ICO slams Electoral Commission over security failures ICO slams Electoral Commission over security failuresNews The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies 
- 
 Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firmsNews Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement 
- 
 ICO reprimands Coventry school over repeated data protection failures ICO reprimands Coventry school over repeated data protection failuresNews The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach