Advertisement
Promo

Security threats Toolkit

Insecure online forms put PayPal users at risk

Published: 26 Jan 2005 09:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Online financial service PayPal has warned a small number of customers that they should be extra-vigilant against online scams, after their email addresses were leaked on the Internet.

The subsidiary of Web auctioneer eBay said this week that BenchmarkPortal had not properly secured an online form for customers to opt out of a recent survey that PayPal had hired the company to perform. PayPal did not reveal how many email addresses had been harvested using the flaw but called the breach "extremely limited".

"Even first and last names are only kept on our own servers," PayPal spokeswoman Sara Bettencourt said. "All sensitive financial information resides on our servers, and none of that information was ever accessed."

The data leak was possible because of a flaw in the opt-out form provided by BenchmarkPortal, a provider of survey services. The form showed a customer's email address to anyone who guessed BenchmarkPortal's survey ID for that customer. If an intruder guessed a valid ID number, the corresponding PayPal user email address was returned.

BenchmarkPortal could not immediately be reached for comment.

Bettencourt said PayPal had contacted every affected user and had reserved a customer service number for them. Because only email addresses were accessed, the consequences of the leak should be minimal, she said. The affected users may get a larger number of email scams than normal, she said.

Like banks and other financial institutions, PayPal is a major target of phishing attacks, because sensitive information gained from customers can be turned into cash. Bettencourt would not discuss whether the data leak had an impact on PayPal's relationship with BenchmarkPortal.

"Right now, we are working with them to make sure that this doesn't occur in the future," Bettencourt said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
66 out of 141 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters