Businesses need to wake up and smell the hackers

eBay is just one target of cybercriminals who cost the global economy $300bn a year

Know you should change your password but can't be bothered? Your inertia may be stirred. The hacking of between 120 million and 145 million eBay accounts, revealed this week, is the latest in a series of huge data leaks to have hit corporate giants.

The leaking of 40 million of its customers' credit card details cost the chief executive of the US retailer Target, Gregg Steinhafel, his job earlier this month and has dented company performance. The US department store group Neiman Marcus, British grocer Morrisons and the social network LinkedIn have also been hit by large-scale data breaches as their goldmines of customer details have been drained, causing corporate humiliation. From "spear phishing" to "sprite" hacks, the types of data breaches are becoming more frequent and more varied.

The perpetrators of the attack on eBay are yet to be discovered but the auction site said criminals elicited customers' names, encrypted passwords, email addresses, physical addresses, phone numbers and dates of birth. It may not seem greatly sensitive but could equate to a mortgage being taken out in your name or your identity being used to commit crime.

Although no financial information was involved, fears are rising that the data could be used in conjunction with information from other hacks – traded on the black market – to build a detailed profile of a victim. Customers have been told to change their password urgently as the hack actually occurred three months ago.

In the meantime, the impact of the Heartbleed bug – thought to have hit 17 per cent of the internet's secure servers – has come to light. Although it is unlikely to be connected to the eBay attack, it heightens the sense that online security is looking shaky.

Reports suggest that eBay users rushing to change their password have swamped the site. "Even if every hacked user changed their password, that would still take six days and many have been unable to change them," says Ian Shaw, managing director of the consultant MWR InfoSecurity.

The cost of hacking to businesses worldwide is escalating. A report on cyber crime and espionage by the Center for Strategic and International Studies in Washington last year estimated that it costs the global economy $300bn (£180bn) a year. An industry is growing around hacking. Research by the accountancy firm PwC shows cyber insurance is the fastest-growing speciality cover ever – worth around $1.3bn a year in the US and anywhere between £50m and £130m in the EU.

The seismic ripples of hacks will have struck fear into the hearts of those in charge of protecting priceless data in large financial institutions. The Financial Policy Committee, the regulator, has recommended that additional studies are made of cyber crime.

In November, the Bank of England told banks to strengthen their defences against online saboteurs and invited 100 bankers, regulators and government officials to take part in a "war game" simulation dubbed "Waking Shark 11' in the City.

Hackers are also raising their profile. Large-scale organisations including Anonymous and the Syrian Electronic Army have become global names and, in the latter's case, fed off the recession in hitting out at large corporate organisations online. However, big companies are also often being outsmarted by small, organised gangs, causing further embarrassment.

On the surface, companies appear remarkably vulnerable to attacks. EBay said its systems were infiltrated via the accounts of a "small number of employee log-in credentials", from which hackers could gain access to an entire database.

"It's like saying 'I'm a little bit pregnant'," said Andrew France, chief executive of the cyber defence company Darktrace. "If the accounts hacked are the chief technology officer or chief executive then the information could be vital."

Businesses are even more vulnerable when suffering deliberate data leaks. In March, the details of thousands of Morrisons' customers were leaked online and to a local newspaper by a disenchanted employee who had legitimate access to the data. "That was a malicious case but often employees are just ignorant about how systems work," says Mr France. "Security needs to spot unusual behaviour, deliberate or otherwise."

The huge eBay security breach also raises a question over public communications as the attack dated back to February. David Emm, a senior researcher at the internet security firm Kaspersky Lab, said: "While it might seem as though eBay has been slow to respond, if the company has only just discovered the full extent of the attack it is now doing the right thing by notifying customers in a timely manner."

Cyber crime seems as if it is inexorably on the up, as does the cost of preventing it. However, if large companies and consumer alike are to prevent it, decisive and frequent action will need to be taken quickly before bank accounts are drained. The latest swathe of hacks may just spark a few more sceptics into action.

Need to know: What to do to stop the hackers

"Change your password, change your password, change your password," says Andrew France at Darktrace. "I know it's a pain but change it every month, use upper and lower case letters and different numbers. It's the only absolute way to avoid hacking."

Brian Krebs, who writes the blog Krebs on Security, which exposed the Target data breach, also advises changing all passwords, but adds: "Be extra wary of phishing emails that spoof eBay and PayPal and ask you to click on some link or download some security tool; attackers are likely to capitalise on this incident to spread malware and to hijack accounts."

Start your day with The Independent, sign up for daily news emails
ebooksA special investigation by Andy McSmith
  • Get to the point
Latest stories from i100
Have you tried new the Independent Digital Edition apps?
Independent Dating

By clicking 'Search' you
are agreeing to our
Terms of Use.

iJobs Job Widget
iJobs Money & Business

Recruitment Genius: Retirement Coordinator - Financial Services

Negotiable: Recruitment Genius: To provide a prompt, friendly and efficient se...

Recruitment Genius: Annuities / Pensions Administrator

Negotiable: Recruitment Genius: You will be the first point of contact for all...

Ashdown Group: HR, Payroll & Benefits Officer - Altrincham - up to £24,000.

£18000 - £24000 per annum + benefits: Ashdown Group: HR, Payroll & Benefits Of...

Ashdown Group: Learning and Development Programme Manager

£35000 - £38000 per annum + benefits : Ashdown Group: A highly successful, int...

Day In a Page

The saffron censorship that governs India: Why national pride and religious sentiment trump freedom of expression

The saffron censorship that governs India

Zareer Masani reveals why national pride and religious sentiment trump freedom of expression
Prince Charles' 'black spider' letters to be published 'within weeks'

Prince Charles' 'black spider' letters to be published 'within weeks'

Supreme Court rules Dominic Grieve's ministerial veto was invalid
Distressed Zayn Malik fans are cutting themselves - how did fandom get so dark?

How did fandom get so dark?

Grief over Zayn Malik's exit from One Direction seemed amusing until stories of mass 'cutting' emerged. Experts tell Gillian Orr the distress is real, and the girls need support
The galaxy collisions that shed light on unseen parallel Universe

The cosmic collisions that have shed light on unseen parallel Universe

Dark matter study gives scientists insight into mystery of space
The Swedes are adding a gender-neutral pronoun to their dictionary

Swedes introduce gender-neutral pronoun

Why, asks Simon Usborne, must English still struggle awkwardly with the likes of 's/he' and 'they'?
Disney's mega money-making formula: 'Human' remakes of cartoon classics are part of a lucrative, long-term creative plan

Disney's mega money-making formula

'Human' remakes of cartoon classics are part of a lucrative, long-term creative plan
Lobster has gone mainstream with supermarket bargains for £10 or less - but is it any good?

Lobster has gone mainstream

Anthea Gerrie, raised on meaty specimens from the waters around Maine, reveals how to cook up an affordable feast
Easter 2015: 14 best decorations

14 best Easter decorations

Get into the Easter spirit with our pick of accessories, ornaments and tableware
Paul Scholes column: Gareth Bale would be a perfect fit at Manchester United and could turn them into serious title contenders next season

Paul Scholes column

Gareth Bale would be a perfect fit at Manchester United and could turn them into serious title contenders next season
Inside the Kansas greenhouses where Monsanto is 'playing God' with the future of the planet

The future of GM

The greenhouses where Monsanto 'plays God' with the future of the planet
Britain's mild winters could be numbered: why global warming is leaving UK chillier

Britain's mild winters could be numbered

Gulf Stream is slowing down faster than ever, scientists say
Government gives £250,000 to Independent appeal

Government gives £250,000 to Independent appeal

Donation brings total raised by Homeless Veterans campaign to at least £1.25m
Oh dear, the most borrowed book at Bank of England library doesn't inspire confidence

The most borrowed book at Bank of England library? Oh dear

The book's fifth edition is used for Edexcel exams
Cowslips vs honeysuckle: The hunt for the UK’s favourite wildflower

Cowslips vs honeysuckle

It's the hunt for UK’s favourite wildflower
Child abuse scandal: Did a botched blackmail attempt by South African intelligence help Cyril Smith escape justice?

Did a botched blackmail attempt help Cyril Smith escape justice?

A fresh twist reveals the Liberal MP was targeted by the notorious South African intelligence agency Boss