Businesses need to wake up and smell the hackers

eBay is just one target of cybercriminals who cost the global economy $300bn a year

Know you should change your password but can't be bothered? Your inertia may be stirred. The hacking of between 120 million and 145 million eBay accounts, revealed this week, is the latest in a series of huge data leaks to have hit corporate giants.

The leaking of 40 million of its customers' credit card details cost the chief executive of the US retailer Target, Gregg Steinhafel, his job earlier this month and has dented company performance. The US department store group Neiman Marcus, British grocer Morrisons and the social network LinkedIn have also been hit by large-scale data breaches as their goldmines of customer details have been drained, causing corporate humiliation. From "spear phishing" to "sprite" hacks, the types of data breaches are becoming more frequent and more varied.

The perpetrators of the attack on eBay are yet to be discovered but the auction site said criminals elicited customers' names, encrypted passwords, email addresses, physical addresses, phone numbers and dates of birth. It may not seem greatly sensitive but could equate to a mortgage being taken out in your name or your identity being used to commit crime.

Although no financial information was involved, fears are rising that the data could be used in conjunction with information from other hacks – traded on the black market – to build a detailed profile of a victim. Customers have been told to change their password urgently as the hack actually occurred three months ago.

In the meantime, the impact of the Heartbleed bug – thought to have hit 17 per cent of the internet's secure servers – has come to light. Although it is unlikely to be connected to the eBay attack, it heightens the sense that online security is looking shaky.

Reports suggest that eBay users rushing to change their password have swamped the site. "Even if every hacked user changed their password, that would still take six days and many have been unable to change them," says Ian Shaw, managing director of the consultant MWR InfoSecurity.

The cost of hacking to businesses worldwide is escalating. A report on cyber crime and espionage by the Center for Strategic and International Studies in Washington last year estimated that it costs the global economy $300bn (£180bn) a year. An industry is growing around hacking. Research by the accountancy firm PwC shows cyber insurance is the fastest-growing speciality cover ever – worth around $1.3bn a year in the US and anywhere between £50m and £130m in the EU.

The seismic ripples of hacks will have struck fear into the hearts of those in charge of protecting priceless data in large financial institutions. The Financial Policy Committee, the regulator, has recommended that additional studies are made of cyber crime.

In November, the Bank of England told banks to strengthen their defences against online saboteurs and invited 100 bankers, regulators and government officials to take part in a "war game" simulation dubbed "Waking Shark 11' in the City.

Hackers are also raising their profile. Large-scale organisations including Anonymous and the Syrian Electronic Army have become global names and, in the latter's case, fed off the recession in hitting out at large corporate organisations online. However, big companies are also often being outsmarted by small, organised gangs, causing further embarrassment.

On the surface, companies appear remarkably vulnerable to attacks. EBay said its systems were infiltrated via the accounts of a "small number of employee log-in credentials", from which hackers could gain access to an entire database.

"It's like saying 'I'm a little bit pregnant'," said Andrew France, chief executive of the cyber defence company Darktrace. "If the accounts hacked are the chief technology officer or chief executive then the information could be vital."

Businesses are even more vulnerable when suffering deliberate data leaks. In March, the details of thousands of Morrisons' customers were leaked online and to a local newspaper by a disenchanted employee who had legitimate access to the data. "That was a malicious case but often employees are just ignorant about how systems work," says Mr France. "Security needs to spot unusual behaviour, deliberate or otherwise."

The huge eBay security breach also raises a question over public communications as the attack dated back to February. David Emm, a senior researcher at the internet security firm Kaspersky Lab, said: "While it might seem as though eBay has been slow to respond, if the company has only just discovered the full extent of the attack it is now doing the right thing by notifying customers in a timely manner."

Cyber crime seems as if it is inexorably on the up, as does the cost of preventing it. However, if large companies and consumer alike are to prevent it, decisive and frequent action will need to be taken quickly before bank accounts are drained. The latest swathe of hacks may just spark a few more sceptics into action.

Need to know: What to do to stop the hackers

"Change your password, change your password, change your password," says Andrew France at Darktrace. "I know it's a pain but change it every month, use upper and lower case letters and different numbers. It's the only absolute way to avoid hacking."

Brian Krebs, who writes the blog Krebs on Security, which exposed the Target data breach, also advises changing all passwords, but adds: "Be extra wary of phishing emails that spoof eBay and PayPal and ask you to click on some link or download some security tool; attackers are likely to capitalise on this incident to spread malware and to hijack accounts."

Voices
Hunted: A stag lies dead on Jura, where David Cameron holidays and has himself stalked deer
voicesThe Scotland I know is becoming a playground for the rich
News
newsMcKamey Manor says 'there is no escape until the tour is completed'
News
people'When I see people who look totally different, it brings me back to that time in my life'
Arts and Entertainment
Soul singer Sam Smith cleared up at the Mobo awards this week
newsSam Smith’s Mobo triumph is just the latest example of a trend
PROMOTED VIDEO
News
ebooksAn unforgettable anthology of contemporary reportage
News
news
News
people

Britain First criticised for using actress's memory to draw attention to their 'hate-filled home page'

Arts and Entertainment
A photograph taken by David Redferm of Sonny Rollins
people
News
news

Emergency call 'started off dumb, but got pretty serious'

Extras
indybest
Latest stories from i100
Have you tried new the Independent Digital Edition apps?
Independent Dating
and  

By clicking 'Search' you
are agreeing to our
Terms of Use.

iJobs Job Widget
iJobs Money & Business

Compensation and Benefits Manager - Brentwood - Circa £60,000

£60000 per annum: Ashdown Group: Compensation and Benefits Manager - Compensat...

Data Analyst/Planning and Performance – Surrey – Up to £35k

£30000 - £35000 Per Annum plus excellent benefits: Clearwater People Solutions...

IT Systems Business Analyst - Watford - £28k + bonus + benefits

£24000 - £28000 per annum + bonus & benefits: Ashdown Group: IT Business Syste...

Markit EDM (CADIS) Developer

£50000 - £90000 per annum + benefits: Ampersand Consulting LLP: Markit EDM (CA...

Day In a Page

Wilko Johnson, now the bad news: musician splits with manager after police investigate assault claims

Wilko Johnson, now the bad news

Former Dr Feelgood splits with manager after police investigate assault claims
Mark Udall: The Democrat Senator with a fight on his hands ahead of the US midterm elections

Mark Udall: The Democrat Senator with a fight on his hands

The Senator for Colorado is for gay rights, for abortion rights – and in the Republicans’ sights as they threaten to take control of the Senate next month
New discoveries show more contact between far-flung prehistoric humans than had been thought

New discoveries show more contact between far-flung prehistoric humans than had been thought

Evidence found of contact between Easter Islanders and South America
Cerys Matthews reveals how her uncle taped 150 interviews for a biography of Dylan Thomas

Cerys Matthews on Dylan Thomas

The singer reveals how her uncle taped 150 interviews for a biography of the famous Welsh poet
DIY is not fun and we've finally realised this as a nation

Homebase closures: 'DIY is not fun'

Homebase has announced the closure of one in four of its stores. Nick Harding, who never did know his awl from his elbow, is glad to see the back of DIY
The Battle of the Five Armies: Air New Zealand releases new Hobbit-inspired in-flight video

Air New Zealand's wizard in-flight video

The airline has released a new Hobbit-inspired clip dubbed "The most epic safety video ever made"
Pumpkin spice is the flavour of the month - but can you stomach the sweetness?

Pumpkin spice is the flavour of the month

The combination of cinnamon, clove, nutmeg (and no actual pumpkin), now flavours everything from lattes to cream cheese in the US
11 best sonic skincare brushes

11 best sonic skincare brushes

Forget the flannel - take skincare to the next level by using your favourite cleanser with a sonic facial brush
Paul Scholes column: I'm not worried about Manchester United's defence - Chelsea test can be the making of Phil Jones and Marcos Rojo

Paul Scholes column

I'm not worried about Manchester United's defence - Chelsea test can be the making of Jones and Rojo
Frank Warren: Boxing has its problems but in all my time I've never seen a crooked fight

Frank Warren: Boxing has its problems but in all my time I've never seen a crooked fight

While other sports are stalked by corruption, we are an easy target for the critics
Jamie Roberts exclusive interview: 'I'm a man of my word – I'll stay in Paris'

Jamie Roberts: 'I'm a man of my word – I'll stay in Paris'

Wales centre says he’s not coming home but is looking to establish himself at Racing Métro
How could three tourists have been battered within an inch of their lives by a burglar in a plush London hotel?

A crime that reveals London's dark heart

How could three tourists have been battered within an inch of their lives by a burglar in a plush London hotel?
Meet 'Porridge' and 'Vampire': Chinese state TV is offering advice for citizens picking a Western moniker

Lost in translation: Western monikers

Chinese state TV is offering advice for citizens picking a Western moniker. Simon Usborne, who met a 'Porridge' and a 'Vampire' while in China, can see the problem
Handy hacks that make life easier: New book reveals how to rid your inbox of spam, protect your passwords and amplify your iPhone

Handy hacks that make life easier

New book reveals how to rid your email inbox of spam, protect your passwords and amplify your iPhone with a loo-roll
KidZania lets children try their hands at being a firefighter, doctor or factory worker for the day

KidZania: It's a small world

The new 'educational entertainment experience' in London's Shepherd's Bush will allow children to try out the jobs that are usually undertaken by adults, including firefighter, doctor or factory worker