account hacked for first time

Earlier today I was looking at some of my listings and noticed a random listing for a new smart TV that I had not listed and the sale being in Euros and not pounds. I had never listed this item and when trying to revise and cancel it was taking me to the french Ebay site. Straight away I rang ebay and managed to get the item cancelled in time before anyone had purchased even though it had been apparently listed 4 days ago.



This has been such a nuissance as I've had to change passwords for 2 email accounts, ebay and paypal and also had to remove the money in my paypal account which I was trying to keep in there and build up for a few weeks running up to christmas. Ebay have also sent through a message saying they have disconnected my direct debit payents for invoices as a precaution.

I sold an item to a French customer 2 weeks ago but can't see this being the cause. Has anyone had any similar issues? Had this gone unoticed I might well have lost my ebay account or it could have resulted in alot of issues had sales gone through.


Even though I've changed everything I can my phone automatically goes through to both of my emails without ever having to access passwords. Do I have to change anything regarding phone settings aswell?

Comments

  • forgotmyname
    forgotmyname Posts: 32,518
    First Anniversary Name Dropper First Post
    Forumite
    edited 18 November 2019 at 12:08PM
    Is your phones software upto date also? Latest OS version? latest browser version?

    I would have logged out of everything. Change the password using different browsers on the PC and on the Phone so they would need access to both to sell something and actually get to the funds.

    Change ebay / email on PC, change paypal / email on phone.

    Dont use the same email for both.

    An odd thing with my account, I changed the email address on paypal and i was still able to login using the old email even though i had removed it. Make sure no additional email accounts are added.

    Not sure how long the old email worked, may have been a minute or more? I didnt keep checking. The next day it didnt work though.
    Censorship Reigns Supreme in Troll City...

  • ruperts
    ruperts Posts: 3,673
    First Anniversary Name Dropper First Post
    Forumite
    Could have been that you were using the same password and email combination on another site which got hacked. The scammers will then try the same email/password on other sites.

    This website claims to be able to check if and where your details have leaked in a hack:

    https://haveibeenpwned.com/

    It has happened to my email six times according to that.

    I had my ebay account hacked about a year ago. I hadn't used it for some time so it was still set up with my email and a basic old password that had been hacked from other sites, so I guess that's how it happened. I closed my account in the end because I never use it anyway.
  • I've never used the same password and user name or email on any sites nor do I go direct to any websites from any emails I receive so this is a real mystery. Fortunately I only have 2 pages of items so it was easy to spot a listing I had not placed but had of had say a few pages I would probably never have noticed until the first sale came through so it's got me a little worried now about ever having a shop full of hundreds of listings. Fortunately ebay were good and removed the item but had a sale or more come through I don't know if they would have been as helpful and whether or not paypal would have refunded me but I can't say for sure as it hasn't happened and have never been in this situation before. I don't understand though how a listing can be directed to say it ships from france and the whole listing was in French yet nothing had altered in my paypal so if a sale had come through how would the scammer have been able to direct the money to themselves?
  • amberhen49
    amberhen49 Posts: 49 Forumite
    edited 20 November 2019 at 7:14PM
    More and more websites allow 2 factor authentication. I'd always recommend having it turned on if possible.

    If means even if someone does get your password, they need access to your phone as well before they could log on. Depending on the site, you can receive an SMS text or use something like Google Authenticator which will create you a one time pass code.

    https://medium.com/@mshelton/two-factor-authentication-for-beginners-b29b0eec07d7
This discussion has been closed.
Meet your Ambassadors

Categories

  • All Categories
  • 342.5K Banking & Borrowing
  • 249.9K Reduce Debt & Boost Income
  • 449.4K Spending & Discounts
  • 234.6K Work, Benefits & Business
  • 607.1K Mortgages, Homes & Bills
  • 172.8K Life & Family
  • 247.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 15.8K Discuss & Feedback
  • 15.1K Coronavirus Support Boards