eBay A.I CyberSecurity Scoring
eBay
Company Information
Website:https://www.ebayinc.com/
Employees number:21,881
Number of followers:660,475
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:ebayinc.com
eBay Risk Score (AI oriented)
Between 800 and 849
eBayTechnology, Information and Internet
Updated:
04/08/2026
04/08/2026
805/1000
Good
A
eBay Global Score (TPRM)
xxxx
eBayTechnology, Information and Internet
Score locked

eBayGood
Current Score
805A (GOOD)
01000
4 incidents
-8.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
796
Vulnerability
03 Aug 2026 • eBay
eBay and Google: Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint
Google Passkey Security Flaws Expose Accounts to Silent Hijacking
792
HIGH-4
GOOEBA1785781429
Google Passkey Security Flaws Expose Accounts to Silent Hijacking
New research from Unit 42 reveals critical vulnerabilities in Google’s Cloud Authenticator, allowing malware on compromised Windows devices to hijack synced passkeys and bypass multi-factor authentication (MFA) without user interaction. The findings, part of a three-part series on passkey security, highlight flaws in device trust, onboarding, and recovery mechanisms that undermine the protections passkeys were designed to provide.
Passkeys, which replace passwords with public-key cryptography, are vulnerable due to Chrome’s handling of the "identity key" a hardware-backed credential meant to verify device possession. Instead of being permanently secured in the Trusted Platform Module (TPM), the key is generated as an exportable blob, enabling malware to extract and use it via Windows cryptography APIs to authenticate as the victim. This "Pass-ta-key" attack allows silent logins without triggering biometric or PIN prompts.
A more severe variant, the "Silver Pass-ta-key" attack, exploits Chrome’s re-onboarding process. By corrupting local passkey state files, attackers force the browser to accept a new, attacker-controlled verification key, granting persistent access even to MFA-protected accounts. The most damaging technique, the "Golden Pass-ta-key" attack, targets the security domain secret (SDS), a 32-byte master key encrypting all synced passkeys. Researchers found this key exposed in Chrome’s logs and memory during recovery, allowing attackers to decrypt past and future passkeys creating undetectable, long-term access since Google lacks a mechanism to rotate the SDS.
The vulnerabilities stem from implementation gaps rather than flaws in passkey cryptography itself, particularly over-reliance on client device trust and inconsistent validation by service providers. Some platforms, including eBay, have patched verification gaps following responsible disclosure. Mitigation strategies include enforcing user verification checks, validating device key attestation, restricting local access to credential stores, and monitoring for unusual onboarding or recovery triggers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
808
JUNE 2026
808
MAY 2026
808
APRIL 2026
808
MARCH 2026
806
Cyber Attack
23 Mar 2026 • eBay
Lockheed Martin: Lockheed Martin targeted in alleged breach by pro-Iran hacktivist
Lockheed Martin Targeted in Alleged Pro-Iran Hacktivist Attack
793
CRITICAL-13
LOC1774283448
Lockheed Martin Targeted in Alleged Pro-Iran Hacktivist Attack
Lockheed Martin, a leading aerospace and defense contractor, has been targeted by a pro-Iran hacktivist group known as APT Iran, which claims to have stolen 375 terabytes of sensitive data. The threat actor alleges possession of blueprints for the F-35 fighter jet, the U.S.’s most advanced aircraft, alongside other corporate information.
Security researchers, including Flashpoint and Check Point Software, have verified the group’s claims, which were first shared on Telegram, a platform frequently used by cybercriminals to disseminate threats. Halcyon later reported that APT Iran is demanding over $400 million in exchange for withholding the data from U.S. adversaries.
Lockheed Martin acknowledged the reports in a statement, confirming awareness of the alleged breach while emphasizing its multilayered cybersecurity defenses. The company stated it maintains confidence in the integrity of its systems.
APT Iran has previously claimed responsibility for attacks on critical infrastructure in Jordan, as documented by Palo Alto Networks. The group’s latest operation underscores the persistent threat posed by state-aligned hacktivists to high-profile defense contractors.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
808
JANUARY 2026
808
DECEMBER 2025
807
NOVEMBER 2025
807
OCTOBER 2025
807
SEPTEMBER 2025
807
AUGUST 2023
815
Vulnerability
23 Aug 2023 • eBay
eBay and Google: Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
New 'Pass-ta-key' Attacks Expose Flaws in Google’s Synced Passkeys
799
CRITICAL-16
GOOEBA1785824643
New "Pass-ta-key" Attacks Expose Flaws in Google’s Synced Passkeys
Security researchers at Palo Alto Networks’ Unit 42 uncovered a series of attacks dubbed "Pass-ta-key" that allow malware on compromised Windows devices to hijack Google-synced passkeys without requiring passwords, biometrics, or device unlocking. The findings, published on August 23, 2023, reveal three techniques targeting Chrome’s Google Password Manager on systems with a Trusted Platform Module (TPM).
### How the Attacks Work
Passkeys, designed to replace passwords with cryptographic key pairs, rely on Google’s cloud authenticator and hardware-backed device keys. However, Unit 42 demonstrated that malware running under a standard user account (no admin privileges needed) could exploit weaknesses in Chrome’s synchronization and device trust mechanisms.
1. Pass-ta-key (Basic Impersonation)
- Malware accesses Chrome’s LevelDB database (`%LocalAppData%\Google\Chrome\User Data\<Profile>\Sync Data\LevelDB`), extracting WebAuthn credential records, including encrypted private keys.
- By stealing Chrome’s TPM-wrapped device identity key, attackers can sign authentication requests via Windows’ Cryptography API: Next Generation (CNG), impersonating the victim’s trusted device.
- If a website’s WebAuthn policy is set to "preferred" (not "required") for user verification, the attacker may bypass biometric or PIN checks entirely.
2. Silver Pass-ta-key (Device Re-Enrollment)
- Attackers force Chrome to re-onboard a device by deleting the `passkey_enclave_state` file or issuing a "device-forget" command.
- During the temporary `uv_key_pending` state, they register a new user-verification key under their control, enabling assertions with the User Verified (UV) flag even if the victim’s device is offline.
- This grants persistent, reusable access to accounts.
3. Golden Pass-ta-key (Master Key Exposure)
- The most severe threat involves stealing Chrome’s 32-byte Security Domain Secret (SDS), a master key used to encrypt synced passkeys.
- While Google removed the SDS from device logs post-disclosure, Unit 42 noted it may still be temporarily accessible in Chrome’s process memory during onboarding.
- If obtained, attackers could decrypt all synced passkey private keys, enabling credential theft, resale, or long-term access even after device re-enrollment.
### Impact and Mitigations
- Affected Services: During testing, eBay was found to improperly validate the UV flag but patched the issue after disclosure.
- Vulnerable Configurations: Websites with userVerification="preferred" (instead of "required") are at higher risk.
- Recommended Fixes:
- Websites should enforce userVerification="required" and rigorously validate the UV flag.
- Credential providers should validate attestation for new device keys, secure recovery workflows, and prevent sensitive keys from lingering in memory.
- Monitoring for unauthorized modifications to local passkey state files is advised.
The research highlights that while passkeys resist phishing and password theft, endpoint compromises can undermine their security if cloud synchronization, device trust, and recovery systems are not equally hardened.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2017
824
Breach
01 Dec 2017 • eBay
eBay
eBay Privacy Breach
772
MEDIUM-52
EBA1722323
eBay suffered from privacy breach in December 2017 that exposed customer names on Google.
The exposed information includes real name in a product review that left for a benign product like clothing or books is disturbing enough, Google was also displaying eBay customer names for sensitive purchases such as medical diagnostic tests including pregnancy, drug, and HIV home testing kits.
They investigated the incident and established a toll-free call center to help those affected by the breach.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for eBay ??
What was eBay's A.I Rankiteo Cyber Score in July 2026 ??
What was eBay's A.I Rankiteo Cyber Score in June 2026 ??
What was eBay's A.I Rankiteo Cyber Score in May 2026 ??
What was eBay's A.I Rankiteo Cyber Score in April 2026 ??
What was eBay's A.I Rankiteo Cyber Score in March 2026 ??
What was eBay's A.I Rankiteo Cyber Score in February 2026 ??
What was eBay's A.I Rankiteo Cyber Score in January 2026 ??
What was eBay's A.I Rankiteo Cyber Score in December 2025 ??
What was eBay's A.I Rankiteo Cyber Score in November 2025 ??
What was eBay's A.I Rankiteo Cyber Score in October 2025 ??
What was eBay's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on eBay's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with eBay ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view eBay's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?