Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
eBay

eBay Vendor Cyber Rating & Cyber Score

ebayinc.com

At eBay, we create pathways to connect millions of sellers and buyers in more than 190 markets around the world. Our technology empowers our customers, providing everyone the opportunity to grow and thrive — no matter who they are or where they are in the world. And the ripple effect of our work creates waves of change for our customers, our company, our communities and our planet.


eBay A.I CyberSecurity Scoring

eBay
Company Information
Website:https://www.ebayinc.com/
Employees number:21,881
Number of followers:660,475
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:ebayinc.com
eBay Risk Score (AI oriented)
Between 800 and 849
logo
eBayTechnology, Information and Internet
Updated:
04/08/2026
805/1000
Good
A
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
eBay Global Score (TPRM)
xxxx
logo
eBayTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

eBay
eBayGood
Current Score
805A (GOOD)
01000
4 incidents
-8.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
796Before Incident
Vulnerability
03 Aug 2026eBay
eBay and Google: Malware Can Steal Your Google Synced Passkey Without Asking for Your Password or Fingerprint

Google Passkey Security Flaws Expose Accounts to Silent Hijacking

792After Incident
HIGH-4
GOOEBA1785781429
Google Passkey Security Flaws Expose Accounts to Silent Hijacking New research from Unit 42 reveals critical vulnerabilities in Google’s Cloud Authenticator, allowing malware on compromised Windows devices to hijack synced passkeys and bypass multi-factor authentication (MFA) without user interaction. The findings, part of a three-part series on passkey security, highlight flaws in device trust, onboarding, and recovery mechanisms that undermine the protections passkeys were designed to provide. Passkeys, which replace passwords with public-key cryptography, are vulnerable due to Chrome’s handling of the "identity key" a hardware-backed credential meant to verify device possession. Instead of being permanently secured in the Trusted Platform Module (TPM), the key is generated as an exportable blob, enabling malware to extract and use it via Windows cryptography APIs to authenticate as the victim. This "Pass-ta-key" attack allows silent logins without triggering biometric or PIN prompts. A more severe variant, the "Silver Pass-ta-key" attack, exploits Chrome’s re-onboarding process. By corrupting local passkey state files, attackers force the browser to accept a new, attacker-controlled verification key, granting persistent access even to MFA-protected accounts. The most damaging technique, the "Golden Pass-ta-key" attack, targets the security domain secret (SDS), a 32-byte master key encrypting all synced passkeys. Researchers found this key exposed in Chrome’s logs and memory during recovery, allowing attackers to decrypt past and future passkeys creating undetectable, long-term access since Google lacks a mechanism to rotate the SDS. The vulnerabilities stem from implementation gaps rather than flaws in passkey cryptography itself, particularly over-reliance on client device trust and inconsistent validation by service providers. Some platforms, including eBay, have patched verification gaps following responsible disclosure. Mitigation strategies include enforcing user verification checks, validating device key attestation, restricting local access to credential stores, and monitoring for unusual onboarding or recovery triggers.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Synced passkeys (public-key credentials)Systems Affected: Google Cloud Authenticator (Chrome on Windows)Operational Impact: Bypass of multi-factor authentication (MFA)Brand Reputation Impact: Undermines trust in passkey securityIdentity Theft Risk: High (silent account hijacking)
DATA BREACH
Type Of Data Compromised: Passkeys (public-key credentials)Sensitivity Of Data: High (authentication credentials)Data Encryption: Weak (exportable identity key, exposed SDS)
JULY 2026
808Before Incident
JUNE 2026
808Before Incident
MAY 2026
808Before Incident
APRIL 2026
808Before Incident
MARCH 2026
806Before Incident
Cyber Attack
23 Mar 2026eBay
Lockheed Martin: Lockheed Martin targeted in alleged breach by pro-Iran hacktivist

Lockheed Martin Targeted in Alleged Pro-Iran Hacktivist Attack

793After Incident
CRITICAL-13
LOC1774283448
Lockheed Martin Targeted in Alleged Pro-Iran Hacktivist Attack Lockheed Martin, a leading aerospace and defense contractor, has been targeted by a pro-Iran hacktivist group known as APT Iran, which claims to have stolen 375 terabytes of sensitive data. The threat actor alleges possession of blueprints for the F-35 fighter jet, the U.S.’s most advanced aircraft, alongside other corporate information. Security researchers, including Flashpoint and Check Point Software, have verified the group’s claims, which were first shared on Telegram, a platform frequently used by cybercriminals to disseminate threats. Halcyon later reported that APT Iran is demanding over $400 million in exchange for withholding the data from U.S. adversaries. Lockheed Martin acknowledged the reports in a statement, confirming awareness of the alleged breach while emphasizing its multilayered cybersecurity defenses. The company stated it maintains confidence in the integrity of its systems. APT Iran has previously claimed responsibility for attacks on critical infrastructure in Jordan, as documented by Palo Alto Networks. The group’s latest operation underscores the persistent threat posed by state-aligned hacktivists to high-profile defense contractors.
INCIDENT DETAILS -
TYPE
Data Breach, Ransomware, Hacktivism
MOTIVATION
Hacktivism, Financial Gain, Geopolitical
IMPACT
Data Compromised: 375 terabytes of sensitive dataBrand Reputation Impact: Potential reputational damage
DATA BREACH
Blueprints for F-35 fighter jetCorporate informationSensitivity Of Data: Highly sensitive (military/defense)Data Exfiltration: Yes
FEBRUARY 2026
808Before Incident
JANUARY 2026
808Before Incident
DECEMBER 2025
807Before Incident
NOVEMBER 2025
807Before Incident
OCTOBER 2025
807Before Incident
SEPTEMBER 2025
807Before Incident
AUGUST 2023
815Before Incident
Vulnerability
23 Aug 2023eBay
eBay and Google: Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint

New 'Pass-ta-key' Attacks Expose Flaws in Google’s Synced Passkeys

799After Incident
CRITICAL-16
GOOEBA1785824643
New "Pass-ta-key" Attacks Expose Flaws in Google’s Synced Passkeys Security researchers at Palo Alto Networks’ Unit 42 uncovered a series of attacks dubbed "Pass-ta-key" that allow malware on compromised Windows devices to hijack Google-synced passkeys without requiring passwords, biometrics, or device unlocking. The findings, published on August 23, 2023, reveal three techniques targeting Chrome’s Google Password Manager on systems with a Trusted Platform Module (TPM). ### How the Attacks Work Passkeys, designed to replace passwords with cryptographic key pairs, rely on Google’s cloud authenticator and hardware-backed device keys. However, Unit 42 demonstrated that malware running under a standard user account (no admin privileges needed) could exploit weaknesses in Chrome’s synchronization and device trust mechanisms. 1. Pass-ta-key (Basic Impersonation) - Malware accesses Chrome’s LevelDB database (`%LocalAppData%\Google\Chrome\User Data\<Profile>\Sync Data\LevelDB`), extracting WebAuthn credential records, including encrypted private keys. - By stealing Chrome’s TPM-wrapped device identity key, attackers can sign authentication requests via Windows’ Cryptography API: Next Generation (CNG), impersonating the victim’s trusted device. - If a website’s WebAuthn policy is set to "preferred" (not "required") for user verification, the attacker may bypass biometric or PIN checks entirely. 2. Silver Pass-ta-key (Device Re-Enrollment) - Attackers force Chrome to re-onboard a device by deleting the `passkey_enclave_state` file or issuing a "device-forget" command. - During the temporary `uv_key_pending` state, they register a new user-verification key under their control, enabling assertions with the User Verified (UV) flag even if the victim’s device is offline. - This grants persistent, reusable access to accounts. 3. Golden Pass-ta-key (Master Key Exposure) - The most severe threat involves stealing Chrome’s 32-byte Security Domain Secret (SDS), a master key used to encrypt synced passkeys. - While Google removed the SDS from device logs post-disclosure, Unit 42 noted it may still be temporarily accessible in Chrome’s process memory during onboarding. - If obtained, attackers could decrypt all synced passkey private keys, enabling credential theft, resale, or long-term access even after device re-enrollment. ### Impact and Mitigations - Affected Services: During testing, eBay was found to improperly validate the UV flag but patched the issue after disclosure. - Vulnerable Configurations: Websites with userVerification="preferred" (instead of "required") are at higher risk. - Recommended Fixes: - Websites should enforce userVerification="required" and rigorously validate the UV flag. - Credential providers should validate attestation for new device keys, secure recovery workflows, and prevent sensitive keys from lingering in memory. - Monitoring for unauthorized modifications to local passkey state files is advised. The research highlights that while passkeys resist phishing and password theft, endpoint compromises can undermine their security if cloud synchronization, device trust, and recovery systems are not equally hardened.
INCIDENT DETAILS -
TYPE
Credential Theft
IMPACT
Data Compromised: Passkey private keys, device identity keys, Security Domain Secret (SDS)Systems Affected: Windows devices with Google Chrome and Google Password ManagerOperational Impact: Potential unauthorized access to accounts using passkeysBrand Reputation Impact: Potential erosion of trust in passkey security and Google’s authentication mechanismsIdentity Theft Risk: High (if passkeys are used for sensitive accounts)
DATA BREACH
Type Of Data Compromised: Cryptographic keys (passkey private keys, device identity keys, Security Domain Secret)Sensitivity Of Data: High (can enable unauthorized account access)Data Encryption: Data was encrypted but could be decrypted if SDS was exposedFile Types Exposed: LevelDB database files, TPM-wrapped keys
DECEMBER 2017
824Before Incident
Breach
01 Dec 2017eBay
eBay

eBay Privacy Breach

772After Incident
MEDIUM-52
EBA1722323
eBay suffered from privacy breach in December 2017 that exposed customer names on Google. The exposed information includes real name in a product review that left for a benign product like clothing or books is disturbing enough, Google was also displaying eBay customer names for sensitive purchases such as medical diagnostic tests including pregnancy, drug, and HIV home testing kits. They investigated the incident and established a toll-free call center to help those affected by the breach.
INCIDENT DETAILS -
TYPE
Privacy Breach
IMPACT
Customer Names
DATA BREACH
Customer Names

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for eBay ?
?
What was eBay's A.I Rankiteo Cyber Score in July 2026 ?
?
What was eBay's A.I Rankiteo Cyber Score in June 2026 ?
?
What was eBay's A.I Rankiteo Cyber Score in May 2026 ?
?
What was eBay's A.I Rankiteo Cyber Score in April 2026 ?
?
What was eBay's A.I Rankiteo Cyber Score in March 2026 ?
?
What was eBay's A.I Rankiteo Cyber Score in February 2026 ?
?
What was eBay's A.I Rankiteo Cyber Score in January 2026 ?
?
What was eBay's A.I Rankiteo Cyber Score in December 2025 ?
?
What was eBay's A.I Rankiteo Cyber Score in November 2025 ?
?
What was eBay's A.I Rankiteo Cyber Score in October 2025 ?
?
What was eBay's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on eBay's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with eBay ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view eBay's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?