Eye4Fraud Breach Exposes Data Of Millions Of Ecommerce Shoppers

Liz Morton
Liz Morton


Comments

UPDATE 3-17-23

Eye4Fraud has finally publicly acknowledged the breach in a statement posted on their website:

Eye4Fraud

We recently experienced a cybersecurity incident where a backup file that related to certain customers and contained limited information was subject to unauthorized access. We moved to promptly retain cybersecurity experts and outside advisors to assist us in our response. We have notified and are cooperating with law enforcement authorities to investigate the incident.

We provide fraud protection services for ecommerce merchants, who provide us with limited information about transactions. We do not collect sensitive personal information about individuals like account passwords or full payment card numbers in the course of providing our services.

We are working to understand the situation, and our priority is to provide accurate information, including any additional updates as appropriate.

However, instead of doing the ethical and responsible thing by having a banner or other above the fold, prominent notice to users, Eye4Fraud has chosen to bury the link to this statement at the very bottom of the page in their footer....behind an ambiguous link that just says "Statement About Recent Event."

That's not nearly good enough and any serious company would know that. 👎


UPDATE 3-13-23

Eye4Fraud still has not responded to calls for responsible disclosure of this breach, but another impacted merchant has come forward and Abstract Ocean isn't pulling any punches.

Eye4Fraud
On March 6, 2023, Troy Hunt notified users of his website (HaveIBeenPwned) that Eye4Fraud (“E4F”) experienced a data breach involving ~16M accounts. Abstract Ocean trialed Eye4Fraud’s services between August 2019 and January 2020. E4F provides services that help protect against fraudulent orders (i…

On March 6, 2023, Troy Hunt notified users of his website (HaveIBeenPwned) that Eye4Fraud ("E4F") experienced a data breach involving ~16M accounts.Abstract Ocean trialed Eye4Fraud's services between August 2019 and January 2020. E4F provides services that help protect against fraudulent orders (ignore the irony there) for eCommerce companies.

Unfortunately, they have so far failed to disclose any information about this breach. We have contacted them directly for information, but they have not been forthcoming to us, or anyone else for that matter (e.g. there is not even a mention of the breach on their website). What we know is based on information mostly provided by Troy on Twitter. We will update this page as we find out more.


Ecommerce fraud detection and prevention SaaS Eye4Fraud has reportedly experienced a massive undisclosed data breach, exposing over 16 Million emails and other customer data from ecommerce businesses who use their service.

Troy Hunt, creator of Have I Been Pwned, detailed his efforts to contact Eye4Fraud and encourage ethical disclosure of the breach - which so far Eye4Fraud has not done.

As Hunt points out, this is a particularly important breach because many of the impacted users will have no idea their information was ever shared with Eye4Fraud.

When you shop on any ecommerce website, the company you purchase from may use third party software for any number of aspects of the shopping journey, including fraud detection - and that's exactly what Eye4Fraud is.

If you shop on any site that uses Eye4Fraud's service, your personal information will be shared with them as part of the fraud checking process and as the buyer, you likely aren't even aware.

Here's how it works, according to Eye4Fraud:

Every order, including phone orders, is put through our cutting-edge AI system. This system uses Persona™ and Dynamic Scoring™ technology to go deeply into your customer's profile and make sure everything is legit.

Some of the data that gets pulled into our system:

  • Email address
  • IP location
  • Behavioral data
  • Purchasing history
  • Issuing bank data
  • Public records

No red flags? Your order gets approved — within 2 minutes.


Hunt put together a full list of SiteName values and the number of customer records from each site that were allegedly exposed in the breach.

Eye4Fraud SiteName values
Eye4Fraud SiteName values. GitHub Gist: instantly share code, notes, and snippets.

While Eye4Fraud has not yet disclosed the breach, curiously the top impacted site, LovelySkin, has now been removed from Eye4Fraud's customer page.

The direct URL for LovelySkin's customer page now redirects back to the Eye4Fraud homepage, but the Internet Archive shows what the page used to look like.

So far at least once merchant who used Eye4Fraud's services and is listed in the breach has notified their customers in a textbook example of how disclosure should be handled.

Important Notification: Eye4Fraud Data Breach Incident - Zyltech Engineering

Dear ZYLtech.com Customers,

We are writing to inform you about a potential data breach incident that may have impacted your personal information.

We have recently learned that Eye4Fraud, our service provider for fraud detection and prevention services, has experienced a data breach that may have impacted our customers. The breach may have exposed personal information, such as your name, address, phone number, email address, payment type and last 4 digits of your credit card if used during ordering. We don't store your password so your password at ZYLtech.com is not affected by this incident. We strongly recommend you to be cautious of phishing emails and phone calls.

We have stopped our connection with Eye4fraud immediately after we learned of this breach. We apologize for any inconvenience or concern this may cause, and we want to assure you that we are doing everything in our power to address the situation and take action to enhance the protection of your information. We value your business and will keep you informed as we learn more.

Best-selling ecommerce author Marsha Collier shared the FTC's requirements for businesses to notify consumers of security breaches involving personal information.

Data Breach Response: A Guide for Business
You just learned that your business experienced a data breach. Whether hackers took personal information from your corporate server, an insider stole customer information, or information was inadvertently exposed on your company’s website, you are probably wondering what to do next. What steps shoul…

Notify Appropriate Parties
When your business experiences a data breach, notify law enforcement, other affected businesses, and affected individuals.

Determine your legal requirements. All states, the District of Columbia, Puerto Rico, and the Virgin Islands have enacted legislation requiring notification of security breaches involving personal information. In addition, depending on the types of information involved in the breach, there may be other laws or regulations that apply to your situation. Check state and federal laws or regulations for any specific requirements for your business.

Notify individuals. If you quickly notify people that their personal information has been compromised, they can take steps to reduce the chance that their information will be misused. In deciding who to notify, and how, consider:

  • state laws
  • the nature of the compromise
  • the type of information taken
  • the likelihood of misuse
  • the potential damage if the information is misused

The Eye4Fraud breach is also being discussed on HackerNews:

Eye4fraud Data Breach | Hacker News

And Reddit:


Have you been impacted by the Eye4Fraud data breach? Let us know in the comments below!

FraudNews

Liz Morton Twitter Facebook
LinkedIn

Liz Morton is a 17 year ecommerce pro turned indie investigative journalist providing ad-free deep dives on eBay, Amazon, Etsy & more, championing sellers & advocating for corporate accountability.

8 comments
Avatar
Laia Ordonez
OMG, thanks a lot, just found out this. Gonna check up my data. Thanks, Liz!
2
Hide Replies 1
Avatar
Administrator
Liz Morton
You're welcome Laia! Glad this information was helpful for you.
1
Avatar Placeholder
Sam
Class action needed.
1
Avatar Placeholder
Carp
Hello my identity is trying to be stolen currently because of this breach. Would you kno the attorney representing the case? I’m guessing there’s a class action suit out there somewhere? Please help.
411
Avatar Placeholder
MUT
Lookout shows my data breached in eye4fraud on 1/2023, also in twitter which I use and changed my password, Straffic and SHEIN which I know nothing about and have never used. What is going on and what do I do?
44
Avatar Placeholder
Cassini
This sucks as per Malwarebytes and i been pwned all my info has been Compromised and someone needs to take responsibility for it.
11
Avatar Placeholder
DMA
Lookout ID Scan states data breach from Eye4Fraud. Where do I begin to fix this??? Please help!

48
Hide Replies 1
Avatar Placeholder
Ryan121617
There is no easy way per'se. Start with lookin through this list of vendors and see which ones you use. Then go to those sites and change your passwords, reach out to them and see if you can find out which data was compromised and if they are offering any sort of identity protection for the affected customers.
417

Recent Comments
Avatar PlaceholderConcernedYesterday
It is Slowwwwwww and is more expensive to the buyer. In the past items I have ordered will sit at the hub for around 2 weeks. I avoid ebay unless I cannot get it elsewhere.
Avatar Placeholdermarks30472 days ago
Hi, I have a friend who had an interesting experience recently that fell under this issue. They sold an item, packed and dispatched to the UK Ebay hub, this was midway through the period as the pause occurred. They then received a message from the buyer that they had checked tracking and discovered that the item had disappeared on ebay, no advice. It then turned out that the tracking had been fudged and the package was with them but not forwarded on to the USA. A few hours of to and fro to get the answer that it was due to the tariff dilemma. NO fault of the buyer(who had paid) or the seller ((who had been paid) and a strange response that the item could not be delivered. The buyer would be refunded in full, the seller would keep payment and the item would not be returned. Strange, Ebay must be hurting paying our both sides of the deal+
Avatar Placeholdercwi3 days ago
  1. Start building out the brand and promoting the heck out of Canadian sellers to our domestic market. Work with Federal/Provincial level governments in the push to build a strong presence here in Canada.

  2. Add other calculated shipping options than Canada Post UPS/FedEx for domestic shipping - partner with couriers nationwide, leverage agreements and software integrations with courier reseller platforms such as Stallion Express. Build out a crowd sourced network using national/regional retail locations as drop points for rural regions, leveraging transport networks to move packages to courier pickup points, akin to the UK courier model but adapted to the Canadian realities.

  3. Create a centralized international shipping clearing house to aide micro businesses with affordable shipping rates and customs clearance to avoid pitfalls and complexities (akin to US eIS).

  4. Bring features forward to the platform from other localizations, such as prepaid best offer acceptance, etc.