Amazon and eBay are two e-commerce giants from the U.S.
The former is best known as a retail site, while the latter is mostly about providing a place for auctions and facilitating the sale of products between third-party sellers and buyers. Because of this, the two holds sensitive user data and information.
And this makes the two alluring to malicious actors on the web.
This was apparent when an unknown person was found selling the data of 14 million Amazon and eBay customers’ accounts on a popular hacking forum, for a mere $800.
The leaked data includes customers' full name, postal code, delivery address, shop name, and a huge 1.6 million phone records.
Reports said that the alleged data came from users who had Amazon or eBay accounts between 2014-2021 in 18 different countries.

When it was discovered, the seller managed to sell two copies of the database leak, and has then closed the sale.
At this time, the alleged person is still unknown, and both Amazon and eBay denied any data breach.
A representative of Amazon said that the allegations had been reviewed with no evidence of any data violation.
Because of this, it is presumed that the threat actor got the passwords using spraying passwords, which is an brute force attack attempting to enter a wide number of accounts using only a handful of popular passwords.
Fortunately for those who have their data leaked, the database does not hold billing records, national ID numbers of even email addresses.
But still, the data being sold can be used for a range of reasons, including doxing users by public dissemination of private data. Hackers can also use the data for creating a spam list.




















































































































































































































































































































































































