AI digestGenerated by Niceggie AI
eBay temporarily disabled community direct messages after phishing messages impersonating official accounts appeared in the community, and it is investigating security risks.
Key decision points
- 1Community direct messages temporarily disabled
- 2Phishing messages impersonating officials appeared
- 3Account-verification scams involved
What this means for sellers
eBay’s closure of community direct messages shows that platform communication channels can also become entry points for account attacks. Keep security verification separate from routine operations. A common mistake is logging in through a message link after seeing a “time-limited verification” notice, which can put account, payment, or store permissions at risk. Highest-priority action: This week, require operations staff to handle security notices only through the official back end or by entering the URL independently, and review login protections.
Action items (within 24h)
Several phishing messages have recently appeared in the eBay community. Attackers impersonated platform officials and asked sellers to complete supposed account-security verification within 24 hours. The messages were sent through community direct messages and used the threat of account restrictions or the need for immediate action to direct recipients to click links or submit account information.
According to reports, attackers used the platform’s community migration and related vulnerabilities to send fake notifications to sellers. To reduce the further spread of such messages, eBay’s technical team decided to temporarily disable the community direct-message module and investigate the related security risks.
The measure targets the community direct-message channel and does not mean that sellers’ accounts have been collectively determined to be compromised. The platform is addressing the community and security issues, and sellers should verify account notifications through official eBay channels.