eBay Inc came under pressure on Thursday over a massive hacking of customer data as three US states began investigating the e-commerce company's security practices.
Connecticut, Florida and Illinois said they are jointly investigating the matter. New York Attorney General Eric Schneiderman requested eBay provide free credit monitoring for everyone affected.
Details about what happened are still unclear because eBay has provided few details about the attack. It is also unclear what legal authority states have over eBay's handling of the matter.
The states' quick move shows that authorities are serious about holding companies accountable for securing data following high-profile breaches at other companies, including retailers Target Corp, Neiman Marcus and Michaels and credit monitoring bureau Experian Plc.
Congress and the Federal Trade Commission are investigating the Target breach, which resulted in the firing of the company's chief executive and its chief information officer.
"There is definitely a climate shift," said Jamie Court, president of the advocacy group Consumer Watchdog. "The departure of the Target CEO over the problem signals inside the board room and in the halls of government that these are betrayals of customers and that they won't be tolerated."
EBay shares fell 0.7 on Nasdaq, compared with a 0.6 increase in the Nasdaq Composite Index.
The investigation by the states will focus on eBay's measures for securing data, circumstances that led to the breach and the company's response, said Jaclyn Falkowski, a spokeswoman for Connecticut Attorney General George Jepsen.
EBay spokeswoman Amanda Miller declined to comment on the states' actions, but said the company was working with authorities around the globe.
"We have relationships with and proactively contacted a number of state, federal and international regulators and law enforcement agencies," she said. "We are fully cooperating with them on all aspects of this incident."
Some customers complained on eBay Community forums that they had not received much information about the breach from eBay and have yet to get notifications by email, which the company has promised to do.
"This is all over the news - Nothing from eBay," sfbay111 said in one post on an eBay forum.
Several security experts said the best practices would be to have a message pop up when users log in, telling them about the breach and forcing password changes.
As of Thursday afternoon, eBay did not have information on the attack visible on its market home page, www.ebay.com.
"That's really poor incident response," said David Kennedy, a cyber forensics expert who is CEO of TrustedSEC