Short answer: Sign in at ebay.com, go to My eBay → Account settings → Sign in and security, and turn on 2-step verification. Choose the authenticator app option where available, or a passkey — eBay now supports passkeys, which is the better choice if your device offers it. Then check your saved payment and payout details, because that is what an attacker actually wants.
What is at stake on eBay
Buyers and sellers face different versions of the same problem.
As a buyer: saved payment methods, delivery addresses, and purchase history. A compromised account can place orders to a redirected address before you notice.
As a seller: considerably worse. Your account holds a linked bank account for payouts, and account takeovers of sellers follow a well-worn script: change the payout details, list some high-value electronics at attractive prices, collect the money from buyers who never receive anything, and leave the real seller holding the disputes and a destroyed feedback rating.
Feedback ratings are the reason established accounts are targeted specifically. A ten-year account with 2,000 positive reviews sells fraudulent listings that a new account never could.
Step 1: Find the security settings
- Sign in at ebay.com.
- Hover My eBay (top right) → Account settings.
- Open Sign in and security.
- Look for 2-step verification.
eBay’s interface varies a little by region and account type, and the labels have changed over the years. If the wording differs, everything you need sits under the account security section.
Step 2: Choose the strongest method offered
eBay’s options depend on your region and device, but generally include:
- Passkey — the strongest option. Bound to eBay’s domain, so it cannot be used on a phishing page. If your phone or laptop offers it, take it. See passkeys vs 2FA.
- Authenticator app — six-digit codes generated offline. Scan the QR code with any standard app.
- SMS or push to the eBay app — convenient, and the weakest of the three. Text codes are exposed to SIM swapping.
If you set up an authenticator app, use any standard one — Google Authenticator, Aegis, 2FAS, Microsoft Authenticator, or a password manager. Start with what is an authenticator app if this is unfamiliar, and manual key entry if the QR will not scan.
Do not screenshot the QR code — it contains the raw secret key.
Step 3: Lock down the money
This is the part that matters more than the login on eBay specifically. Under Account settings:
- Payments / payouts — verify your linked bank account is correct. For sellers, this is the field attackers change first. Check it now and check it again after any suspicious activity.
- Saved payment methods — remove cards you no longer use.
- Addresses — delete old delivery addresses. An unfamiliar one appearing is a red flag.
- Email and phone on file — make sure both are current and that the email itself has strong 2FA. See our Google account guide.
eBay will notify you when payout details change, which is precisely why attackers also try to gain email access. Your inbox and your eBay account are one security problem, not two.
Step 4: The eBay-specific scams
Two-factor authentication stops account takeover. It does nothing against these, which are the actual day-to-day risk:
- Off-platform payment requests. A “buyer” or “seller” who wants to move to bank transfer, gift cards or a payment app. Every one is a scam, and you lose all eBay protection the moment you leave the platform.
- Fake payment confirmation emails claiming money is held pending shipment. eBay does not work this way.
- Phishing that mimics eBay messages. Always check messages inside your eBay account rather than trusting email links. Real eBay messages appear in your message centre; phishing does not.
- Overpayment and refund scams asking you to return the difference.
- Requests for your verification code — never, under any circumstance. See OTP scams.
Step 5: Sign out what you are not using
Check for active sessions and sign out anything unfamiliar. Also review any third-party listing tools, cross-posting services or analytics apps you have authorised — these hold API access to your account and are a common weak point for high-volume sellers.
If you sell seriously, treat your eBay credentials like business infrastructure: unique password, strongest available second factor, and no shared logins. Our guide to 2FA for small teams covers shared access properly.
Frequently asked questions
Does eBay support authenticator apps everywhere?
Availability varies by region and account type — some markets see app and passkey options, others primarily SMS and app push. Choose the strongest option your account displays; passkey first, app second, SMS last.
Should I use a passkey instead of an app?
Yes, if offered. Passkeys cannot be phished, and eBay phishing is relentless. Keep a second method registered for recovery. See what WebAuthn and FIDO2 are.
Why is my code being rejected?
Usually clock drift on your phone. Turn on automatic network time. More: why 2FA codes get rejected.
What if I lose access to my second factor?
eBay account recovery involves identity verification with customer support. Keep any backup codes you were given, and make sure the email and phone on file are current. See recovering accounts after losing your 2FA phone.
My seller account has been taken over. What do I do?
Contact eBay immediately, then change your password, check and correct the payout bank details, end any listings you did not create, and sign out all sessions. Speed matters — fraudulent listings accumulate buyer money and disputes by the hour.
Does 2FA protect me from buyer or seller fraud?
No. It protects the account. Transaction fraud is a separate problem handled by staying on-platform, using eBay’s payment system, and never agreeing to move a deal elsewhere.
The bottom line
Turn on the strongest method eBay offers you — passkey if you can, authenticator app if not — then spend five minutes on payout details, saved addresses and the email account behind it. For sellers especially, the login is only half the job: the bank details field is what the attack is actually aiming at.
Need a code while you set up? Our free online 2FA code generator runs entirely in your browser.