E-commerce company eBay said client identity information including emails, addresses and birthdays was stolen in a hacking attack between late February and early March.
EBay urged users to change their passwords after the attack on a database that also contained encrypted passwords, physical addresses and phone numbers.
The company said it found no evidence of any unauthorized access to financial or credit card information, which is stored separately in encrypted formats.
EBay shares fell as much as 3.2% on Wednesday morning after the latest high-profile hacking attack on a US company.
“For the time being, we cannot comment on the specific number of accounts impacted,” eBay spokeswoman Kari Ramirez said. “However, we believe there may be a large number of accounts involved and we are asking all eBay users to change their passwords.”
EBay said it was probing the breach and working with law enforcement agencies.
The company also said it had not seen any indication of increased fraudulent account activity on eBay and that there was no evidence that its online payment service PayPal had been affected in the attack.
The attack on eBay was made through compromised employee accounts that allowed unauthorized access to its corporate network, the company said in a statement. It said the breach was first detected about two weeks ago.