Wow, pretty shocking. Are you able to share more detail?
I think so.
I was at work yesterday, about to start an after-school ukulele club, when I checked my phone/email. I had an email from TB stating that my email address was recently changed, and if I did not authorize the change, to contact admin. Right there, I was pretty sure someone hacked my TB account. This was about 3:25pm.
At 4:45pm, I'm done with the uke club, head to my car, and head to TB (as a guest) and search my user name. It had a for sale ad up, but my account was marked 'inactive'. I contact TB stating that my account was hacked (via the basic 'contact us' link on the bottom of the site). I got a phonecall from a mod around 5:45pm telling me what happened, and that a hacker posted a pedal for sale. They got about 5 people to pay for this pedal, and then my account was shut down.
I'm amazed how quickly the account was shut down (about 90 minutes after it was compromised), but disgusted at the speed with which a scammer was able to operate and trick people into sending money. I read the DMs...poor language/grammar, sometimes their PayPal wouldn't work so they gave out a SECOND email/PayPal for people to send money to. In one case, the PayPal didn't work and they switched it to Venmo. I have a bunch of emails of this hacker, but I bet they were all new/temporary ones.
So that's it, in a nutshell. Like I said, I didn't regularly cycle passwords for sites I considered 'less sensitive', but I'll be updating/changing them all more regularly now. Also, I'll be looking for grammatical anomalies with any future potential people I transact with. If someone's posts and discussion style suddenly changes, that should be a red flag. I think the buyers that were scammed in this case were just so excited to get this pedal that they overlooked the red flags.