Amazon Data Breach History
WebsiteAmazon.com, Inc. is an American multinational technology company. Fortune 500.
This page shows all data breaches of Amazon. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Amazon Breaches
- 2025 2025 Amazon Q Developer for VS Code — destructive agent prompt shipped in v1.84 (CVE-2025-8217) Unknown records Share
- 2023 2023 Amazon data breaches — full timeline Unknown records Share
- 2021 Twitch source code and streamer data leaked to 4chan Unknown records Share
- 2021 EU fines Amazon €746m for GDPR violations Unknown records Share
- 2021 2021 — Amazon Reviews: Poor security / misconfiguration, 13,124,962 records 13.1M records Share
Amazon Data Breach Summary
This page tracks the Amazon data breach history and cybersecurity incidents affecting Amazon (United States). BreachHistory currently indexes 14 publicly disclosed or catalogued incidents spanning 2012 through 2025, with approximately 66.3 million records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Amazon breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed, while 1 remain unverified claims pending independent verification.
Largest Amazon Data Breaches
The largest indexed incidents include the 2017 AmEx credit card numbers exposed on internal network, the 2012 Zappos breach — 24M accounts, and the 2021 — Amazon Reviews: Poor security / misconfiguration, 13,124,962 records, along with additional historical incidents involving exposed passwords, public databases, and large-scale data scraping. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Amazon or a regulator. Below is the list of large data breaches:
- 2017 AmEx credit card numbers exposed on internal network — about 24.0M records exposed · Catalogued incident
- 2012 Zappos breach — 24M accounts — about 24.0M records exposed · Catalogued incident
- 2021 2021 — Amazon Reviews: Poor security / misconfiguration, 13,124,962 records — about 13.1M records exposed · Catalogued incident
- 2018 2018 — Amazon: Customer names & email addresses were disclosed on… — about 5.0M records exposed · Catalogued incident
- 2018 2018 — Amazon: Customer names and email addresses accidentally… — about 100.0K records exposed · Catalogued incident
- 2016 Hacker claims 80k Kindle accounts (#0x2Taylor) — about 80.0K records exposed · Unverified claim
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords and login credentials, names, physical addresses, payment card and financial account data, health and medical (PHI) records, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Amazon Data Breach 2026
At the time of this update, no Amazon data breach has been catalogued for 2026. New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Amazon data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Amazon breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.