Amazon touches nearly every consumer purchase online and operates AWS—the cloud backbone of the internet. Searches for Amazon data breach timeline spike after every Twitch leak, seller scandal, or email exposure notice. BreachHistory tracks 13 Amazon-linked incidents from the 2012 Zappos breach through 2026.
Amazon's breach profile
Amazon incidents cluster into: subsidiary breaches (Zappos), configuration errors (2018 email exposure, 2021 Twitch), insider marketplace corruption (bribed employees deleting competitor reviews), regulatory enforcement (GDPR), and internal storage mistakes (2017 AmEx numbers on internal networks).
Chronological timeline
2021 — Twitch source code and payout leak
In October 2021 an anonymous poster dropped Twitch source code, internal tools, and streamer payout spreadsheets on 4chan—a configuration error, not a password breach. Passwords and full payment cards were not in the leak, but creator earnings data was highly sensitive for doxing and extortion.
Same year: EU regulators fined Amazon €746 million for GDPR violations—a privacy enforcement action with breach-like consumer impact.
2020–2021 — Marketplace insider bribery
Six people were indicted for bribing Amazon employees to reinstate suspended seller accounts and leak competitor data—insider threat, not external hacker, but personal data changed hands.
2019 — Amazon Japan order history bug
Amazon Japan exposed other customers' order histories and addresses via an access-control bug—classic IDOR failure affecting trust in Asia-Pacific operations.
2018 — Customer email accidental exposure
Amazon disclosed a technical error exposing customer names and emails on its website—small field set, massive phishing risk. Related catalog rows estimate up to 5 million and 100,000 affected in overlapping filings.
Krasr bribery scheme (2018) saw employees sabotage Marketplace competitors—another insider row.
2017 — Internal AmEx card storage
Security researchers found 24 million American Express card numbers on an unsecured internal Amazon segment—employees and legacy systems, not checkout pages.
2016 — Disputed Kindle account claim
Hacker #0x2Taylor claimed 80,000 Kindle accounts; Amazon denied a breach. Indexed with dispute noted—do not treat as confirmed.
2012 — Zappos: the landmark consumer breach
Zappos lost 24 million accounts—names, emails, addresses, phone numbers, encrypted passwords. Amazon's acquisition integration lesson: subsidiary security equals parent brand risk.
2026 and AWS note
AWS customer misconfigurations cause daily exposures, but those are tenant errors—not Amazon.com corporate breaches. BreachHistory separates Amazon retail/subsidiary rows from generic S3 bucket leaks unless Amazon corporate systems are attested.
If you're an Amazon customer
- Enable 2FA on Amazon.com and Twitch.
- Watch phishing after any email exposure—Amazon will not ask for passwords via link.
- Use unique passwords for Zappos/Twitch/Amazon—credential stuffing is the main follow-on attack.
- Sellers: treat employee access to Seller Central as high-value insider risk.
Explore all rows: breachhistory.com/amazon · Twitch: Twitch 2021 leak · Zappos: Zappos 2012