Looking for a complete Amazon data breaches list? This page answers common searches like "Amazon hacked," "Amazon breach history," and "list of Amazon data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.
Amazon data breach history: Zappos, internal AmEx exposure, and marketplace seller leaks—Amazon’s breach timeline mixes retail, cloud, and logistics. BreachHistory indexes 12 verified or attested incidents tied to Amazon, spanning 2012–2023. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new Amazon notice drops.
Why Amazon stays on breach trackers
Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target Amazon for credentials, source code, CRM exports, and employee directories. When you read headlines about "Amazon hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.
Data breaches list — Amazon
Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."
- 2023 — Amazon data breaches — full timeline (Unverified / not disclosed records)
- 2021 — Twitch source code and streamer data leaked to 4chan (Unverified / not disclosed records)
- 2021 — EU fines Amazon €746m for GDPR violations (Unverified / not disclosed records)
- 2020 — Six indicted for bribing Amazon employees (marketplace) (Unverified / not disclosed records)
- 2019 — Amazon Japan — order histories and addresses exposed (Unverified / not disclosed records)
- 2018 — Krasr bribes — employees sabotage competitors (Unverified / not disclosed records)
- 2018 — Customer names and emails exposed (technical issue) (Unverified / not disclosed records)
- 2018 — Amazon: Customer names & email addresses were disclosed on… (5M+ records)
- 2018 — Amazon: Customer names and email addresses accidentally… (100K+ records)
- 2017 — AmEx credit card numbers exposed on internal network (24M+ records)
- 2016 — Hacker claims 80k Kindle accounts (#0x2Taylor) (80K+ records)
- 2012 — Zappos breach — 24M accounts (24M+ records)
Biggest and most consequential incidents
AmEx credit card numbers exposed on internal network
Cache of AmEx card numbers left unsecured on internal network for months; broadly available to employees. Audit logs only 90 days; abuse unclear. Full incident record →
Zappos breach — 24M accounts
Hacker breached Zappos (Amazon-owned); up to 24M customers. Amazon accounts reportedly not affected. Full incident record →
2018 — Amazon: Customer names & email addresses were disclosed on…
Nov 2018. Customer names & email addresses were disclosed on its website. Amazon hasn't confirmed how many records were exposed. Full incident record →
2018 — Amazon: Customer names and email addresses accidentally…
Nov 2018. Customer names and email addresses accidentally disclosed on its website, just two days ahead of Black Friday. No of users affected not released. Full incident record →
By the numbers (catalog snapshot)
- 12 incidents indexed under Amazon on BreachHistory
- 53.2M+ combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
- 2017 — year of the largest attested row in our catalog
Patterns in Amazon's breach history
- Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
- Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
- Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
- Supply-chain spillover — npm, SDK, and CRM tenant breaches affect Amazon customers even when corporate HQ databases stay intact.
What to do if you used Amazon
- Enable multi-factor authentication on every Amazon account and linked SSO identity.
- Check Have I Been Pwned when new Amazon headlines appear.
- Rotate passwords that were reused on email, banking, or work SSO.
- Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
- Follow official Amazon security communications—not SMS links from unknown numbers.
Related searches
- Amazon data breach list
- Has Amazon been hacked?
- Amazon hack history
- Amazon data leak timeline
- How many times has Amazon been breached?
- Amazon breach records on BreachHistory
FAQ
How many data breaches has Amazon had?
BreachHistory indexes 12 verified or attested Amazon data breaches spanning 2012–2023. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.
What is the biggest Amazon data breach?
The largest attested incident in our catalog is 24M+ records (AmEx credit card numbers exposed on internal network). See the full timeline for sources and remediation details.
Has Amazon been hacked?
Yes — Amazon appears on breach trackers with 12 indexed incidents including AmEx credit card numbers exposed on internal network. This page links every catalog row with primary sources and what users should do if affected.
Does Amazon send data breach notifications?
Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.
Explore every Amazon incident on BreachHistory
Browse the full catalog: Amazon breach records
Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.