← Blog

Data Breaches List of Amazon

Share on X

Looking for a complete Amazon data breaches list? This page answers common searches like "Amazon hacked," "Amazon breach history," and "list of Amazon data breaches" with a verified timeline, record counts, root causes, and step-by-step guidance if you may have been affected.

Amazon data breach history: Zappos, internal AmEx exposure, and marketplace seller leaks—Amazon’s breach timeline mixes retail, cloud, and logistics. BreachHistory indexes 12 verified or attested incidents tied to Amazon, spanning 2012–2023. This page is a complete, searchable timeline—not a single event—linking every catalog row with context on scale, root cause, and what users should do when a new Amazon notice drops.

Why Amazon stays on breach trackers

Global tech brands combine massive user bases, high-value intellectual property, and complex supply chains. Attackers target Amazon for credentials, source code, CRM exports, and employee directories. When you read headlines about "Amazon hacked," the incident may be a consumer PII leak, a developer artifact exposure, or a third-party SaaS tenant breach—each with different remediation steps.

Data breaches list — Amazon

Below are the major incidents in our catalog, newest first. Record counts use company, regulator, or Have I Been Pwned attestation where available; actor-only marketing shows as "Unverified / not disclosed."

Biggest and most consequential incidents

AmEx credit card numbers exposed on internal network

Cache of AmEx card numbers left unsecured on internal network for months; broadly available to employees. Audit logs only 90 days; abuse unclear. Full incident record →

Zappos breach — 24M accounts

Hacker breached Zappos (Amazon-owned); up to 24M customers. Amazon accounts reportedly not affected. Full incident record →

2018 — Amazon: Customer names & email addresses were disclosed on…

Nov 2018. Customer names & email addresses were disclosed on its website. Amazon hasn't confirmed how many records were exposed. Full incident record →

2018 — Amazon: Customer names and email addresses accidentally…

Nov 2018. Customer names and email addresses accidentally disclosed on its website, just two days ahead of Black Friday. No of users affected not released. Full incident record →

By the numbers (catalog snapshot)

  • 12 incidents indexed under Amazon on BreachHistory
  • 53.2M+ combined attested records across rows with disclosed numerators (many incidents overlap or count emails—not unique people)
  • 2017 — year of the largest attested row in our catalog

Patterns in Amazon's breach history

  • Credential and session theft — Phishing, stuffing, and OAuth token abuse recur across tech platforms.
  • Cloud misconfiguration — S3 buckets, misconfigured APIs, and file shares expose data without a traditional "hack."
  • Extortion without precise counts — Ransomware and leak-site actors often publish before victims confirm scope.
  • Supply-chain spillover — npm, SDK, and CRM tenant breaches affect Amazon customers even when corporate HQ databases stay intact.

What to do if you used Amazon

  1. Enable multi-factor authentication on every Amazon account and linked SSO identity.
  2. Check Have I Been Pwned when new Amazon headlines appear.
  3. Rotate passwords that were reused on email, banking, or work SSO.
  4. Watch for phishing that cites real breach details (order numbers, usernames) to appear legitimate.
  5. Follow official Amazon security communications—not SMS links from unknown numbers.

Related searches

FAQ

How many data breaches has Amazon had?

BreachHistory indexes 12 verified or attested Amazon data breaches spanning 2012–2023. Counts vary when researchers merge scraping, misconfiguration, and ransomware as separate events.

What is the biggest Amazon data breach?

The largest attested incident in our catalog is 24M+ records (AmEx credit card numbers exposed on internal network). See the full timeline for sources and remediation details.

Has Amazon been hacked?

Yes — Amazon appears on breach trackers with 12 indexed incidents including AmEx credit card numbers exposed on internal network. This page links every catalog row with primary sources and what users should do if affected.

Does Amazon send data breach notifications?

Regulated markets require consumer notices for many PII events. Not every source-code or scraping story triggers email alerts—read each incident row for notification status.

Explore every Amazon incident on BreachHistory

Browse the full catalog: Amazon breach records

Compiled from BreachHistory data/breaches.json and primary sources linked on each incident page. Updated 2026-06-15.