Data breach
Amazon
- Records
- 2,861,101
- Breach date
- 31 May 2023Estimated
- Added
- 13 November 2024
What was exposed
7 types of data
- Employment2,861,101
- Employers2,861,101
- Job descriptions2,861,101
- Job titles2,860,530
- Names2,858,916
- Email addresses2,825,976
- Phone numbers48,577
About this breach
Over 2.8 million lines of Amazon employee data were published on a hacking forum in November 2024, more than a year and a half after the underlying theft. The data was taken during the May 2023 mass exploitation of MOVEit Transfer, a widely used corporate file transfer tool, and it surfaced through a threat actor using the alias "Nam3L3ss." Amazon confirmed the incident, saying the information came from a breach at a third-party property management vendor, not from Amazon's own systems. Amazon spokesperson Adam Montgomery told TechCrunch that the only Amazon data involved was employee work contact information, such as work email addresses, desk phone numbers, and building locations. Amazon said the vendor does not have access to sensitive data like Social Security numbers or financial information, and that the vendor has since fixed the vulnerability used in the attack.
According to our investigation team, this listing contains roughly 2.86 million records, with an estimated breach date of May 31, 2023.
May 31, 2023: Attackers began exploiting a zero-day vulnerability in MOVEit Transfer, identified as CVE-2023-34362, allowing unauthorized access to files without authentication. Amazon's employee data dates to this period.
November 11, 2024: The threat actor Nam3L3ss posted more than 2.8 million lines of Amazon employee data on BreachForums, along with data from roughly 25 other major companies, as first reported by cybersecurity firm Hudson Rock and covered by BleepingComputer.
November 11, 2024: Amazon confirmed the breach, attributing it to a security event at a third-party property management vendor, and stated that Amazon and AWS systems remained secure.
What Information Was Compromised?
Our analysis found the following data types in this breach: names, work email addresses, job information including job titles, employers, and job summaries, and phone numbers for a smaller subset of records.
Amazon's own statement, reported by 404 Media and BleepingComputer, indicates the exposed records also included desk phone numbers and building locations. Hudson Rock noted that the stolen directories held employee details such as email, phone, cost codes, and in some cases organizational hierarchies.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The exposed data is limited to work contact details, so it does not include passwords, Social Security numbers, or financial information. That reduces the risk of direct account takeovers, but the data can still be misused.
Because the leak includes job titles, employers, and in some cases organizational structures, it is well suited to targeted phishing and business email compromise. An attacker who knows an employee's name, role, and work email can craft convincing messages impersonating colleagues, vendors, or IT staff. Exposed work emails may also receive more spam and scam attempts. Current and former Amazon employees whose contact details appear in the leak should treat unsolicited messages claiming to be from Amazon, HR, or IT with extra suspicion.
What Is Amazon Doing in Response?
Amazon confirmed the breach and said the affected third-party vendor has patched the vulnerability used in the attack. The company stated that Amazon and AWS systems were not breached and that the vendor only had access to employee work contact information. Amazon declined to say how many employees were affected.
What Should You Do If You Were Affected?
If you worked for Amazon or believe your work contact information may be in this leak, here are sensible steps:
Be cautious with unexpected emails, calls, or messages that reference your job, workplace, or coworkers. Verify requests through known internal channels before responding.
Do not click links or open attachments in unsolicited messages that claim to come from Amazon, HR, IT support, or payroll.
Use strong, unique passwords and enable two-factor authentication on your work and personal accounts.
Consider marking suspicious work emails as phishing through your internal reporting tools so security teams can track campaigns.
Remember that Amazon customers were not affected by this incident. This breach involved employee contact information only, so customer passwords do not need to be changed as a result of it.
In the news
- BleepingComputer: Amazon confirms employee data breach after vendor hackbleepingcomputer.com (opens in a new tab)
- TechCrunch: Amazon confirms employee data stolen after hacker claims MOVEit breachtechcrunch.com (opens in a new tab)
- 404 Media: Amazon Confirms Breach of Employee Data404media.co (opens in a new tab)
