Monday, March 3, 2025
HomeData BreachAmazon Terminated Employees for Leaking Customers Sensitive Data Such as Email Address...

Amazon Terminated Employees for Leaking Customers Sensitive Data Such as Email Address & Phone Number

Published on

SIEM as a Service

Follow Us on Google News

Amazon fires a number of employees who have leaked customer’s sensitive data such as Email addresses and phone numbers to unauthorized 3rd parties.

Amazon disclosed this data leak to its customers via email and said that the actions committed by employees are a “violation of our policies.”

The company now supporting law enforcement for their prosecution, but there is very small information gathered about to whom they have shared the data.

Amazon didn’t reveal any information about how many customers were affected but the Email said that “No other information related to customer account was shared “

Amazon Fires Employees
Email that sent to customers about Data Leak

The email read to customers that “This is not a result of anything you have done, and there is no need for you to take any action,”

Amazon spoke person who said via Tech Crunch “We have fixed the issue and informed customers who may have been impacted.” The company emailed all impacted users to be cautious. “

Last year Amazon faced a similar incident in a year back when it sent a message to its customers who had received an email purporting to come from the company including the warning which says that their email addresses and names had been leaked.

Insider threats are very real and make up the majority of cybersecurity attacks on enterprises. Yet, many businesses still spend most of their time safeguarding their systems against outsider threats.

Also Read

5 Steps How To Protect Your Company Infrastructure From Insider Threats

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Njrat Exploits Microsoft Dev Tunnels for C2 Communication

A new campaign involving the notorious remote access trojan (RAT) Njrat has been uncovered,...

North Korean IT Workers Hide Their IPs Using Astrill VPN

Security researchers have uncovered new evidence that North Korean threat actors, particularly the Lazarus...

Paragon Partition Manager Vulnerabilities Allow Attackers to Escalate Privileges and Trigger DoS Attacks

Security researchers have uncovered five significant vulnerabilities in Paragon Partition Manager's BioNTdrv.sys driver, affecting...

Space Pirates Hackers Attacking IT Organizations With LuckyStrike Using OneDrive

A recent investigation by cybersecurity experts has unveiled a series of advanced cyberattacks orchestrated...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

260 Domains Hosting 5,000 Malicious PDFs to Steal Credit Card Data

Netskope Threat Labs uncovered a sprawling phishing operation involving 260 domains hosting approximately 5,000...

Authorities Arrested Hacker Behind 90 Major Data Breaches Worldwide

Cybersecurity firm Group-IB, alongside the Royal Thai Police and Singapore Police Force, announced the...

Orange Communication Breached – Hackers Allegedly Claim 380,000 Email Records Exposed

Telecommunications provider Orange Communication faces a potential data breach after a threat actor using the pseudonym “Rey”...