Amazon has been ordered to pay a $2.25 million fine after the Federal Trade Commission (FTC) accused the company of refusing to help customers who were victims of identity theft . The case involves a violation of the US Fair Credit Reporting Act (FCRA) and highlights serious weaknesses in the way the company handles data from fraud victims.

According to the FTC complaint , Amazon systematically refused to provide identity theft victims with information about purchases made through fraudulent accounts. This meant that victims were unable to prove their innocence, reverse charges, or protect their financial information. The FTC argues that this behavior directly violates obligations under the FCRA , which requires companies to respond to victims’ requests within 30 days .
See also: Cloud: Amazon and Microsoft face off against the DMA law
The most notable incident described in the complaint involves a customer who contacted Amazon to remove their credit card information from a fraudulent account. The service representative refused to proceed unless the victim could name the fraudulent account holder — information they apparently did not have. The victim tried to guess the name more than 30 times, to no avail. The FTC describes this process as a “Kafkaesque sequence,” where victims are trapped in a vicious cycle, unable to address the issue.
Identity theft and Amazon's responsibility towards victims
Identity theft is one of the most widespread crimes in the digital world. In the US alone, millions of citizens fall victim to it every year, with criminals using stolen credentials to create accounts on platforms like Amazon and make purchases. The FCRA requires companies to cooperate with victims , providing them with transaction records so they can prove they are not responsible for the charges. Amazon’s refusal to do so is not just a technical violation — it is essentially abandoning its customers at an extremely difficult time.
The FTC said Amazon repeatedly failed to respond to victims’ requests within the 30-day set by the FCRA. This delay significantly worsens the situation for victims, as in the meantime the fraudulent accounts may continue to be used, charges may accumulate, and the victims’ creditworthiness may be negatively affected. The regulator argues that this behavior was not isolated, but was a systematic practice.
See also: Nearly 7,000 fake Amazon domains registered ahead of Prime Day 2026

$2.25 million fine and the changes announced by Amazon
Amazon agreed to pay $2.25 million to settle the case with the FTC, without admitting liability. A company spokesperson told Bloomberg that Amazon “resolved the matter with the FTC” and “implemented process improvements for customers who believe they may have been victims of identity theft.” However, the company did not disclose details of the changes it implemented. According to The Verge, the case was previously reported by Bloomberg.
The $2.25 million fine may seem small for a company with hundreds of billions of dollars in annual revenue like Amazon. However, the significance of the case lies not in the size of the fine, but in the precedent it sets: Big tech companies cannot ignore their legal obligations to victims of identity theft. The FTC is sending a clear message that compliance with the FCRA is not optional.
See also: Amazon investigates its engineers for testifying in favor of regulating AI data centers
For consumers, this case is a reminder of the importance of protecting your personal information. If you are a victim of identity theft, you have a legal right to request records of transactions made in your name from companies like Amazon. It is recommended that you regularly monitor your bank account transactions, use unique passwords for each service, and enable two-factor authentication (2FA) where available. If you see suspicious activity, contact both the company and your bank immediately.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
