Amazon has acknowledged that a technical error exposed customer names and email addresses to undisclosed parties, a privacy lapse that surfaced as the company headed into its busiest shopping period.
The retailer said it emailed an undisclosed number of customers on Wednesday to explain that the information had been shared inadvertently. Amazon said the problem has been fixed and told customers there was no need to change their passwords.
“We have fixed the issue and informed customers who may have been impacted,” Amazon said in the email, while declining to say who received the data.
How regulators respond may depend on where the affected customers live, according to Marc Rotenberg, president of the Electronic Privacy Information Center. He said the U.S. Federal Trade Commission has often been reluctant to pursue privacy cases, but the European Union would likely investigate and fine a company if customer data from its jurisdiction had been exposed. Bloomberg reported that the FTC declined to comment.
Rotenberg said the incident could trigger a European enforcement response because it appeared to breach a basic data protection duty. “That will lead to an investigation and likely a fine,” he said.
Cybersecurity specialist Andy Norton of Lastline Inc. said Amazon should have given more detail about what went wrong and warned shoppers about possible email phishing attempts tied to the exposed contact information.
“This could be viewed as one of the worst breach notes in history,” he said. “It is creating confusion and uneasiness, and creating more questions than answers, when it should have done the opposite.”
Online holiday sales are expected to top $124 billion this year, up 14.8% from a year earlier, according to Adobe Inc. Thanksgiving, Black Friday and Cyber Monday are expected to be among the biggest spending days in the U.S.
The disclosure comes with memories of the 2013 holiday shopping season, when Target suffered a major data leak. Hackers stole credit- and debit-card data, along with personal information, for tens of millions of customers, a breach that hurt sales, dragged down the stock and helped lead to the exit of Chief Executive Officer Gregg Steinhafel.