# Amazon Fined $2.25 Million for Denying Fraud Victims Access to Transaction Records


FTC enforcement action reveals systemic failures in identity theft victim support and FCRA compliance


The U.S. Federal Trade Commission has ordered Amazon to pay $2.25 million to settle charges that the company systematically denied identity theft victims access to their fraudulent transaction records—a violation of federal law that left consumers unable to defend themselves against fraud and hindered law enforcement investigations.


## The Core Violation


Amazon failed to comply with Section 609(e) of the Fair Credit Reporting Act (FCRA), which requires companies to provide consumers with copies of transaction records related to fraudulent activity within 30 days of request. The FTC's investigation uncovered a pattern of non-compliance that extended beyond simple administrative failures: Amazon customer service agents actively blocked access by citing "privacy" or "security" concerns—rationales the FTC deemed improper under the law.


In some cases, Amazon agents told consumers they lacked technical capability to retrieve the records. The company even refused to honor legitimate requests from law enforcement agencies acting on behalf of identity theft victims, undermining both consumer protection and official investigations.


## Timeline and Scope


| Period | Key Finding |

|-----------|----------------|

| April 2024 – Present | Fraudulent transaction record requests denied or delayed |

| 30-day compliance window | Amazon frequently missed the legally mandated deadline |

| Recent enforcement | FTC settlement filed July 1, 2026 |


The FTC did not disclose the total number of affected consumers, though the scope of enforcement suggests a systemic issue affecting thousands of fraud victims seeking to reclaim their accounts and protect their credit.


## Background: Why These Records Matter


Identity theft victims depend on transaction records to:

  • Prove fraudulent activity to credit bureaus and financial institutions
  • Support disputes with their banks and credit card companies
  • Build cases for law enforcement and civil litigation
  • Freeze accounts and prevent further unauthorized transactions
  • Recover damages through federal and state consumer protection laws

  • The FCRA recognizes transaction records as critical evidence. When a company delays or refuses to provide these documents, victims lose months of protection—time during which additional fraud can occur and their credit scores continue to deteriorate.


    ## The Regulatory Requirement


    Section 609(e) of the Fair Credit Reporting Act explicitly mandates that companies provide:

  • Complete records of transactions made by unauthorized parties in a consumer's name
  • Delivery within 30 days of a lawful request
  • No legal discretion to withhold based on company concerns about privacy or security

  • The law applies equally to consumers and law enforcement agencies acting with proper authorization. Amazon's refusal to cooperate with law enforcement was particularly egregious, as it obstructed official investigations into identity theft rings.


    ## What Amazon Did Wrong


    The FTC's complaint identified multiple categories of violations:


    1. Outright Denials

    Customer service agents refused requests entirely, citing vague "privacy" or "security" reasons that lack legal grounding under the FCRA.


    2. False Capability Claims

    Agents claimed Amazon lacked the technical ability to retrieve transaction records—implausible given Amazon's sophisticated data infrastructure.


    3. Missed Deadlines

    When records were provided, they often arrived well beyond the 30-day window, defeating the purpose of timely fraud victim assistance.


    4. Law Enforcement Obstruction

    Perhaps most troubling: Amazon refused lawful requests from law enforcement agencies authorized to request records on behalf of victims. This created a direct obstruction of criminal investigations into identity theft operations.


    5. Lack of Escalation Process

    Frustrated consumers who escalated complaints or sent copies of FCRA guidance to Amazon still received no assistance, suggesting a systemic indifference rather than individual agent errors.


    ## The Settlement Terms


    Under the proposed order, Amazon must:


  • Pay $2.25 million in civil penalties
  • Establish a new process to provide transaction records within 30 days of lawful request
  • Train staff on FCRA compliance requirements
  • Notify affected consumers who submitted requests since April 2024 without receiving records, informing them of their right to resubmit
  • Comply with all future law enforcement requests that meet authorization standards
  • Implement monitoring and audit mechanisms to ensure sustained compliance

  • The settlement does not require Amazon to admit wrongdoing, a common feature of FTC settlements that has drawn criticism from consumer advocates who argue it allows companies to settle without reputational consequences.


    ## Broader Context: A Pattern of Non-Compliance


    Amazon's violations echo a similar 2019 enforcement action against Kohl's Department Stores, which paid $220,000 to settle charges of refusing to provide fraudulent transaction records to victims. The recurrence of this violation across major retailers suggests either widespread ignorance of the FCRA requirement or deliberate cost-cutting through understaffing of compliance functions.


    This is not Amazon's first FTC enforcement action:

  • July 2023: $25 million fine for Alexa privacy violations involving children's data
  • September 2025: $2.5 billion settlement for using "dark patterns" to trap consumers in Prime memberships and obscure cancellation options

  • The accumulation of major FTC penalties indicates systemic compliance failures across Amazon's consumer-facing operations.


    ## Why This Matters: The Broader Fraud Ecosystem


    Amazon's obstruction of fraud victims occurs within a broader context of rising identity theft losses. The FTC reported $3.5 billion in losses to imposter scams in 2025 alone, and fraudsters increasingly exploit e-commerce platforms to test stolen payment credentials and make unauthorized purchases.


    When companies delay or deny transaction records to victims, they:

  • Extend fraud timelines (allowing criminals to make more unauthorized purchases)
  • Weaken law enforcement investigations into organized fraud rings
  • Increase victim recovery costs (victims must hire attorneys or dispute managers)
  • Undermine credit reporting accuracy (fraudulent accounts remain on credit reports longer)

  • ## HackWire Analysis


    Amazon's obstruction reveals a troubling corporate incentive structure. The $2.25 million fine—roughly 0.0001% of Amazon's annual revenue—creates minimal financial pressure to change behavior. More revealing is the pattern: Amazon actively resisted compliance, with customer service agents citing "privacy" and "security" concerns that contradicted federal law. This suggests deliberate training, policy, or tone-setting that discouraged providing records rather than administrative incompetence.


    The refusal to honor law enforcement requests is the most serious element. When companies obstruct official investigations, they are not merely violating a consumer protection statute—they are actively protecting the fraud ecosystem. If law enforcement cannot obtain transaction records from major platforms, fraud rings operate with impunity. This is especially relevant to the organized schemes involving stolen data of millions of elderly Americans (referenced in related cases) and large-scale identity theft operations that depend on anonymity across multiple retail platforms.


    What's missing from this enforcement action: The FTC did not disclose whether Amazon's delays were intentional or systematic. If the company simply underfunded compliance, retraining and monitoring should fix it. If Amazon deliberately obstructed victims to reduce customer service costs, the penalty is insufficient. The settlement's silence on this distinction leaves open the question of whether Amazon's behavior is likely to persist at smaller scales.


    For defenders: Organizations subject to the FCRA (most financial institutions and major retailers) should audit their transaction record fulfillment processes immediately. Measure: Are you meeting the 30-day deadline for ALL requests? Are customer service agents correctly trained on which requests are legally mandatory? Do you have an escalation path for consumers who encounter resistance? An audit now will reveal whether your company has similar exposure.


    HackWire Editorial


    ## Implications for Consumers and Organizations


    For individual consumers: If you've been an identity theft victim and Amazon (or any major retailer) denied your request for transaction records, the settlement notification should provide an avenue to resubmit. Document your original request dates and any communication with Amazon denying access—this creates evidence for credit bureaus and law enforcement.


    For retail and e-commerce platforms: Audit your FCRA Section 609(e) processes immediately. The FTC has signaled active enforcement in this area. Ensure:

  • Customer service training explicitly covers mandatory record provision
  • 30-day timelines are baked into workflow systems
  • Law enforcement requests receive dedicated, compliant handling
  • There is no ambiguity that "privacy concerns" can override FCRA requirements

  • For law enforcement: This settlement affirms your authority to request transaction records on behalf of identity theft victims. If retailers continue to resist, document their non-compliance and report to the FTC.


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)