Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsAmazon disclosed on November 21, 2018, that a website technical error had exposed some customers’ names and email addresses. Amazon said it fixed the issue, notified affected customers and told them they did not need to change their passwords. The public record does not include a detailed forensic report, so that reassurance should be attributed to Amazon rather than treated as an independently verified audit. This was a 2018 incident, not evidence of a newly confirmed Amazon breach in 2026.
What happened in the 2018 Amazon disclosure?
Amazon described a technical error that inadvertently disclosed customer information. The company said the issue had been fixed and affected customers informed; it also said the incident was not caused by anything customers had done. Contemporary reporting placed the disclosure just before the 2018 Black Friday and Cyber Monday shopping period, a time when convincing retail-themed phishing attempts could be especially concerning. That timing is historical context, not a warning about a current incident.
Amazon reportedly distinguished the event from an attacker breaking into its websites or systems. News outlets often called it a data breach or security incident because customer information was disclosed without authorization. In this context, “technical error” describes Amazon’s account of the cause; “breach” can describe the unauthorized disclosure more broadly.
What information was exposed—and what remains unknown?
| Information or detail | What the public record establishes |
|---|---|
| Customer names and email addresses | Reported as the information disclosed. TechCrunch’s contemporaneous report covered the disclosure. |
| Passwords | Amazon’s notice said customers did not need to change their passwords. Contemporary reporting said passwords did not appear to have been disclosed, but Amazon did not publish a detailed forensic account of every data field examined. Ars Technica reproduced and reported on the notice. |
| Payment-card details, orders, addresses, phone numbers, or other account contents | Not reported as exposed in the contemporaneous coverage cited here; the public record does not establish a comprehensive field-by-field investigation. |
| Number of affected customers | Amazon did not provide a public count in the reporting at the time. Claims that a particular number—or “millions”—were affected are not confirmed by that reporting. Ars Technica noted the lack of a disclosed figure. |
| Where the error occurred, how long information was exposed, or whether anyone copied it | Not publicly established in the contemporaneous reporting. TechCrunch covered the limited details supplied by Amazon. |
Were Amazon passwords exposed?
There is no public report in the cited contemporaneous coverage that Amazon passwords were disclosed in this incident. Amazon’s notification said a password change was unnecessary. Because the company did not release a detailed forensic report, the most accurate wording is that passwords were not reported as exposed and Amazon said customers did not need to change them—not that an independent audit proved they could not have been accessed.
#1 Best Overall
The distinction matters: the incident disclosed identifying information, not credentials according to the public accounts. A name and email address alone do not authenticate someone to an Amazon account, but they can help a scammer make a fraudulent message sound personal. Separately, if you reused your Amazon password on another service whose credentials were compromised, that reuse can put the Amazon account at risk even though the 2018 incident itself did not report password exposure.
What should you do if you received the old notification?
Receiving a historical notice does not by itself prove that your account was hacked, and Amazon said a password reset was not required because of this event. Use the checks below to address current account security without trusting an old email link.
- Open Amazon directly. Use the official app or type Amazon’s address yourself rather than clicking a link in an old message. Amazon’s current scam guidance recommends checking account issues through its website or app.
- Review account details. In the app or site, open Account → Login & security and inspect the account information. Review recent orders and account activity for changes you do not recognize; menu wording can vary by region and app version.
- Use a unique password. Change the Amazon password if it is reused on another site, weak, old, or if you entered it on a suspicious page. Use a unique password for the email account linked to Amazon as well.
- Turn on two-step verification or set up a passkey. Amazon Pay documents the two-step-verification path as Account & Lists → Your Account → Login & security → Advanced Security Settings → Edit/Get Started; labels can vary by region and account. See Amazon Pay’s two-step verification guidance. Amazon also describes passkeys in its passkey setup guidance. A passkey can reduce exposure to ordinary password phishing, but keep device security and account recovery in mind.
- Secure the linked email account. Enable multifactor authentication with the email provider, review recent sign-ins and forwarding rules, and remove unfamiliar recovery methods. Access to that mailbox may allow someone to reset the Amazon password.
- Check for other known breaches if useful. Have I Been Pwned can check whether an address appears in breach records it has processed. A “not found” result does not prove the address has never been exposed, and a listing does not show that your Amazon account was compromised. The service explains what breach data it stores in its data and information overview.
How to handle an Amazon message that looks suspicious
Names and email addresses can make impersonation attempts more convincing, but an unexpected message is not proof that the sender has access to your Amazon account. Scammers may claim there is an account suspension, refund, delivery problem or suspicious order to pressure you into acting quickly.
- Do not follow an unexpected account-alert link. Open Amazon directly and check the account there.
- Never give a sender or caller your password or one-time verification code, and do not provide payment details or pay with gift cards in response to an unsolicited message.
- If you entered credentials on a page reached from a suspicious message, change that password from the official site and change it anywhere else you reused it. Review the account and linked email for unfamiliar activity.
- If you see an unfamiliar order, address, sign-in or payment change, use Amazon’s official help flow to report it.
Amazon’s scam-avoidance advice warns that impersonation can arrive by email, text, phone or social media, and covers requests for account details, payments and codes.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




