Amazon employee contact data surfaced in MOVEit leak from a vendor
- Organization
- Amazon
- Exploit
- Third-Party Data Breach
- Industry
- Retail
In November 2024, a forum user going by Nam3L3ss began publishing employee data sets on BreachForums that were drawn from the 2023 mass exploitation of Progress Software's MOVEit Transfer, tracked as CVE-2023-34362. The largest of the postings was attributed to Amazon and ran to roughly 2.8 million lines.
Amazon confirmed that employee information had been exposed but placed the breach outside its own environment. Spokesperson Adam Montgomery said Amazon and AWS systems remained secure and that the company had not experienced a security event of its own, adding that it had been notified of a security event at one of its property management vendors that affected several of that vendor's customers.
Reporting on the leaked files described the Amazon records as work contact details: employee names, work email addresses, desk phone numbers, building locations and internal cost center and organizational codes. Amazon said no Social Security numbers, financial information, credentials or customer records were included.
Nam3L3ss posted material tied to more than two dozen other organizations at the same time, among them HSBC, MetLife, HP, Lenovo, Delta Air Lines and McDonald's, and claimed to be holding a far larger archive of database files. The underlying MOVEit campaign, run by the Clop extortion group from May 2023, affected thousands of organizations and tens of millions of individuals.