Nov 21, 2018

Amazon says technical error disclosed customer information

An Amazon fulfillment center prepares for Black Friday sales. Photo: Leon Neal/Getty Images

The names and email addresses of some Amazon customers were revealed due to a technical error, but the issue has since been fixed, the e-commerce giant said Wednesday.

The big picture: Passwords do not appear to have been disclosed. Amazon's notice to impacted consumers even says that there is "no need for you to change your password or take any other action." If a bad guy saw the emails and passwords while they were exposed — and we don't know any did — they do not immediately have access to the accounts.

Why it matters: The glitch occurred just days before Black Friday and Cyber Monday, the busiest shopping days of the year. In theory, a bad guy who saw the names and email addresses could send scam emails pretending to be Amazon to users to try to steal log-in information, or could match email addresses with passwords from other sites' breaches to see if they work.

Quick take: Given the fact that millions of people around the world already have an account with Amazon, a bad guy could literally do this for Amazon accounts with any list of names and email addresses.

  • This isn't good by any stretch, and it may limit consumer confidence in the company. It's a bad look, especially given that Amazon fired an employee who shared customer data without permission.

What we know: Amazon says all affected users have been contacted and it fixed the issue.

What we don't know: How many users had data exposed, how long the data was exposed or how difficult the data would be to find.

Go deeper

John Kelly defends James Mattis against Trump attacks

John Kelly in the White House in July 2017. Photo: Cheriss May/NurPhoto via Getty Images

Former White House chief of staff John Kelly defended James Mattis on Thursday after President Trump attacked the former defense secretary as "the world's most overrated general" and claimed on Twitter that he was fired.

What he's saying: “The president did not fire him. He did not ask for his resignation,” Kelly told the Washington Post in an interview. “The president has clearly forgotten how it actually happened or is confused."

Barr claims "no correlation" between removing protesters and Trump's church photo op

Attorney General Bill Barr said at a press conference Thursday that there was "no correlation" between his decision to order police to forcibly remove protesters from Lafayette Park and President Trump's subsequent visit to St. John's Episcopal Church earlier this week.

Driving the news: Barr was asked to respond to comments from Defense Secretary Mark Esper, who said Tuesday that he "did not know a photo op was happening" and that he does everything he can to "try and stay out of situations that may appear political."

Updates: Cities move to end curfews for George Floyd protests

Text reading "Demilitarize the police" is projected on an army vehicle during a protest over the death of George Floyd in Washington, D.C.. early on Thursday. Photo: Yasin Ozturk/Anadolu Agency via Getty Images

Several cities are ending curfews after the protests over the death of George Floyd and other police-related killings of black people led to fewer arrests and less violence Wednesday night.

The latest: Los Angeles and Washington D.C. are the latest to end nightly curfews. Seattle Mayor Jenny Durkan tweeted Wednesday night that "peaceful protests can continue without a curfew, while San Francisco Mayor London Breed tweeted that the city's curfew would end at 5 a.m. Thursday.