Source: site

The Federal Trade Commission has ordered Amazon to pay $2.25 million in civil penalties to resolve allegations that the company knowingly violated the Fair Credit Reporting Act (FCRA) by denying identity theft victims access to fraud‑related transaction records they are entitled to under federal law.
Case overview
The FTC’s complaint, filed by the Department of Justice in federal court in Washington, D.C., alleges that Amazon repeatedly failed to comply with Section 609(e) of the FCRA. Section 609(e requires any company that conducted or recorded a transaction using information stolen from an identity theft victim to provide, within 30 days and at no charge, copies of application and business transaction records related to that fraud. According to the FTC, Amazon routinely refused or obstructed these requests from consumers whose credit or debit card information and other personal data were used to complete unauthorized purchases on its platform.
How Amazon allegedly violated FCRA 609(e)
Regulators say victims who contacted Amazon seeking records about fraudulent accounts encountered what the FTC described as a “Kafkaesque sequence” with customer service. In many instances, Amazon allegedly required victims to identify the fraudster by name before providing any records, despite the fact that the law does not impose such a requirement. One victim reportedly resorted to guessing more than 30 names in an effort to satisfy the demand, and still did not receive the requested documents or have their card removed from the fraudulent account. The complaint also alleges that Amazon failed to respond to valid records requests within the 30‑day timeframe mandated by Section 609(e).
Beyond these procedural failures, the FTC contends that Amazon lacked any written policy for handling identity theft records requests for years, even after agency staff had specifically advised the company to review and shore up its Section 609(e) compliance. Amazon did not implement such a policy until early 2025, and only after learning it was under active FTC investigation.
Settlement terms and injunctive relief
Under the proposed consent order, Amazon will pay $2.25 million in civil penalties, which the FTC notes is the largest penalty it has ever obtained for a violation of FCRA Section 609(e). While modest relative to Amazon’s overall revenues, the order includes extensive behavioral remedies aimed at preventing future violations. The order prohibits Amazon from failing to comply with Section 609(e) going forward, and obligates the company to provide fraud records requested by identity theft victims and by law enforcement agencies acting on their behalf.
The settlement also requires Amazon to:
-
Establish and maintain a clear written process for verifying and responding to identity theft records requests, including staff training on FCRA obligations.
-
Notify consumers about their rights under Section 609(e) and explain how identity theft victims can request transaction and application records from Amazon.
-
Proactively reach out to consumers who requested records from Amazon since April 2024 but did not receive them, informing those individuals that additional records may exist and that they may submit new requests.
If approved by the U.S. District Court for the District of Columbia, the consent order will put Amazon under a federal court mandate to provide identity theft victims with relevant transaction and application records free of charge within 30 days of a valid request.
Broader enforcement context for FCRA and e‑commerce
The Amazon case continues a pattern of heightened federal scrutiny of large technology and e‑commerce platforms around data rights, identity theft response, and consumer protection more broadly. In recent years, the FTC has targeted major firms for dark patterns in subscription enrollment and cancellation flows, deceptive disclosures, and failures to honor statutory access rights to consumer data. The agency has previously pursued similar Section 609(e) actions, including matters involving retailers that failed to provide identity theft victims with fraud‑related records, but the $2.25 million penalty against Amazon is more than ten times the civil penalty imposed in at least one prior case involving another national retailer.
For companies that store or process payment card and identity data associated with online transactions, the case underscores the FTC’s willingness to treat Section 609(e) as a substantive data‑access right that requires operational follow‑through, not merely a legal notification. The complaint highlights that informal, ad hoc approaches to identity theft inquiries—and reliance on frontline staff to improvise responses without documented procedures—are likely to draw enforcement if they result in systemic denial or delay of records requests.
Implications for credit and collection industry stakeholders
While Amazon’s business model differs from that of traditional credit grantors and third‑party debt collectors, the settlement carries several compliance lessons for financial services and collections organizations that hold consumer account and transaction data.
Key takeaways include:
-
Formal policies and training are essential. The FTC’s emphasis on Amazon’s lack of written procedures and systematic training suggests that regulators expect documented 609(e) workflows, not just general customer service scripts.
-
Timely response is a core risk vector. Section 609(e) contains a clear 30‑day deadline, and the complaint’s focus on delayed responses indicates that failure to meet that timeframe can be treated as a stand‑alone violation, even apart from record‑denial issues.
-
Identity verification must be reasonable. Conditioning records access on a victim’s ability to identify the fraudster runs contrary to the statute’s intent and may be viewed as an impermissible barrier to exercising data rights.
-
Cross‑functional coordination matters. Because fraud records often sit in different systems—payments, customer accounts, internal investigation tools—organizations need cross‑department processes to compile and release complete records packages when an identity theft victim, law enforcement officer, or collection‑industry partner makes a request.
For credit and collection professionals, the Amazon settlement is a timely reminder that even non‑traditional “credit reporting” contexts can trigger FCRA obligations, particularly when identity theft is involved and transaction records are necessary to help victims dispute debts, unwind fraud, or respond to collection activity. Agencies and creditors that rely on online portals, marketplace platforms, or embedded fintech partners to originate or service accounts should review how those partners handle 609(e) requests and ensure contract language and oversight processes reflect FCRA expectations.





