CSIDB logo
Incident

Amazon.com Inc.

Incident posture

Attack window
Apr 2017
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-07 00:00

Linked entities

Victim
Amazon.com Inc.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers targeted third-party sellers on a major e-commerce platform, exploiting vulnerabilities to gain unauthorized access to seller accounts. The incident impacted numerous merchants operating through the marketplace, disrupting operations and potentially compromising sensitive business information. Attack methods leveraged phishing or credential theft to hijack seller accounts, highlighting security risks associated with third-party vendor ecosystems in online retail environments.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early April 2017, Amazon faced a cybersecurity incident impacting its third-party seller ecosystem. Hackers targeted these external merchants operating on Amazon’s marketplace platform, exploiting vulnerabilities to gain unauthorized access to seller accounts. The attackers focused on compromising seller credentials or account controls, though the exact intrusion methods remain unspecified in available reports. This incident highlighted the growing risks associated with Amazon’s expanding network of independent sellers, who relied on the platform’s infrastructure to manage inventory, process payments, and fulfill orders. The breach disrupted normal business operations for affected sellers, though the full scope of compromised accounts and duration of unauthorized access were not publicly quantified.

Amazon acknowledged the hacking campaign against its third-party sellers but did not disclose specific technical details about the attack vectors or forensic findings. The company’s response included standard account security measures such as password resets and enhanced monitoring for suspicious activity, though no customized remediation steps or system-wide security upgrades were detailed in initial reports. Financial losses primarily affected individual sellers through disrupted sales and potential fraudulent transactions, rather than impacting Amazon’s corporate finances directly. The incident underscored persistent security challenges in e-commerce platforms where external business operators integrate with core marketplace systems. No data theft involving customer information was confirmed in relation to this specific event.

Sources

Sources available to members: 1 source.

CSIDB