To ensure the best browsing experience, please enable JavaScript in your web browser. Without it, many website features are inaccessible.


24/7 Support     Login: Client | Partner
Total Tests:
485,773,462
737,046
130,956

Amazon To Pay $2.25M For Withholding Records From Fraud Victims

July 16, 2026

Read also: South Korea's LocknLock penalized for a data breach, FMF fined over FAN ID privacy violations, and more.

Views: 1.7k Read Time: 3 min.

Amazon To Pay $2.25M For Withholding Records From Fraud Victims

Amazon to pay $2.25M for withholding records from fraud victims

Amazon has agreed to pay a record $2.25 million civil penalty after the US Federal Trade Commission (FTC) said the company failed to provide identity theft victims with records of fraudulent transactions made in their names.

According to the FTC, Amazon customer service agents often denied requests for the records, saying they could not provide them because of ‘privacy’ or ‘security’ reasons. In other cases, the company took longer than the 30 days required by the Fair Credit Reporting Act (FCRA) to provide the information. Some customers were also told that Amazon could not access the records they needed. The regulator noted that Amazon had no policy to respond to Section 609(e) requests in place until early 2025, after it learned of the investigation.

The FTC's complaint also said Amazon refused to provide records to law enforcement agencies that were legally authorized to request them on behalf of identity theft victims. Some consumers even sent Amazon copies of the law and FTC guidance, but the company still did not provide the requested records.

As part of the settlement, Amazon must pay the $2.25 million fine and provide lawfully requested records to identity theft victims and authorized law enforcement agencies within 30 days. The company must also notify customers who requested records since April 2024 but never received them so they could obtain the information.

South Korea's LocknLock fined 530 million won for data breaches

South Korea's Personal Information Protection Commission (PIPC) has imposed a 530 million won penalty surcharge (around $337,000) and 5.4 million (~$35,000) won in fines on household goods maker LocknLock after personal data from around 1.3 million customers was leaked in a series of cyber-attacks. The administrative fines are imposed for failures to comply with the Personal Information Protection Act (PIPA).

The commission said hackers first breached the company's systems in April 2024 by exploiting a security flaw. The intruders later stole customer and employee information, including names, phone numbers, addresses, and some sensitive employee documents.

Authorities found LocknLock failed to install important security updates, used the same password for administrator accounts, and did not detect the breach until the company received a blackmail email from the hackers. In addition to fines, the company was also ordered to publish the penalty on its website.

The watchdog has also fined South Korean BPO Ubase 168 million won (about €105,000) and photo and video equipment distributor SUN-PHOTO 30 million won (~€18,750) after separate data breaches exposed the personal information of 1,852 and about 170,000 users, respectively.

In June, South Korea's largest online retailer Coupang was hit with a 624.7 billion won ($409 million) fine after a major data breach exposed the personal information of over 30 million customers last year. The penalty is the largest ever issued for a personal data breach, surpassing the previous record fine imposed on SK Telecom in October 2025.

Italy penalizes Character.AI maker over GDPR and child safety concerns

Italy’s data privacy watchdog has fined Character Technologies €158,000 for violating the European Union’s General Data Protection Regulation (GDPR). The fine must be paid within 30 days of notification and follows an investigation into how the AI platform handles users’ personal data and protects minors.

Character Technologies is an American company behind Character.AI, a chatbot service where users can chat with AI-generated characters, including virtual assistants and role-playing figures.

The Italian regulator said the company didn’t provide clear enough information about how users’ data is collected and used and that the service’s age verification system was not effective enough.

The Garante said Character Technologies must improve its age-checking system, strengthen measures that stop blocked minors from creating new accounts, and make minor users’ profiles private by default.

The regulator also found that the company failed to complete a required data protection impact assessment and did not appoint an EU representative within the required timeframe.

In April, the Italian watchdog fined Intesa Sanpaolo €31.8 million after an investigation found that an employee had accessed the personal banking information of over 3,500 customers more than 6,600 times without authorization. The DPA concluded that the bank’s internal controls failed to detect the unauthorized access.

ImmuniWeb Newsletter

Get Cybercrime Weekly, invitations to our events and webinars in your inbox:


Private and Confidential Your data will stay private and confidential

Ofcom fines adult content site £630,000 over online safety act breaches

The UK communications regulator Ofcom has fined the operator of an adult content platform £630,000 (~$840,000) for breaking rules under the Online Safety Act.

The penalty includes £600,000 for failing to put proper age checks in place to stop children from accessing pornographic content. An additional £30,000 (~$40,000) was issued after the company failed to provide information requested by Ofcom.

Following Ofcom’s action, Fapello[.]com blocked access to users in the UK.

Ofcom has also started a new investigation into Bit Hive, the operator of Eporner[.]com, to check whether its age verification system meets legal requirements. The regulator has also expanded its investigation into Kemono[.]cr over concerns that it may not have followed official information requests.

ImmuniWeb can help you to prevent data breaches and meet regulatory requirements.

Mexican football federation fined about €1.95M over FAN ID data privacy violations

The Mexican Football Federation (FMF) has been fined 42.8 million pesos (about €1.95 million) by Mexico's Secretariat of Anti-Corruption and Good Governance for violations of personal data protection laws related to the FAN ID digital identification system.

Authorities found that the FMF failed to clearly inform users that the facial photographs collected to create a FAN ID are considered sensitive personal data, preventing fans from fully understanding how their biometric information would be processed.

The Secretariat also determined that the federation did not obtain the express, written consent required by law for processing sensitive personal data. Instead, the federation used a website checkbox to authorize registration, which, the authority ruled, did not meet legal requirements.

The authority also found that the FMF did not meet its responsibilities under the law, as it failed to take the necessary steps to ensure personal data was handled properly.

What’s next:

Talk to an Expert