E-mails from Amazon regarding user's e-mails being disclosed
sellercentral.amazon.com
sellercentral.amazon.com
The email, in full:
—— Hello,
We’re contacting you to let you know that our website inadvertently disclosed your email address due to a technical error. The issue has been fixed. This is not a result of anything you have done, and there is no need for you to change your password or take any other action.
Sincerely, Customer Service http://Amazon.com ——
No template; not addressed to me; no details. Capitalized domain name.
The email is checking the “we have to notify” box and not an inch more.
The interesting thing to me is that some people seem to have received the email from no-reply@amazon.com. I received it from order-update@amazon.co.uk
Perhaps that's just due to being on different TLD but seems interesting to me that I should receive one from the order-update@amazon.co.uk address.
no-reply@amazon.co.uk exists and would seem like the better email to send out such a notice from. I'm curious why they'd use the order update email system.
Maybe the name and email was revealed as part of a mis-configured ordering process? Perhaps revealed to sellers and not a 'breach' in the traditional sense?
You are not their primary concern or interest. Market share and margins are. You are 100% replaceable within seconds on their platform.
Edit: Asked around, so far, none of my friends and family who use the UK site exclusively have gotten an email.
Could also be phishing gone wrong? Because what better time to do it than close to Black Friday?
> Amazon's UK press office acknowledged that the email was genuine, saying only: "We have fixed the issue and informed customers who may have been impacted."
and
> [...] this is not a breach in the sense of a hack while maintaining that the snafu is an inadvertent technical error and that they emailed customers from an abundance of caution.
Looks like they've ballsed up the incidence response quite badly, and seems to be Amazon's fault.
[0] https://www.theregister.co.uk/2018/11/21/amazon_data_breach/