Amazon fined $2.25M by FTC for refusing to aid identity theft victims

The FTC penalized Amazon $2.25 million under Section 609(e) for failing to release fraud records to identity theft victims within 30 days. Analysts warn India's regulatory gap under DPDPA 2023 and the IT Act could let similar practices persist, amid Amazon India's ongoing dark-pattern violations.

— Source publishedThu, 2 Jul, 2026, 17:41 IST·First seen Thu, 2 Jul, 2026, 17:41 IST·Source Medianama

What happened

FTC fined Amazon $2.25M for refusing identity theft victims' fraud records. Article flags India's regulatory gap (DPDPA/IT Act) and Amazon India's ongoing

Key facts

  • $2.25 million
  • Section 609(e)
  • 30 days
  • DPDPA 2023

Why this matters

Watch for tightening data-access and dark-pattern enforcement globally, as jurisdictional gaps like India's DPDPA 2023 shortfall may narrow and reshape compliance costs across e-commerce M&A targets.

What to watch

  • Additional FTC Section 609(e) actions against other retailers/platforms
  • Finalization of DPDPA 2023 implementation rules in India
  • New CCPA/India dark-pattern enforcement against Amazon India
  • Consumer group filings or class actions citing this precedent
  • Amazon public statement or policy update on victim data access
  • Amazon standardizes a 30-day fraud-record release process across US operations
  • Legal and compliance headcount increase to handle Section 609(e) requests
  • Amazon India monitors DPDPA rulemaking and pre-positions minimal-compliance posture
  • Peer platforms (Walmart, eBay, marketplaces) audit their own identity-theft data workflows