Amazon will pay a $2.25 million civil penalty to settle US Federal Trade Commission allegations that it knowingly denied identity-theft victims the transaction records that federal law says they are entitled to receive. For any business that holds records fraudsters exploit, the case is a pointed warning that a little-used consumer-protection provision has teeth.

The Department of Justice filed the complaint in the US District Court for the District of Columbia following an FTC referral, and a proposed consent order is now before the court. Amazon, represented by Sidley Austin, has not contested the settlement terms.

What the FTC found

According to the regulator, Amazon had no written procedure at all for responding to requests under Section 609(e) of the Fair Credit Reporting Act until early 2025 — and it put one in place only after discovering the FTC had opened an investigation, despite earlier direct outreach from FTC staff urging it to review its compliance. Customer-service representatives repeatedly cited privacy and security concerns to withhold records, justifications the statute does not recognise. In one case the FTC documented, a victim was made to guess the name of the person who had opened the fraudulent account more than thirty times before giving up. The Bureau of Consumer Protection’s director described the experience as a “Kafkaesque ordeal.”

The obligation the case turns on

Section 609(e), enacted in 2003 under the Fair and Accurate Credit Transactions Act, gives identity-theft victims the right to obtain business records relating to transactions made in their name — records they need to prove the fraud to banks, police and credit bureaus. The provision does not permit a company to demand that the victim first identify the fraudster. That is precisely the barrier the FTC said Amazon’s representatives erected.

Why the penalty is notable

This is only the second time the FTC has brought an enforcement action under Section 609(e). The sole prior case, against Kohl’s Department Stores in 2020, resulted in a $220,000 penalty. Amazon’s penalty is more than ten times larger, a gap the FTC tied to the knowing nature of the conduct rather than mere negligence. The message for compliance teams is that dormant statutory obligations can be enforced, and that the size of the penalty may turn on whether a company ignored a duty it plainly understood.

What Amazon must now do

Beyond the penalty, the settlement requires Amazon to put written compliance policies in place, train staff on the statutory obligation, notify consumers of their rights under the FCRA, and go back and contact customers who submitted records requests since April 2024 without receiving a response. The remedial obligations, as much as the fine, define what “getting it right” looks like.

What it means for businesses that hold records

The case is a template for how regulators approach records-access failures. For in-house counsel, the practical lessons are concrete: maintain a documented procedure for handling identity-theft records requests; train frontline staff that privacy and security are not lawful grounds to refuse a valid request; and never condition disclosure on a victim naming their attacker. Retailers, banks, telecoms and any business whose accounts can be opened fraudulently sit within the reach of Section 609(e) — and, on the strength of this settlement, within the FTC’s enforcement appetite.