Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesAmazon confirmed that employee work contact information was involved in a security incident at an unnamed property-management vendor that served Amazon and other customers. The company said its own and AWS systems remained secure, and that the vendor did not have access to sensitive information such as Social Security numbers or financial information. Amazon did not say how many employees were affected.
The much larger figure circulating in November 2024—more than 2.8 million lines—was a claim by the person using the alias Nam3L3ss, not an Amazon-confirmed employee count. The incident was linked to the 2023 exploitation of MOVEit software; the reported data publication claim came later, in November 2024.
What Amazon confirmed about the incident
Amazon spokesperson Adam Montgomery told TechCrunch on November 11, 2024, that employee information was involved in a security event at a third-party property-management vendor. The vendor’s name was not disclosed in that report. Amazon said the vendor served several customers, including Amazon, and that the event was at the vendor—not in Amazon’s or AWS’s systems.
Montgomery described the information involved as employee work contact information: work email addresses, desk phone numbers, and building locations. Amazon said the vendor did not have access to sensitive information such as Social Security numbers or financial information, and that the vendor had fixed the vulnerability.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
What the hacker claimed—and what the numbers mean
Nam3L3ss claimed to have published data from 25 organizations and described the material as more than 2.8 million lines. Those are the actor’s claims as reported by TechCrunch in November 2024. They are not an Amazon-reported count, and “lines” should not be read as a count of employees, unique people, or verified Amazon records.
| Statement | Who said it | What it establishes |
|---|---|---|
| Employee work emails, desk phone numbers, and building locations were involved | Amazon, through spokesperson Adam Montgomery | Amazon’s description of the information involved; no employee count was disclosed. |
| More than 2.8 million lines | Nam3L3ss, as reported by TechCrunch | An attributed claim about the material, not a verified number of Amazon employees or records. |
| Data from 25 organizations | Nam3L3ss, as reported by TechCrunch | An attributed claim about organizations; it does not establish that each organization confirmed exposure. |
Were other big technology companies affected?
The actor claimed that data from 25 organizations was published, but the cited November 2024 TechCrunch report did not establish that every named organization was affected. TechCrunch said it had contacted the other organizations listed by the actor and had not received further responses by publication. The report does not settle whether those organizations later confirmed exposure or what information any of them may have had involved.
Rank #2
How the 2023 MOVEit breach relates to the 2024 report
The MOVEit exploitation and the later publication claim are separate points on the timeline. Progress Software said in its fiscal 2023 Form 10-K that it received a customer support call about unusual activity on May 28, 2023, discovered a zero-day vulnerability on May 30, and released a patch for supported MOVEit Transfer and MOVEit Cloud versions on May 31.
CISA and partner agencies described exploitation of CVE-2023-34362, a SQL injection flaw used to install the LEMURLOOT web shell on MOVEit Transfer web applications and steal files. The November 2024 report concerned a hacker’s claim to publish data associated with that earlier campaign; it did not describe a newly discovered 2024 MOVEit exploit.
Rank #3
Progress also disclosed that its on-premise MOVEit Transfer software did not provide the company ongoing telemetry about customer usage, file transfers, or patch status. As a result, Progress could not centrally determine each customer’s exposure from its own telemetry.
How this compares with other MOVEit impact figures
Other organizations reported their own MOVEit impacts in 2023, but those disclosures are not evidence of Amazon’s affected employee count. Maximus, Inc. described 8 to 11 million individuals as a preliminary estimate of people whose personal information was in affected files in a July 26, 2023 filing, and said the estimate could change. Apple reported at least 2,300 organizations and more than 65 million individuals as MOVEit impact figures as of October 2023, based on sources it cited. These figures refer to different organizations, measures, and dates.
Rank #4
What employees should take from Amazon’s statement
Amazon’s reported exposure was limited to work contact details, and it said the vendor lacked access to Social Security numbers and financial information. The available statement does not give a count of affected employees or establish that every listed contact detail was accurate. Employees who want to know whether their own information was involved should rely on direct communications from Amazon or their employer rather than infer individual exposure from the hacker’s line count.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




