Amazon chasing employees for acting as rogue 'data brokers'
Employees are selling services and internal information for between $80 and $2,000 to businesses seeking advantage


Amazon is investigating several incidents in which employees in the US and China allegedly stole internal data to sell on to third parties.
People who are familiar with the investigation told the Wall Street Journal (WSJ) that internal sales data, reviewers' emails addresses and offering to delete negative reviews are among those offered by 'brokers' for between $80 and $2,000.
Sellers would be enticed by such offers to gain an advantage over rivals, and game the automated ranking system. Contact information for reviews, for example, would allow sellers to approach users to ask them to change negative reviews.
"We have strict policies and a Code of Business Conduct & Ethics in place for our employees," an Amazon spokesperson told IT Pro.
"We implement sophisticated systems to restrict and audit access to information. We hold our employees to a high ethical standard and anyone in violation of our Code faces discipline, including termination and potential legal and criminal penalties.
"In addition, we have zero tolerance for abuse of our systems and if we find bad actors who have engaged in this behavior, we will take swift action against them, including terminating their selling accounts, deleting reviews, withholding funds, and taking legal action.
"We are conducting a thorough investigation of these claims."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Eric Broussard, Amazon's vice president for international marketplaces opened an internal probe in May, the WSJ report continued, after being tipped off about such activity in China.
The company has also shaken up the top roles in China in an effort to clamp down on any illicit activity that may have been overseen from a senior level.
Product rankings on Amazon are determined by a combination of factors - with reviews being one of the most crucial. WSJ says the rate for deleting one review amounts to $300 in China - with brokers usually demanding a five-review minimum. Sales data, meanwhile, would cost closer to $80.
Amazon recently reached the $1 billion dollar valuation milestone, becoming the second company to achieve this following Apple in August. But the firm has sustained criticism, in the US especially, for paying its employees relatively low wages, and for "prison-like" working conditions in its warehouses.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
PyPI attack: Targeting of repository 'shows no sign of stopping'
News Greater collaboration and understanding of attackers’ tactics is key to mitigating open source security threats
By Ross Kelly Published
-
Capita's handling of cyber attack shows companies still fail at breach reporting
Analysis Capita initially told customers there was “no evidence” of data having been compromised in the March cyber attack
By Ross Kelly Published
-
Malware being pushed to businesses by search engines remains a pervasive threat
News High-profile malvertising campaigns in recent months have surged
By Ross Kelly Published
-
There's only one way to avoid credential stuffing attacks
Opinion PayPal accounts were breached last year due to a credential stuffing attack, but can PayPal avoid taking responsibility?
By Davey Winder Published
-
Five things to consider before choosing an MFA solution
In-depth Because we all should move on from using “password” as a password
By Rene Millman Published
-
Cyber security suffers from a communication problem
News Negative language around ‘human failures’ is eroding trust between security teams and broader business functions - it has to stop
By Ross Kelly Published
-
Does LastPass really deserve a last chance?
Opinion After several disastrous security incidents and a communications breakdown, it’s time to leave LastPass for pastures new
By Ross Kelly Published
-
What is the spell-jacking vulnerability and how can your business avoid exposing data?
In-depth Spell-jacking vulnerabilities are threatening to unwittingly leak data to third parties, undermining any drive to protect privacy
By Davey Winder Published