An identity-theft victim’s hardest task is often simply proving what was stolen. The records that show which account was opened, what was ordered, and where it shipped sit inside the retailer’s systems, and getting them released can decide whether a police report goes anywhere. A federal order against Amazon has now made clear that handing those records over is not a courtesy the company can withhold, but a legal duty it must meet on a tight clock.
What the federal order requires
The Department of Justice, acting on a referral from the Federal Trade Commission, obtained a stipulated court order requiring Amazon to pay a $2.25 million civil penalty and permanently barring it from violating the identity-theft records provisions of the Fair Credit Reporting Act. As the Justice Department announced, the company must now supply qualifying records to victims, and to law enforcement acting on their behalf, free of charge and within 30 days once identity and the claim of fraud are verified. Amazon is also required to post a notice on its website explaining exactly how a victim can request those records.
The civil penalty is a punishment paid to the government, not a fund that consumers can file to collect. The value to ordinary account holders lies in the injunction: the enforceable promise that the records will flow the next time someone discovers a fraudulent account opened in their name. That distinction matters, because the practical benefit is a right to information, not a check in the mail.
Free retirement updates: One number can cost or save hundreds a month in retirement. The free Retirement Shield newsletter surfaces the ones worth knowing. Sign up free.
The right the law already gave victims
The obligation itself is not new. Section 609(e) of the Fair Credit Reporting Act has long required a business to give an identity-theft victim the application and transaction records connected to accounts or purchases made in the victim’s name, at no cost, within 30 days of a verified request. What the case established is that a company cannot quietly ignore that duty. According to the FTC, regulators alleged Amazon knowingly failed to comply, and the order converts a statutory right that was easy to stonewall into one backed by the threat of further penalties.
For a retiree who discovers a stranger opened an account and ran up charges, that record is the raw material of every step that follows: the police report, the dispute with a bank or card issuer, and the fraud alert placed with the credit bureaus. Without the underlying transaction detail, a victim is left arguing about charges no one will describe.
How stonewalling looked in practice
Regulators described tactics that turned a legal right into a maze. In one account, a consumer seeking records tied to unauthorized charges was told the details could not be shared “for security reasons” unless the consumer could first guess the name attached to the fraudulent account, an impossible demand for a victim who never opened it. In other instances, the company declined to provide records even to law enforcement officers authorized to request them on a victim’s behalf. The order forecloses those excuses and sets identity verification, not a guessing game, as the only gate.
The pattern is a useful warning for anyone navigating a fraud claim with any large company. A demand that a victim supply information only the criminal would know is not a security measure; it is an obstacle, and it does not satisfy the law. Older consumers, who are disproportionately targeted by account-opening fraud, are the ones most likely to be worn down by it.
What the records actually contain
The documents Section 609(e) reaches are the ones that turn a victim’s word into evidence. They include the application used to open a fraudulent account and the transaction records tied to it: what was ordered, the dates, the amounts, the payment method attached, and where the goods were shipped. In an account-opening fraud, that shipping and device information can be the thread that identifies the person who exploited the victim’s name, and it is often the only proof a police department or a bank will act on. The retailer sits on all of it, which is why the law places the duty to hand it over on the business rather than on the victim to reconstruct.
The statute is not limited to any one company. It applies to any business holding the records of a transaction made in a victim’s name, from a bank or card issuer to a wireless carrier or an online merchant. The significance of the Amazon order is that it shows the duty is enforceable even against the largest of them, and it puts every business on notice that treating the request as optional invites the same scrutiny. A victim who meets resistance can now point to a concrete federal action as leverage when a company hesitates to release what the law already requires.
How to use the 30-day right
The practical takeaway is that the request should be made in writing, framed explicitly as a Section 609(e) request for records of identity theft, and paired with proof of identity and evidence of the fraud, such as a police report or an FTC identity-theft report. Documenting the date of the request starts the clock, and the 30-day limit gives a victim a concrete standard to hold the company to rather than an open-ended wait. Keeping copies of every message and every record received builds the file that banks, card issuers, and the credit bureaus will need.
The larger significance of the Amazon order is precedent. It signals that regulators will treat a refusal to release identity-theft records as a violation worth pursuing, which strengthens the hand of every victim who invokes the same right against any company holding the evidence of a fraud committed in their name.
This article was researched and drafted with the assistance of AI and reviewed by The Financial Wire editorial team.
More Financial Reading
- How many CDs can you park at 1 bank? FDIC rules you must know
- What really happens to your joint savings account when you die?



