Amazon's registries for weddings, birthdays, new babies, and more are publicly visible by default, a sensitive personal data one-stop shop for identity thieves
a byproduct of very weak default privacy settings on their parenting registry products. Good find by the @theintercept: https://theintercept.com/... @theintercept : Imagine if a budding identity thief had a free, user-friendly, publicly searchable database that contained the name, location, date of birth, and mother's maiden name of millions of people. Enter @amazon registries, writes Nikita Mazurov. https://theintercept.com/... Marsha Collier / @marshacollier : Amazon's One-Stop Shop for Identity Thieves 👉 Public Amazon registries could reveal enough information to steal the identity of someone who hasn't been born yet #tech #privacy https://theintercept.com/... https://twitter.com/...
Context & Ripple Effects
The Intercept's reporting lands on top of a long arc of Amazon privacy lapses: internal docs detailed in Wired showed careless handling of retail customer data, and in 2019 a third-party firm left 752,000+ birth certificate applications exposed on AWS with neither Amazon nor the collector moving to take it down. What's different here is that no breach is required — the sensitive data (name, location, date of birth, mother's maiden name) is public by design, via default settings on registry products users likely never thought to lock down.
It also slots into a broader pattern the corpus has tracked: [[a:924385|static personal facts like SSNs and birthdates remain master keys to government data systems]], and companies complying with GDPR and CCPA have shown insecure practices around identity verification. Registries concentrate exactly the fields knowledge-based verification relies on, in one searchable place.
First-order effects
- Millions of registry users — new parents, couples, birthday registrants — have core identity-theft inputs (full name, address, DOB, mother's maiden name) exposed to anyone who searches, with no action required from an attacker.
- Amazon faces immediate pressure to flip the default: the exposure stems from product settings choices, not a hack, so the fix is a settings change rather than an incident response.
Second-order effects
- The report hands privacy regulators and plaintiffs a clean template — default-public settings for sensitive data — the same compliance-gap territory the NYT flagged in GDPR and CCPA data-access practices, raising the cost of Amazon's 'careless with retail data' pattern.
- Any identity-verification flow that leans on mother's maiden name or DOB (government portals, financial services) loses more ground as those fields become trivially searchable, pushing those systems toward biometric or document-based checks — the direction Amazon itself is already going with Amazon One palm scanning for payments and ID verification.
Third-order effects
- If default-visibility keeps surfacing as the root cause across platforms, the structural fix regulators gravitate toward is privacy-by-default mandates — opt-in sharing rather than opt-out — shifting the burden of data exposure from users to product design.
- Knowledge-based identity verification, built on facts that keep leaking through exactly these channels, is on a path to obsolescence; the long-term beneficiaries are whoever owns biometric and document verification rails.
The trend: As platforms leak the static personal facts that identity systems rely on, default-privacy settings and the shift from knowledge-based to biometric verification are becoming the battleground for consumer trust.