Tech
Amazon Order Email Change Raises Phishing Concerns
Amazon is making its order confirmation emails harder to trust, giving scammers another reason to make fake ones look legitimate.
Instead of showing shoppers the exact product they purchased, Amazon’s newer order emails can display only broad categories, forcing customers to open the Amazon app or website to view the actual order details.
An Amazon spokesperson told The Verge that the company made the change to simplify communications and reduce the amount of customer information shared outside its own channels. The Verge further pointed out that the move is tied to the company’s effort to prevent external AI shopping agents from accessing detailed purchase data via email.
But the privacy move also removes details customers may use to distinguish legitimate order confirmations from generic phishing emails, making it more important to verify messages directly through Amazon.
The paradox Amazon is trying to deal with
Rather than resisting AI, Amazon is bringing it more deeply into its shopping business with Alexa for Shopping, which helps customers discover products, compare options, and make purchasing decisions.
The distinction is that while Amazon is willing to use customer shopping data to power its own services, it is less willing to make that same data easily available to third-party AI agents.
That matters because the inbox is becoming another place where AI services can interpret purchase information. Google’s Gemini features, for example, can use information from connected services such as Gmail, subject to the user’s settings and permissions.
For Amazon, that could mean greater competition over who controls the shopping experience and the customer data it produces.
And Amazon is not alone in having this concern. Retailers are increasingly seeking to leverage AI-generated shopping traffic while keeping customers, transactions, and the resulting data on their own platforms, because that information can strengthen personalization, loyalty, and other aspects of the business.
That is the paradox behind Amazon’s email change: retailers want AI to help sell their products, but they do not necessarily want AI companies to own the customer relationship or get unrestricted access to the data generated by those purchases.
Must-read security coverage
How the change could complicate phishing checks
At the same time, Amazon’s privacy move creates a security problem Amazon may not have intended.
Amazon’s newer messages can replace a product’s name and image with generic descriptions such as “Beauty item” or “Hardware item,” leaving customers with far less information in the email itself.
Specific order details can give customers a quick way to compare an email with something they recently purchased. If an Amazon email says exactly what was purchased, a customer can immediately make a mental comparison with their recent orders. If the message simply says that a generic household or personal-care item was ordered, there is much less to verify without opening Amazon separately.
The change could therefore make generic order-confirmation phishing emails harder to dismiss immediately. Amazon is already a frequent target for brand impersonation, although there is no evidence cited here that attackers are exploiting this particular email change.
Staying safe: what can be done
Scammers typically send broad, untargeted campaigns and may not know whether a recipient is genuinely expecting an Amazon delivery, so an unexpected order message should be treated with suspicion even if it looks convincing.
Users who want to investigate an email can also inspect its full headers, which can expose information about where the message actually came from.
It is also worth hovering over links before clicking them to see where they lead, while avoiding any messages that ask for passwords, payment information, or other sensitive details.
Finally, enabling multi-factor authentication on an Amazon account can limit the damage if a phishing attempt does succeed in stealing a password. And if an email is clearly fraudulent, users can report it to Amazon rather than simply deleting it, helping the company identify spoofed messages targeting its customers.
>
Tech
Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants
Private equity giant Apollo Global Management has confirmed a data breach in which hackers stole reams of personal information from the company’s cloud systems.
The breach comes a month after security researchers sounded the alarm on a new hacking campaign targeting financial and private equity giants.
The financial giant confirmed the incident in a letter filed with California’s attorney general. Apollo’s human resources chief Matthew Breitfelder said that hackers used a social engineering attack to gain access to the company’s cloud environment between July 6 and July 10. The hackers took names, birth dates, contact information, including home addresses, and Social Security numbers.
The letter does not specifically say who had their personal information stolen, such as Apollo employees or individuals at companies it owns. Apollo is one of the world’s largest private equity firms with $938 billion in assets under its management.
When reached by TechCrunch, Apollo spokesperson Giovanna Falbo did not immediately provide comment or answer questions about the incident, including whether the company paid the hackers a ransom.
Apollo has around 5,000 employees as of February 2026, according to the company’s public regulatory filings.
The now-confirmed hack comes weeks after security researchers at Google warned that hackers were targeting private equity companies and financial giants as part of a widespread extortion campaign. Reuters reported that Apollo was one of the companies that hackers targeted, alongside Blackstone, Bridgewater, Bain Capital, and others, but that it was unclear if any of the companies had been successfully breached.
Google says the hackers, who go by various names — Falcon, Helix, Pink, and Redact — rely largely on social engineering attacks that involve calling employees and pretending to be IT helpdesks or support. The goal is to trick the employees into entering their passwords and multi-factor authentication codes in spoofed login portals, which allow the hackers to gain access to corporate networks.
After stealing data, the hackers then extort the companies into paying a ransom or threaten to publish the data on their leak site.
Some of the attacks netted the hackers ransoms as much as $750,000, according to Google.
Until 2025, TechCrunch was a subsidiary of Yahoo, an advertising tech company owned by Apollo.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Senator asks US government watchdog to review how feds use hacking tools
Democratic senator Ron Wyden is asking the U.S. government to review how federal law enforcement agencies use hacking tools and spyware against Americans, citing a lack of transparency into how often or for what reasons these tools are deployed.
On Friday, Wyden sent a letter to the U.S. Government Accountability Office (GAO), which audits the federal government, requesting it to launch a comprehensive inquiry into how the FBI, the Drug Enforcement Administration, ICE’s Homeland Security Investigations, and the Secret Service employ hacking and spyware in their investigations.
In the letter, shared with TechCrunch, Wyden wrote that while these tools have been used for more than two decades, “there exists little public information regarding its scope, frequency, or operational safeguards.”
Wyden said that, unlike wiretaps and pen registers, which allow authorities to see when a call is placed and to whom, the government “does not publish annual reports for hacking operations.” For that reason, Wyden requested GAO to publish an unclassified report with its findings and recommendations.
Federal agents have used hacking tools and spyware several times over the years, but as Wyden noted in the letter, the U.S. Department of Justice and the FBI “have repeatedly ignored congressional requests for greater transparency across multiple administrations.”
Wyden is making several requests to the GAO:
- Investigate whether agents abused hacking tools and spyware for unauthorized or personal purposes, and to check what technical and oversight measures are in place to control and prevent misuse;
- Review how agencies “acquire, store, and secure” these tools to avoid dangerous leaks, as well as whether they submit them to a program designed to determine if the U.S. government should report security flaws to help tech companies fix them;
- And, assess how the feds inform courts when requesting warrants for the use of these tools, and whether they disclose the risk of affecting unknown or innocent targets.
To highlight the risks around the acquisition of hacking tools, Wyden specifically mentioned the case of Peter Williams, a former executive at the defense contractor L3Harris, who stole and sold advanced hacking tools to a Russian broker. The tools ended up being used by Russian spies against Ukraine, and Chinese cybercriminals against cryptocurrency owners.
The earliest documented case of the FBI using spyware goes back to 1999. During an investigation for illegal gambling and loan sharking, federal agents discovered that Philadelphia mobster Nicodemo S. Scarfo used the program Pretty Good Privacy (PGP) to encrypt a file on his computer, which they believed contained key evidence.
To access it, the FBI installed a rudimentary malware designed to record the keystrokes on Scarfo’s computer, which allowed them to decrypt the file.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Tesla, Uber, and Waymo all get the OK to operate thousands of robotaxis in Nevada
Nevada, get ready for the robotaxis.
The Nevada Transportation Authority unanimously approved three permits Thursday that will allow Tesla, Uber, and Waymo to operate commercial robotaxi services in Clark County, home to Las Vegas. Together, these permits would deploy up to 8,000 robotaxis across the county over the next 12 months.
Tesla’s permit allows it to deploy up to 5,000 robotaxis, while Waymo is allowed operate up to 1,000 autonomous vehicles over the next year. Uber was also approved for 1,000 robotaxis, which it will operate through partnerships with Hyundai subsidiary Motional and Zoox. Zoox already holds an autonomous vehicle network company permit that allows it to operate 100 robotaxis.
Whether these companies will be able to launch that many robotaxis is an unanswered question. Testimony from Tesla representatives and the other companies suggests the answer is no.
“The 5,000 has always been a ceiling for us,” said Eric Early, Tesla’s Cybercab chief engineer, during the meeting. “I don’t think we’ll be in a position by this time next year to deploy 5,000 vehicles, and it’s not [because of] the technology. … I think we would be extremely happy and satisfied if we could get ourselves up to 2,500, maybe maybe a bit higher than that in the next year.”
Even if these three companies roll out only half of those totals, Clark County — and Las Vegas specifically — is shaping up to be a major robotaxi battleground, with Tesla, Uber (via its autonomous vehicle partners Motional and Zoox), and Waymo all competing for the same riders.
That kind of fast, large-scale robotaxi deployment is poised to change the city — and specifically its workforce. Depending on who you ask, these companies will either deliver a whole new category of jobs designed to maintain, charge, and clean these vehicles or will wipe out an entire category of workers: human taxi and gig drivers.
Representatives from the Livery Operators Association and local taxi companies opposed the permits, arguing the approvals move too far, too fast.
“These applications raise two grave concerns,” said Kimberly Maxson-Rushton, a lawyer representing the Livery Operators Association, at the hearing. “One deals with the oversaturation of the commercial transportation industry as a whole in Nevada,” she said. “And the second one deals with the overcrowding of the roadways, and specifically the Golden Triangle.”
(The Golden Triangle, an area between the airport and Las Vegas Boulevard and the surrounding area, is where most of the AV testing has occurred to date. Motional is also testing in the downtown area as well as a shopping district known as Towne Square.)
Uber has tried to position itself as the Goldilocks option in this fight, advocating for a hybrid approach in which ride-hailing networks are made up of humans and robotaxis. The company has even lobbied for a system that would require robotaxis to operate on a ride-hailing network that also uses human drivers, a stance that puts it at odds with Waymo and doubles as a hedge against its own autonomous ambitions falling short of Tesla’s or Waymo’s.
Uber made a similar pitch during the NTA meeting, noting that a hybrid approach would allow cities to gradually integrate vehicles to meet peak demand rather than flooding the market all at once.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
-
movies3 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Fashion9 years agoYour comprehensive guide to this fall’s biggest trends
-
Fashion9 years agoA photo diary of the nightlife scene from LA To Ibiza
