Thu, Aug 13 Midday Edition English (UK)
Frontstory.co.uk Frontstory Breaking Wire
Updated 15:50 16 stories today
Blog Business Local Politics Tech World

Amazon Account Attackers Warning – Spot Scams and Protect Account

Jack James Davies Thompson • 2026-04-24 • Reviewed by Daniel Mercer

Amazon has issued urgent warnings to approximately 300 million active customers following a surge in account takeover attacks and impersonation scams, coinciding with alerts from the FBI about increased fraud targeting online shoppers during the holiday season.

The warnings, initially issued in November 2025, highlighted how cybercriminals are using increasingly sophisticated tactics to steal login credentials, personal data, and multi-factor authentication codes by posing as Amazon support through emails, texts, phone calls, and fake websites.

Was Amazon Hacked This Week?

Amazon has not experienced a security breach affecting its systems. However, scammers are successfully targeting individual customer accounts through sophisticated social engineering attacks, leading to what security researchers describe as a surge in account takeovers.

The distinction matters: Amazon’s infrastructure remains secure, but fraudsters are exploiting human behaviour and phishing techniques to gain access to customer accounts directly.

🔔
Alert Origin
Amazon and FBI warnings on account takeover attacks targeting online shoppers
👥
Affected Users
300 million active customers worldwide alerted to ongoing threats
🎯
Attack Methods
Phishing emails, text messages, phone calls, and fake websites impersonating Amazon
⚠️
Current Status
Attacks surging during the 2025 holiday shopping season, prompting urgent action

Key Facts About the Threat

Security researchers have identified several critical aspects of this ongoing threat:

  • Account takeover fraud increased by 21% from the first half of 2024 to the first half of 2025
  • The FBI received over 5,100 complaints since January 2025, with reported losses of $262 million
  • More than 19,000 new fake retail domains have been detected, with approximately 2,900 identified as malicious
  • Attackers reset passwords after gaining access, effectively locking victims out of their own accounts
  • Even accounts with multi-factor authentication enabled remain vulnerable in 65% of compromised cases, according to Proofpoint research
  • Scammers particularly exploit the distraction and urgency of the holiday shopping period
  • Fake Amazon support calls claiming suspicious account activity are among the most reported approaches

Quick Reference: Recent Warning Details

Detail Information Source
Initial Warning Date November 24, 2025 Amazon official communications
Customers Alerted 300 million active accounts Amazon customer communications
FBI Complaints (2025) Over 5,100 reports FBI Internet Crime Complaint Center
Reported Losses $262 million FBI data cited by Malwarebytes
Fraud Increase Rate 21% year-over-year TransUnion analysis
Fake Domains Detected 19,000+ (2,900 malicious) Security researchers

Are “Account Update” Emails from Amazon Legitimate?

Unsolicited emails claiming your Amazon account requires an urgent update are almost certainly scams. Amazon explicitly states it never requests payment information, login credentials, or verification codes through email or phone contacts.

How the Scams Work

Fraudsters send convincing messages that appear to come from Amazon, often using addresses that mimic official domains like “account-update-amazon.com” or similar variations. These emails typically create a sense of urgency, claiming your account has been compromised or requires immediate verification.

Recipients who click the embedded links are redirected to fake login pages designed to capture their credentials. Once submitted, attackers can access the real Amazon account, change passwords, and make purchases or access stored payment methods.

Verification tip

To confirm whether any Amazon communication is genuine, log directly into your Amazon account through the official app or website. Never use links in emails to access your account. Legitimate Amazon communications will appear in your account dashboard.

Red Flags to Watch For

  • Emails requesting personal data, passwords, or payment information
  • Messages claiming your account will be suspended without immediate action
  • Unsolicited attachments or links to “verify” your account
  • Requests for purchases to be made outside the Amazon platform
  • Calls claiming to be Amazon support and asking for verification codes
  • Messages creating artificial urgency around deliveries or account issues

Does Amazon Call Customers About Suspicious Activity?

Amazon does not make unsolicited phone calls to customers about account problems or suspicious activity. Any call claiming to represent Amazon support and requesting personal information, verification codes, or payment details is a scam.

The Support Call Scam Explained

Scammers operating these schemes often use spoofed phone numbers that appear local or legitimate. They employ high-pressure tactics, claiming unauthorized purchases have been made or that suspicious activity has been detected on the account.

The goal is to panic victims into providing multi-factor authentication codes, gift card numbers, or remote access to their devices. Amazon has confirmed it never requests payment by gift card, nor does it ask customers to install software or provide remote access for “security purposes.”

What Amazon Will and Will Not Do

Amazon’s official policy confirms that genuine support interactions occur only through verified channels within the Amazon app or website. The company handles account changes, refunds, and support requests exclusively through its own platforms.

  • Amazon will never ask for your password or verification codes by phone
  • Amazon will never request payment in the form of gift cards
  • Amazon does not make unsolicited calls about account issues
  • All legitimate support is initiated through your Amazon account dashboard
  • Amazon never demands immediate payment or threatens legal action by phone

How to Spot Amazon Phishing Emails and Scams in the UK

Phishing attempts targeting Amazon customers have become increasingly sophisticated. Security researchers at Malwarebytes identified multiple vectors being used to compromise accounts, including SEO-poisoned search results and look-alike domains designed to trick even cautious users.

Common Attack Methods

  • Fake delivery notices claiming package problems require immediate action
  • Messages about account problems that need urgent resolution
  • Third-party advertisements on social media leading to phishing sites
  • Search engine results poisoned to display fraudulent Amazon links
  • Browser push notifications claiming to be from Amazon but delivering malware
  • Fake law enforcement sites that scammers route victims to after initial contact

Protecting Your Account

Amazon and the FBI recommend several protective measures for all customers concerned about these attacks. The most effective step is enabling two-factor authentication, which adds a significant barrier even if your password becomes compromised.

Security recommendation

Bookmark Amazon’s login page directly in your browser and avoid using search engines to find Amazon when accessing your account. This simple habit prevents accidentally visiting spoofed sites designed to capture your credentials.

Always access your Amazon account by typing the address directly or using a bookmark you have previously saved. Never click links in emails claiming to lead to Amazon, regardless of how legitimate the message appears.

Browser Notification Abuse

Security researchers have identified a technique involving browser push notifications that displays convincing alerts from well-known brands. These notifications may claim your Amazon account has been compromised or that suspicious activity has been detected.

Clicking these notifications typically leads to phishing sites or installs malware. Review your browser’s notification permissions regularly and revoke access for any site you do not recognise or trust.

Timeline of Recent Amazon Security Warnings

The current wave of attacks did not emerge overnight. Security researchers and law enforcement have documented a significant escalation in account takeover fraud targeting online shoppers.

  1. January 2025 – FBI begins tracking complaints related to account takeover fraud, receiving reports from thousands of victims
  2. First Half 2025 – Account takeover fraud increases 21% compared to the same period in 2024, according to TransUnion data
  3. November 2025 – Amazon issues urgent warnings to 300 million active customers about impersonation attacks and account takeovers
  4. November 2025 – FBI issues parallel alerts warning of surging holiday shopping season fraud targeting major retailers
  5. Late 2025FortiGuard Labs data confirms rising impersonation domains mimicking major retail brands
  6. February 2026 – Continued news coverage highlights ongoing threat to online shoppers

What’s Confirmed and What Remains Uncertain

Understanding the boundaries between verified information and areas of uncertainty helps readers make informed decisions about their security posture.

What Is Confirmed What Remains Uncertain
Amazon has not experienced a data breach affecting its systems Exact number of UK customers affected by account takeovers
Scammers are targeting customers through sophisticated phishing campaigns Total financial losses specifically attributable to Amazon impersonation scams
Amazon issued warnings to 300 million customers in November 2025 Precise effectiveness of specific protection measures
Account takeover fraud increased significantly in 2025 Whether MFA requirements have reduced successful takeovers
The FBI documented over 5,100 complaints with $262 million in losses Long-term impact on customer trust in online shopping platforms

Understanding the Broader Context

The surge in Amazon impersonation scams reflects a wider trend in cybercrime targeting major brands during high-traffic shopping periods. Criminals deliberately increase activity during events like Black Friday and the holiday season when consumers are more distracted and more likely to click links without scrutiny.

No specific UK-focused reports have emerged, though researchers note that tactics used globally mirror established patterns in brand impersonation fraud affecting banks, streaming services, and other major retailers. UK Amazon customers should treat these warnings as directly applicable to their situation.

The financial stakes are substantial. FBI data showing $262 million in losses from just over 5,100 complaints suggests average losses of approximately $50,000 per incident, though individual amounts vary considerably. Security researchers warn that even security-conscious users can fall victim to increasingly convincing social engineering attacks.

Important note

If you receive an unsolicited call, email, or text claiming to be from Amazon requesting personal information or payment, treat it as potentially fraudulent. Amazon states it will never request such information through these channels. Report suspicious communications directly to Amazon.

What Customers Should Do Now

Customers who believe they may have responded to a scam should act immediately. Time is critical when accounts have been compromised, as attackers move quickly to change passwords and exploit payment methods.

Immediate Action Steps

  • Check your Amazon account activity for any unauthorised orders or changes
  • If you cannot access your account, contact Amazon through official channels immediately
  • Notify your bank about any potentially compromised payment methods
  • Enable two-factor authentication if not already active
  • Forward suspicious emails as attachments to reportascam@amazon.com
  • File a complaint with the FBI’s Internet Crime Complaint Center if you have been victimised

Reporting Resources

Amazon maintains a dedicated email address for reporting suspicious communications: reportascam@amazon.com. Forward suspicious emails as attachments to help Amazon identify and take action against scammers.

Customers who have lost money should contact their bank immediately and file reports with the appropriate authorities. The FBI’s Internet Crime Complaint Center accepts complaints from both domestic and international victims.

Summary and Next Steps

Amazon has not been hacked, but scammers are conducting sophisticated account takeover attacks against millions of customers. The urgency around these warnings reflects genuine risks during the holiday shopping period and beyond.

Customers can protect themselves by bookmarking Amazon’s official website, enabling two-factor authentication, and refusing to engage with unsolicited communications claiming to be from Amazon. When in doubt, access your account directly through the app or official website rather than clicking links in messages.

For those seeking more guidance on identifying parcel-related scams, the Princess Royal Parcel Hub – How to Spot and Avoid the Scam resource provides additional context on delivery fraud tactics.

Frequently Asked Questions

Is Amazon calling me about suspicious account activity?

Amazon does not make unsolicited phone calls to customers about account issues. Any such call is a scam and you should hang up immediately without providing any information.

Was Amazon actually hacked this week?

Amazon’s systems have not been breached. However, criminals are successfully targeting individual customer accounts through phishing and social engineering, which is why the warnings focus on account security rather than system integrity.

Is the “account update” email from Amazon legitimate?

Unsolicited emails requesting account updates are scams. Amazon states it never requests login credentials, payment information, or verification codes via email. Log in directly through the official app to check your account status.

How do I report an Amazon phishing email?

Forward suspicious emails as attachments to reportascam@amazon.com. Include the original message with headers intact to help Amazon’s security team investigate the source.

Can MFA protect my Amazon account?

Two-factor authentication significantly improves account security, though research indicates no protection method is foolproof. Enabling MFA makes accounts considerably more difficult to compromise and should be considered essential rather than optional.

What should I do if my Amazon account has been taken over?

Contact Amazon through official channels immediately, notify your bank about any affected payment methods, change passwords on other accounts using the same credentials, and file a report with the FBI’s Internet Crime Complaint Center.

Does Amazon ask for gift card payments?

Amazon never requests payment in the form of gift cards. Any request for gift card payment, whether by phone, email, or text, is definitively a scam. Treat such requests as confirmation of fraudulent intent.


Jack James Davies Thompson

About the author

Jack James Davies Thompson

Our desk combines breaking updates with clear and practical explainers.