THREAT BRIEFING · 13.08.2026 DEENFRES

Practice & Implementation

Amazon Warns of Renewed Fraud Risks

By Tobias Massow · August 17, 2023 · 6 min read

Phishing remains one of the most prominent dangers in the cyber realm, especially when it involves impersonating well-known companies and reaching a large number of potential victims. While cybercriminals have frequently abused Amazon’s name for their scams in the past, Amazon recently sent an email to its users to inform them about possible new fraud attempts related to its own platform.

According to Dr. Martin J. Krämer, Security Awareness Advocate at KnowBe4, the fraudsters pose as Amazon in their emails and make users believe there are issues with their Prime membership or that new membership fees need to be paid. Customers are then asked to pay or cancel their membership. This way, the fraudsters try to get users to provide their payment or bank account details. Additionally, the fraudsters send SMS messages, emails, and make calls claiming that the user’s account has been locked or deleted, and they urge the user to click on a fraudulent link or verbally provide information to “verify their account.”

In its own email, Amazon informs its users that it would never request confidential data over the phone or on any site other than the official Amazon website. Additionally, some helpful tips were included on how users can recognize this type of fraud and keep their account secure:

Possible fraud attempts via SMS, email, or phone call related to Amazon can and should be reported directly to the company. The user is also the last line of defense. Therefore, participation in security awareness training is always recommended and reduces the risk of falling for fraud attempts.

Phishing as a Mass Phenomenon: Why Big Brands Are in the Crosshairs

Cybercriminals deliberately exploit the fame and trustworthiness of global brands like Amazon to maximize the success rate of their attacks. The larger the user base, the more potential victims can be reached with a single campaign. The psychological effect is enormous: An email from a seemingly known sender is much less likely to be questioned than a message from an unknown source. Companies should therefore not only rely on technical protective measures but also strengthen the human factor – through regular security awareness training that includes realistic phishing simulations.

Overview of Protective Measures for Consumers and Companies

In addition to the behavioral rules recommended by Amazon, there are other effective protective measures: Multi-Factor Authentication (MFA) should be activated for all online accounts. Password managers help to use a unique, strong password for each service. Email clients with integrated phishing filters provide a first technical line of defense. Companies should additionally configure DMARC, SPF, and DKIM for their email domains to make it more difficult to spoof their brand.

TL;DR

Key Facts

Attack Vector: Fake emails, SMS messages, and phone calls in the name of Amazon

Most Common Baits: Alleged problems with Prime membership or impending account suspension

Identifying Feature: Legitimate Amazon URLs always contain the domain amazon.de or amazon.com

Protective Measure: Activate Multi-Factor Authentication and do not disclose payment data over the phone

Fact: The average dwell time of an attacker in the network is 10 days, according to Mandiant.

Fact: The average detection time of a phishing campaign is 16 hours, according to Mandiant.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

How do I recognize a fake Amazon email?

Check the sender address carefully – legitimate Amazon emails only come from domains that end in amazon.de or amazon.com. Watch out for urgent appeals and requests to disclose personal data. Amazon never asks for payment data via email or phone.

What should I do if I receive a suspicious message?

Do not click on any links in the message. Instead, open the Amazon app or website directly and check your account status there. Report the suspicious message via the official Amazon reporting function.

Why do fraudsters use Amazon as a disguise?

Amazon has hundreds of millions of customers worldwide. The likelihood that recipients of a phishing email actually have an Amazon account is therefore very high. This significantly increases the success rate of the attacks.

Does two-factor authentication protect against phishing?

Multi-Factor Authentication makes it much more difficult to misuse stolen login credentials, as attackers need a second factor in addition to the password. However, it does not protect against users entering their data on a fake site.

How can companies protect their employees from such attacks?

Security awareness training with realistic phishing simulations is the most effective protection. Additionally, email systems should be equipped with modern anti-phishing filters and DMARC policies configured.

Further Reading on the Network

Cloud-based email security solutions on cloudmagazin.com

Phishing prevention in everyday business on mybusinessfuture.com

Security awareness as a leadership topic on digital-chiefs.de

Related Articles

Header Image Source: Pexels

Further reading

Practice & Implementation · July 31, 2026

Anthropic: Claude Breached Three Companies

Anthropic's Claude compromised three organizations in cyber evaluations. Harness misconfiguration, PyPI malware, and CISO checklist insights.

Practice & Implementation · July 29, 2026

Codex Security: Open Client Feeds OpenAI

Codex Security CLI: open-source client code under Apache 2.0, scanning backend in limited beta against OpenAI infrastructure.

A magazine by Evernine Media GmbH