Amazon impersonation attacks jumped 188% between late August and September, according to KnowBe4's Threat Lab, and Prime Big Deal Days, the 48-hour sale event running October 6 and 7 across 22 countries, ends today. I run AliasFleet: one email alias per account, so a leaked or phished address names its source. This week is the worst possible moment to be reading your inbox the way you normally do. Half the mail you are waiting for is real order confirmations, and the fakes are now polished enough to sit beside them without anyone noticing.
The numbers
Two research teams, Check Point Research and KnowBe4's Threat Lab, published data ahead of the event. The shape matches:
| Signal | Figure | Source |
|---|---|---|
| Amazon impersonation attacks, late Aug to Sep | Up 188% | KnowBe4 Threat Lab, via IT Security Guru |
| New Amazon/Prime Day-related domains, Sep 2026 | 1,284 | Check Point Research |
| Same figure, September 2025 | 937 | Check Point Research |
| Growth, July to September 2026 | 42% (905 to 1,284) | Check Point Research |
| Share of Sep domains rated malicious or suspicious | 6.5%, about 1 in 16 | Check Point Research |
| New Amazon-themed domains in one three-week window | 700+ | KnowBe4 Threat Lab, via IT Security Guru |
The attack is infrastructure-first. Attackers registered the domains months before the sale, built fake login pages and storefronts, then waited for the event to give the lures credibility. Check Point lists examples like amazonprime-support[.]com, primevideoamazon[.]com, and amazonprimeusa[.]com, plus fake Amazon login pages aimed at users in Japan, Vietnam, and the UK, full fake storefronts in Germany and Japan, and even a site targeting Amazon's delivery partner programme in India. Ten of the eleven AmazonShopping/ShoppingOnAmazon domains were malicious. All five AmazonGlobal domains were malicious. Not opportunistic spam. A campaign calendar.
What the fake emails look like
KnowBe4 broke the lures into four themes:
| Lure theme | Share of attacks |
|---|---|
| Prime billing, account renewal, "login detected" | 31% |
| Free gift or reward | 29% |
| Delivery notice | 25% |
| Limited-time offer | 15% |
Billing scares are the single biggest category, and the TrendLife team at Trend Micro documented exactly how one works. An email arrived under the display name "Prime Assist" warning that Amazon could not charge the payment method for $14.99 of Prime and that benefits were on hold. It reused Amazon's real Prime logo and layout. The "Update Now" button led to a page built to look like Amazon's real account page, designed to capture the login, personal details, and card number in a single flow rather than one piece at a time. One stolen session, one working account, one saved card.
How do attackers get past email filters?
Three quarters of the Amazon-themed attacks KnowBe4 analysed were polymorphic, constantly rotating display names, subject lines, or sending domains so pattern-matching never lands a hit. Almost two thirds used technical obfuscation such as zero-width spaces and hidden characters. More than 95% relied on links leading to fake payment gateways or credential-harvesting pages, with cloned logos, action buttons, and footer disclaimers. In Japan, attackers hid white-on-white invisible characters in the HTML to confuse scanners while the recipient saw a clean message, sent from freshly registered domains built to defeat legacy domain-age checks.
That is the part most advice skips. These emails do not arrive looking like phishing. They arrive looking like everything else in your inbox, because the people sending them study exactly what your inbox contains.
The AI problem
Both research teams flag the same change: generative AI has erased the old warning signs. The classic tells, spelling mistakes, awkward phrasing, obvious machine translation, are gone. The French campaigns read like a native speaker wrote them, and the UK and US lures were personalised by the same machinery. One campaign hid the malicious link behind a clickable image instead of text. Then it bounced victims through a fake news site: a trusted-looking front for credential theft.
"If an email warns that your account is locked, your payment failed, or that you've won a free prize, don't use the links in that message. Navigate directly to the official Amazon app or website to check your account status." (Lucy Gee, Lead Threat Analyst at KnowBe4, via IT Security Guru)
One honest caveat: I did not read KnowBe4's underlying report directly. The 188% figure, the lure breakdown, and the evasion numbers reach me through IT Security Guru's write-up. I am running them because KnowBe4's Threat Lab is a serious source, and Check Point's data independently corroborates the shape of the campaign. But you deserve to know the chain.
Why this week in particular
Sale-week phishing works for a simple reason: you are already expecting the emails. Order confirmations, dispatch notices, delivery updates. If you have ever wondered why your inbox is a firehose in the first place, this week is that answer amplified. One more message in the stream is easy to miss, and the fakes arrive timed to that rhythm.
Germany got a special version this year. On October 1, the country's Federal Court of Justice ruled that the clause Amazon used to raise Prime prices in 2022 was invalid (case III ZR 205/25), and Amazon emailed German members about a temporary cut back to the old rate, €69 a year or €7.99 a month. A real email about money, reaching millions of people, is a perfect template for a fake one that promises a refund in exchange for bank details. Notebookcheck's Steffen Zahn points out that email already led Germany's Amazon-impersonation reports last year at 46%, and that Amazon gets 360,000 support contacts a year from people asking whether a message is real. That last number is the one I keep thinking about. That is nearly a thousand people a day who cannot tell whether a message is real.
Amazon's genuine Prime price email only informs. It says the lower price applies from the next payment, that the change happens automatically, and that members need to do nothing. A message promising a refund for past years and asking for bank or card details is not what Amazon sent. German members who want the money back can register for the class action at Germany's Federal Office of Justice themselves, looking up that page rather than following a link. (Both details from Notebookcheck's account of the German email.)
If you get one of these emails
Work from the assumption that any Amazon email with a link is hostile until you check it. Here is the order that works.
- Go direct. Open the Amazon app or type the address into your browser yourself, never through a link in the message. This one habit defeats the entire campaign.
- Check the Message Center. Under Your Account, it holds every email Amazon has sent you. If the email is not listed there, it did not come from Amazon.
- Forward suspicious mail to verify@amazon.com. Amazon says anyone can use it, customer or not, and you get a reply saying whether it is genuine.
- Hover before you click. Look for hyphenated lookalikes such as amazon-support-login.com.
- Turn on passkeys or two-step verification now. Amazon supports passkeys under Your Account and Login and security, and a passkey is tied to Amazon's real web address, so it will not work on a lookalike site. A phished password alone then opens nothing.
- Watch your statements. If you entered card details on a fake page, call your bank or card issuer immediately.
- Check whether your address is already in a known breach at Have I Been Pwned. Phishing is often the second half of a leak you never heard about.
- Report confirmed scams. In the US, the FTC takes fraud reports at ReportFraud.ftc.gov, feeding cases and investigations.
Clicked already? The breach-response guide walks through account recovery in order.
What one alias per service buys you here
Phishing relies on one assumption: that you cannot tell a real email from a fake one by looking at the address it was sent to, because you use the same address everywhere. Flip that assumption and the whole campaign breaks.
If the address Amazon holds for you exists only for Amazon, then a "delivery failed" notice landing on the alias you created for your streaming service is fake by definition. No inspection, no hovering over links, no Message Center check. The address itself is the verdict. And when the fake mail keeps coming, you pause the alias: the phishing channel dies while your real inbox stays untouched. That is the same leak-tracing mechanism that names a breached company the moment its alias shows up in a dump, doing its job against phishing instead of leaks.
You cannot fix your inbox during a 48-hour sale. But you can stop giving every service the same address and hoping inspection saves you. This is what an email alias is. The set-up guide takes about two minutes. And the address Amazon holds next is up to you.
What is still unclear
No victim numbers exist anywhere in the reporting so far; everything published is attack-side volume, domain registrations and detection counts. Amazon has not publicly commented on these specific campaigns in the sources I read. And while the 48-hour window is the hook, the TrendLife data shows the scam URLs peak in the two weeks before the event, which means the wave is already in inboxes, not waiting for tomorrow.
Top comments (0)