In a critical alert sent earlier this month, Amazon has warned its 200 million customers worldwide about a sophisticated scam involving fake emails impersonating the company. The emails, which falsely claim that customers’ Amazon Prime subscriptions are set to auto-renew at an unexpected price, are part of a growing wave of phishing attacks targeting the e-commerce giant’s massive user base. Amazon’s alert, sent to all registered customers, underscores the increasing audacity of scammers exploiting the trust associated with the Amazon brand.
Malwarebytes, a cybersecurity firm that has identified and blocked phishing sites like amazons.digital, which mimic Amazon’s official platform: https://www.malwarebytes.com/blog/news/2025/07/amazon-warns-200-million-prime-customers-that-scammers-are-after-their-login-info
Amazon has reported a surge in scam attempts, including fake messages about Prime membership renewals, fraudulent refund offers, and phone calls claiming accounts have been compromised. These tactics prey on customers’ trust and urgency, aiming to extract sensitive information under the guise of resolving account issues
According to Amazon, the fraudulent emails often include personal details about recipients, likely obtained from external sources such as social media or the dark web, to appear legitimate. These emails typically contain a “cancel subscription” button that directs users to a fake Amazon login page. Once victims enter their credentials on these counterfeit sites, scammers gain access to their Amazon accounts, enabling unauthorized purchases or even access to other online accounts that share the same login details. In some cases, the fake websites also prompt users to input payment information and other sensitive data, which scammers can quickly exploit or sell. …..