This Amazon scam could trick even the most savvy shoppers

Amazon
(Image credit: Amazon)

Cybercriminal groups are launching new scams designed to capitalize on shopping fever ahead of Black Friday and the holiday season, researchers have warned.

In a blog post, researchers from security firm Avanan described one such campaign, first launched last month, in which fraudsters spoofed Amazon order notification emails.

The objective of these imitation emails is to get the victim to place a call to a fake customer service number, at which point the scammers attempt to get the person to expose their credit card information.

“When you call the number, at first no one will answer. After a few hours, a call back will occur,” explained Avanan. “The person on the other line will say that, in order to cancel the invoice, they will need a credit card number and CVV.”

Amazon invoice scam

According to Avanan, the scammers are able to circumvent email security filters by including legitimate links in the body, which direct to the genuine Amazon website. While some phishing scams use fake landing pages to harvest credentials, in this case the links offer a more reliable path into inboxes, as well as leaving the victim with a false sense of security.

In addition to the theft of payment details, meanwhile, the scam doubles as a form of phone number harvesting, laying the foundations for future voicemail and text-based attacks.

“Once [attackers] obtain the phone number, they can carry out a series of attacks, whether through text messages or phone calls,” wrote the researchers. “Just one successful attack can lead to dozens of others.”

And this is just one relatively simple example. As a result of the global chip shortage and supply chain disruptions, shoppers are expected to make holiday season purchases earlier than ever this year, which will likely spawn a series of scams that aim to capitalize on the level of demand.

To shield against these kinds of attacks, shoppers are advised to interrogate the sender’s email address and the body of the message for anomalies that might betray a scam. Further, it’s sensible to avoid calling unfamiliar numbers unless they are also found on the retailer’s website, and avoid downloading unsolicited attachments that may contain malware.

To protect your devices from attack, meanwhile, check out our list of the best antivirus services, best endpoint protection software and best ransomware protection.

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Concept art representing cybersecurity principles
Cybercriminals cashing in on holiday sales rush
A man falling into a mobile phone screen.
Safer Internet Day: how to avoid online scams and stay safe online
Paper craft illustration of a suspicious email that contains a snake
How to spot a phishing email
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Someone checking their credit card details online.
Hackers use CAPTCHA scam in PDF files on Webflow CDN to get past security systems
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business