Cybercriminals ramp up Amazon Prime Day scams with sophisticated attacks
As millions of shoppers prepare for Amazon's Prime Big Deal Days on October 6 and 7, cybercriminals are gearing up for a surge in scams. Two studies highlight a significant increase in fraudulent activity ahead of the event. KnowBe4’s Threat Lab reports an 188% rise in Amazon impersonation attacks between late August and September. Meanwhile, Check Point Research found a 42% jump in newly registered Amazon- and Prime Day-related domains, reaching 1,284 in September, 37% higher than the same month in 2025.
The primary goals of these attacks remain account takeover, payment card harvesting, and malware distribution. However, the sophistication and regional targeting of these scams have evolved. Check Point identified that 6.5% of Amazon-themed domains registered in September were malicious. KnowBe4 detected over 700 new Amazon-themed domains in just three weeks. Examples of malicious domains include amazonprime-support[.]com and primevideoamazon[.]com, with fake login pages targeting users in Japan, Vietnam, and the UK.
Attackers are employing advanced techniques to evade detection. Three-quarters of the Amazon-themed attacks analyzed by KnowBe4 were polymorphic, constantly changing display names and subject lines. Nearly two-thirds used technical obfuscation, and over 95% led to fake payment gateways or credential-harvesting pages. The largest campaigns averaged 86 phishing attacks each, with some using generative AI to create personalized deals and dynamic subject lines.
The lures vary by region, with delivery and parcel traps dominating in the UK, billing problems in the US, and delivery-based scams in Germany. France saw a high percentage of natively translated attacks, while Japan experienced high-urgency account verification notices. Financial services and consumer goods organizations also faced increased attacks, with an average of 2,650 attacks per organization per week in September, a 66% year-on-year increase.
Experts advise shoppers to pause before clicking on any links in emails, to access Amazon directly through the official app or website, and to be wary of pressure tactics such as countdown timers and suspension threats. Lucy Gee, Lead Threat Analyst at KnowBe4, emphasized the importance of not using links in suspicious messages and verifying account status through official channels.