Skip to content
Back to Guavy Wire
Stocks

Cybercriminals ramp up Amazon Prime Day scams with sophisticated attacks

Instruments
AMZN
Share

As millions of shoppers prepare for Amazon's Prime Big Deal Days on October 6 and 7, cybercriminals are gearing up for a surge in scams. Two studies highlight a significant increase in fraudulent activity ahead of the event. KnowBe4’s Threat Lab reports an 188% rise in Amazon impersonation attacks between late August and September. Meanwhile, Check Point Research found a 42% jump in newly registered Amazon- and Prime Day-related domains, reaching 1,284 in September, 37% higher than the same month in 2025.

The primary goals of these attacks remain account takeover, payment card harvesting, and malware distribution. However, the sophistication and regional targeting of these scams have evolved. Check Point identified that 6.5% of Amazon-themed domains registered in September were malicious. KnowBe4 detected over 700 new Amazon-themed domains in just three weeks. Examples of malicious domains include amazonprime-support[.]com and primevideoamazon[.]com, with fake login pages targeting users in Japan, Vietnam, and the UK.

Attackers are employing advanced techniques to evade detection. Three-quarters of the Amazon-themed attacks analyzed by KnowBe4 were polymorphic, constantly changing display names and subject lines. Nearly two-thirds used technical obfuscation, and over 95% led to fake payment gateways or credential-harvesting pages. The largest campaigns averaged 86 phishing attacks each, with some using generative AI to create personalized deals and dynamic subject lines.

The lures vary by region, with delivery and parcel traps dominating in the UK, billing problems in the US, and delivery-based scams in Germany. France saw a high percentage of natively translated attacks, while Japan experienced high-urgency account verification notices. Financial services and consumer goods organizations also faced increased attacks, with an average of 2,650 attacks per organization per week in September, a 66% year-on-year increase.

Experts advise shoppers to pause before clicking on any links in emails, to access Amazon directly through the official app or website, and to be wary of pressure tactics such as countdown timers and suspension threats. Lucy Gee, Lead Threat Analyst at KnowBe4, emphasized the importance of not using links in suspicious messages and verifying account status through official channels.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc