Skip to content
 

As Online Sales Soar During Pandemic, Cybercrooks Pose as Amazon

Bad actors claim that your account has been misused and try to grab your cash and sensitive data

 A portion of the sign advertising Amazon Go

David Ryder / Stringer / Getty Images

En español | A fake phone number for Amazon.com almost tripped up an 81-year-old man from West Virginia. A retired educator, he says his wife placed an order for two iPhone cases on Amazon.com, but when she tried to log back into her account, she couldn't. She couldn't reset her password, either.

A relative went online for an Amazon customer-service phone number and when the retiree called it, he was told that a $4,800 television had been charged to the account, which reportedly had been hacked by more than 40 people in Mexico. To rectify the situation, the retiree was told, he could use one of two preferred companies to prevent more computer intrusions and get back the information that the hackers may have obtained.

Many red flags

The victim, who spoke to AARP and asked that his name not be used, chose one of the suggested companies. But when the phony Amazon rep transferred him to the computer company, he heard a voice that sounded identical to that of the original fraudster.

"I asked, ‘What government agency has oversight over you?’ “ the retiree says. “He never answered my questions to my satisfaction."

Still, the man chose a $999 “lifetime” option, in hopes of resolving the hacking situation for good. The fraudster, from a distance, even arranged for an authentic-looking receipt to be printed on the retiree's printer. 

Calls AARP's free fraud helpline

Soon, more red flags popped up. The swindler said payment could be made only by money order. That prompted the victim to call AARP's toll-free Fraud Watch Network Helpline, 877-908-3360. As instructed, he refused to pay one red cent to the con artist.

He also went to his bank to have his account monitored, called his credit card issuer so that purchases on his card could be monitored and took his computer to a bona fide expert for a cleanup.


Save 25% when you join AARP and enroll in Automatic Renewal for first year. Get instant access to discounts, programs, services, and the information you need to benefit every area of your life.


Woman loses $13,300 to scammers

Here are more recent Amazon-related frauds reported to AARP's fraud helpline.

  • A woman received an email purporting to be from Amazon and responded by revealing her Social Security and credit card numbers and giving a stranger remote access to her computer and iPad.
  • A second woman received a phishing email July 21 from “Amazon Security Team.” The email, featuring Amazon's logo, said a charge of $732 had been processed on her account. She had not made the charge, and the alert came from an email address ending in “.ng,” signifying Nigeria. The email said her account was locked but could be unlocked — and the money refunded — if she sent her address and complete credit or debit card number. She declined and reported the incident to the FBI's Internet Complaint Center.
  • A third woman received an alert on Messenger that said her Amazon account had been compromised and she needed to call a certain phone number. Her caller ID displayed Apple Mobile Support. The caller told her she had to buy gift cards to claim codes to reestablish her account. She bought gift cards worth $13,300 and revealed their numbers.

Regrettably, that money is probably gone for good, says Amy Nofziger, AARP director of Fraud Victim Support, who oversees the helpline. She says the dismay and distraction people feel amid blaring headlines about the coronavirus are what scammers count on as they lie, cheat and steal. The crooks are playing on people's anxiety while hiding behind the credibility of Amazon's brand, she adds.

Amazon won't detail scope of the problem

Amazon, an online behemoth with $281 billion in sales in 2019, has long been an attractive target for fraudsters. The Seattle-based company, however, does not disclose the scope of the problem or whether fraud reports have increased since the pandemic-triggered boom in online buying.

AARP's helpline reports a jump in complaints about frauds tied to online sales in April, May and June, compared with earlier in the year, Nofziger says. Here's her advice:

  • Beware of phony websites and phone numbers for Amazon. The actual toll-free customer-service number is 888- 280-4331.
  • Don't necessarily trust phone numbers that turn up during an internet search. For your credit card, use a customer-service number on the back of the card or on a statement.
  • Hang up on unsolicited phone calls. Do not click suspicious hyperlinks.
  • Don't always believe what appears on caller ID, since calls can be spoofed. Never give a stranger remote access to your computer, since the person can “wreak havoc and steal your personal information,” Nofziger warns.

Masquerading as customer service

At Censys, an Ann Arbor, Michigan–based internet security firm, IT manager Mike Toole says con artists who pose as Amazon Prime customer support or Amazon security team members often use phishing emails or spoofed caller ID numbers.

screenshot of a scam email purported to be from amazon

Redacted by AARP

Fraudsters try scare consumers into giving up personal information with fake security alerts, like this one purporting to be from Amazon, says Theresa Payton of Fortalice, a cybersecurity firm. Nefarious crooks may utilize “burner emails” for a short time, then abandon them, and even the savviest of digital shoppers have been victims of such fraud, she says.

Theresa Payton, CEO of Fortalice Solutions, a cybersecurity consultancy in Charlotte, North Carolina, suggests that consumers consider using one credit card for all online purchases, to be better able to spot potential fraud. Meantime, they should consider setting up alerts for all card transactions, she says.

Advice from the real Amazon

Amazon, for its part, advises consumers to watch for scams by looking for misspelled words in unsolicited emails, requests to update payment information and prompts to install software on their computer.

Amazon never sends unsolicited emails asking for sensitive information like your Social Security or tax-ID number or bank account number.

Use this link to file an online report to Amazon about spoofing and suspicious emails.

Here's more from Amazon on fraud.

Looking back, the 81-year-old retired educator has learned important lessons about how unscrupulous and persuasive cyberthieves can be. “It all sounded so plausible,” he says of their web of deceit. “I've always thought, I'm too smart to be fooled. But they make you think something bad is going to happen if you don't go along, no matter how many red flags go up."

AARP’s Fraud Watch Network can help you spot and avoid scams. Sign up for free Watchdog Alerts, review our scam-tracking map, or call our toll-free fraud helpline at 877-908-3360 if you or a loved one suspect you’ve been a victim.

Join the Discussion

0 | Add Yours

Please leave your comment below.

You must be logged in to leave a comment.