Scammers pose as Amazon support to steal your account
好的,我现在需要帮用户总结一篇文章,控制在100字以内。首先,我得仔细阅读文章内容,抓住主要信息。 文章主要讲的是网络犯罪分子利用“广泛撒网”的策略,伪装成亚马逊这样的大品牌进行诈骗。他们发送虚假的产品召回邮件,诱导用户点击链接,进而窃取账户信息。用户需要注意不要点击链接,而是直接通过亚马逊官网检查消息,并采取一些安全措施如启用双重验证、报告诈骗等。 接下来,我需要将这些要点浓缩成一段简洁的描述。要确保涵盖骗子的方法、目标品牌、诈骗手段以及防范建议。同时,语言要简洁明了,避免使用复杂的术语。 最后,检查字数是否在100字以内,并确保信息准确无误。 </think> 网络犯罪分子伪装成亚马逊等大品牌,利用虚假产品召回邮件进行诈骗。这些邮件诱导用户点击链接并泄露账户信息。用户应避免点击链接,直接通过亚马逊官网检查消息,并启用双重验证和报告诈骗以保护账户安全。 2026-4-9 13:5:44 Author: www.malwarebytes.com(查看原文) 阅读量:13 收藏

Cybercriminals using the so-called “spray and pray” tactic love to impersonate well-known brands. Especially ones with huge customer bases.

Amazon reportedly has around 310 million active customers, so they certainly qualify as a brand worth impersonating. And it shows in the sheer volume of scams that use its name.

Amazon account take-over (ATO) scams were numerous during the holiday season, and they haven’t gone away. The scammers have ported the “product recall due to safety concerns” text message scam over to email.

The fake product recall message is one of scammers’ most popular lures, and we’ve reported on in the past.

Example of Amazon refund text
Example of Amazon refund text

The hook in a recent email campaign is the same: something you bought does not meet safety or quality standards.

The UK’s Mirror reported on emails that read:

“Dear Customer, we are writing to inform you of a product recall affecting an item from your March 2026 order due to a design defect that may pose a potential safety risk. We apologise for any inconvenience this may cause and appreciate your prompt attention to this important safety matter. Thank you for your continued trust in Amazon.”

Following the link takes the target to a fake login page designed to steal their Amazon username and password.

These messages are intentionally vague about the nature of the product or the exact issue they’re being recalled for. The less specific they are, the more likely it is that someone will think, “This could be me.” If you’ve recently ordered something from Amazon, you’re more likely to fall for it.

How to avoid falling for Amazon phishing scams

  • If you get a recall notice, don’t click any links. Instead, go straight to Amazon using the app or by typing the website into your browser. Then check the Message Centre in your account. Legitimate messages from Amazon will appear there.
  • If you’ve fallen for this, change your Amazon password straight away and anywhere else you use that password. Monitor your bank statements for any unfamiliar charges, and contact your bank immediately if you see anything suspicious.
  • While you’re in your Amazon account settings, turn on two-step verification.
  • Report the scam to Amazon itself, whether you’ve fallen for it or not.
  • In the US, forward scam texts to 7726 (SPAM) or use the “Report Junk” option. For emails, report them as spam in your inbox.
  • Install web protection that can warn you of phishing sites, card skimmers, and other nasties that could lead to your data being taken.

Scammers sometimes use information they’ve found online to personalize their scam messages. Check what information is already out there about you using our free Digital Footprint scanner and then remove or change as much of it as you can.

Pro tip: Malwarebytes Scam Guard can help you spot scams and guide you through what to do next.


We don’t just report on scams—we help detect them

Cybersecurity risks should never spread beyond a headline. If something looks dodgy to you, check if it’s a scam using Malwarebytes Scam Guard. Submit a screenshot, paste suspicious content, or share a link, text or phone number, and we’ll tell you if it’s a scam or legit. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.


文章来源: https://www.malwarebytes.com/blog/news/2026/04/scammers-pose-as-amazon-support-to-steal-your-account
如有侵权请联系:admin#unsafe.sh