Wednesday, September 16, 2026

New Phishing Attack Targets Amazon Prime Users to Steal Login Credentials

A new phishing campaign targeting Amazon Prime users has been identified, aiming to steal login credentials and other sensitive information, including payment details and personal verification data.

The attack, analyzed by the Cofense Phishing Defense Center (PDC), uses a carefully crafted email impersonating official Amazon communications to deceive recipients.

Sophisticated Email Spoofing Campaign Exploits Amazon Branding

The phishing emails appear to notify users of an expired or invalid payment method, urging them to update their information.

The sender’s address is spoofed to resemble a legitimate Amazon notification, while the email body mimics authentic branding with the Amazon logo, corporate footer, and familiar language.

Amazon Prime
Email Body

The subject line creates a sense of urgency, compelling recipients to act quickly. However, closer inspection reveals that the sender’s domain is unrelated to Amazon, a key red flag.

When users click on the provided link, they are redirected to a fraudulent webpage that imitates Amazon’s security verification process.

Instead of leading to Amazon’s official site, the URL redirects users to platforms like Google Docs or other suspicious domains.

This fake security notice is designed to lower suspicion and encourage victims to proceed further.

Fake Amazon Security Alert

Phishing Scheme Seeks Payment and Personal Data for Fraudulent Use

Once on the phishing site, users are prompted to enter their Amazon login credentials on a counterfeit login page.

Following this step, they are directed to additional pages requesting personal information such as their mother’s maiden name, date of birth, phone number, billing address, and even credit card details.

Amazon Prime
Personal Information Phishing Page

According to Cofense Report, these details are commonly used in identity verification processes and can be exploited for unauthorized access or financial fraud.

The phishing scheme also seeks payment card information, including cardholder name, card number, expiration date, and CVV code.

If compromised, these details could enable attackers to conduct unauthorized transactions or sell the data on the dark web.

What sets this campaign apart is its multi-layered approach: it not only harvests login credentials but also requests supplementary data that could aid attackers in bypassing additional security measures.

The fraudulent pages often contain minor grammatical errors, another indicator of their illegitimacy.

To protect against such attacks, users are advised to verify the sender’s email address and avoid clicking on links within unsolicited emails.

Instead, they should log in directly through Amazon’s official website or app.

Enabling multi-factor authentication (MFA) adds another layer of security against credential theft.

Credential Update Page

The rise in phishing attacks targeting popular platforms like Amazon underscores the importance of vigilance in online interactions.

Users should remain cautious when handling sensitive information and report suspicious emails or websites directly to Amazon.

Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response, and Threat Hunting - Register Here

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information

CenterPoint Energy has confirmed that an unauthorized third party...

Parallels Desktop Flaw Lets Unprivileged Mac Users Gain Root Access

A critical local privilege escalation vulnerability in Parallels Desktop...

12 Best Kubernetes Security Tools Compared (2026): Features & Pricing

Quick Answer: Kubernetes security quotes hinge on the node-vs-cluster-vs-developer...

12 Best Container Security Tools Compared (2026): Features & Pricing

Quick Answer: Container security has the deepest free floor...

PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users

A newly identified phishing operation tracked as PAPERMILL is...

Apache Superset SQL Injection Flaw Gets Public PoC Exploit

A public proof-of-concept exploit has been released for CVE-2026-23980,...

China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites

China-aligned threat actors are concealing the PeckBirdy command-and-control framework...

Related Articles

Recent News