The Price of a Deal: How Scammers are Hijacking Amazon Prime Day

KnowBe4 Threat Lab | Oct 6, 2026

Lead Analysts: Lucy Gee and Emily Hanlon

As millions of shoppers prepare their wishlists and await discounts for Amazon’s Prime Big Deal Days starting October 6, cybercriminals are gearing up for their own payday.

In the weeks leading up to major shopping events, Amazon impersonation campaigns reach an annual peak. Scammers capitalize on high transaction volumes, artificial urgency and deal-fever to deceive buyers by using fake order confirmations, delivery failures, account suspension warnings and fraudulent reward offers.mf

Their end goal? Account takeover, credit card harvesting and malware deployment. Recognizing these deceptive traps before clicking "Confirm" is the difference between snagging a bargain and handing over your credentials.

Prime Day Threat Landscape from KnowBe4 Defend’s Numbers

  • From the end of August into September, there was a 188% increase in Amazon Impersonations in the run up to Prime day

  • Over 700 new Amazon-themed domains registered in just a three-week window preceding a Prime Day run-up

  • The largest campaigns used themes on account security alerts ("Suspicious Activity Detected") or order delivery updates, averaging 86 phishing attacks per campaign

  • 75% of attacks were polymorphic, where the attacker modified display names, subject headers, or sender domains per campaign to evade detection

  • 64% of attacks used technical obfuscation techniques: utilizing hidden characters or zero-width spaces to bypass traditional filters.

Global Attack Themes Observed in KnowBe4 Defend:

   
Amazon prime billing/account renewal/ account login detected: 31%
Free gift or reward: 29%
Delivery notice: 25%
Limited time offer: 15%

How Are Different Regions Targeted?

While Prime Day phishing campaigns are broadly opportunistic and sprayed at scale rather than individually targeted, threat actors vary their playbooks by region. Rather than altering who they target, attackers tailor how they lure victims: aligning their messages with localized consumer anxieties, regional shopping habits and language expectations to maximize conversion rates.

🇺🇸 United States — Account and Billing Focus

Primary Lure: Billing Issue / Account Renewal (76% of U.S. Amazon attacks)

Top Subject Lines:

  • Your Prime benefits are on hold due to a billing issue on <date>
  • Your Prime membership is renewing on <date, time>
  • Your Prime membership is on hold. #<code>

Tactic: Exploits fear of service interruption to force immediate credential/payment re-entry.

🇯🇵 Japan — Account Verification and Technical Evasion Traps

Primary Lure: Account Verification and Event Access Security

Top Subject Lines:

  • 【重要】Amazonアカウントの緊急確認が必要です (Important: Urgent Amazon account verification required)
  • Amazonプライム会員情報の更新・確認のお願い (Request to update and verify your Amazon Prime membership details)
  • 【注意】お客様のアカウントで異常なログインが検知されました (Notice: Suspicious login activity detected on your account)

Tactic: Uses high-urgency security notices from newly created look-alike domains, ordering users to verify their account details to ensure uninterrupted access to upcoming deals.

🇮🇹 Italy — Expiration and Delivery Traps

Primary Lure: Card Expiration / Failed Delivery (87% of Italian Amazon attacks)

Top Subject Lines:

  • Amazon Notice: Your registered card is about to expire
  • Amazon Notice: Your card payment has failed
  • IMPORTANT: Your delivery was not successful

Tactic: Plays on urgency around failed transactions and lost packages during high-volume periods.

🇫🇷 France — Local Limited Time Offers

Primary Lure: Time-Sensitive Deals and Exclusive Access

Key Finding: While ~75% of global Amazon attacks are in English or Japanese, French targets received over 90% of these attacks natively translated into French.

Top Subject Lines:

  • Votre accès exclusif se termine bientôt (Your exclusive access ends soon)
  • Dernière chance : profitez de votre offre avant son expiration (Last chance: take advantage of your offer before it expires)

🇬🇧 United Kingdom — Delivery and Parcel Traps

Primary Lure: Fake Delivery Notifications and Address Verification

Key Finding: UK targets are heavily bombarded with urgent logistical lures designed to capitalise on high shopping volumes and fear of missed packages during peak sales.

Top Subject Lines:

  • [Arrives today] We are delivering your order
  • [Important] Please confirm your delivery address before today’s delivery
  • Notice about a parcel being returned because you were not home

Tactic: Weaponizes urgency and logistical anxiety, tricking users into clicking tracking links that redirect to fake address verification or credential-harvesting forms.

Free gift and reward lures are less targeted, and predominantly leveraged in EMEA and APAC markets, where attackers rely less on account suspension fear and more on high-value prize lures.

Typical subject line lures:

  • “You are Qualified For an Amazon Gift bonus.”
  • “<first name>, Claim Your Amazon Bonus”
  • “Re: Gift Alert: Free Amazon <insert product> from Amazon | ID:<code>”

Global Attack Breakdown

  • Target: Widespread, non-industry specific. Attacks focus on individual consumers and employees acting in personal capacities.

  • Payload Type: >95% Link-based leading to credential harvesting pages or fake payment gateways.

To bypass skepticism, attackers replicate official Amazon email templates. By using genuine brand assets, including logos, action buttons and official footer disclaimers, and combining them with spoofed display names, they create a convincing attack.

On the backend, it's a different story. Over 65% of observed campaigns rely on polymorphic techniques, swapping subject line characters, randomizing order numbers and continuously rotating sender domains to slip past standard secure email gateways. Attackers also embedded invisible zero-width characters within the attack: causing traditional security vendors to struggle to decipher the gibberish from the attack, ultimately allowing the message to land in users’ inboxes.

What Are Some Amazon Prime Day Scam Examples?

Example 1: High-Volume Credential Harvesting campaign

Figure-1-Amazon-Prime-Day-Scams-Blog-Image

This widespread credential-harvesting campaign leverages pre-Prime Day urgency to trap users. Posing as urgent security alerts, the emails cite "suspicious account activity" and warn recipients to update their credentials immediately or risk missing out on upcoming deals. Within the email body are embedded links, ready to push the user directly to phishing pages built to steal login and payment data.

To bypass domain reputation filters and hit mailboxes at scale, threat actors launched the campaign across a vast array of free webmail providers and burner accounts. By constantly rotating sending domains, the attackers dilute security detection signals, using high-volume distribution and event-driven panic to maximize success.

Example 2: AI-Generated Personalization & Image-Based Attack Figure-2-Amazon-Prime-Day-Scams-Blog-Image

This campaign targeted mailboxes across the UK and U.S. Leveraging generative AI, threat actors crafted and deployed persuasively personalized lures offering generous, tailored deals in seconds. The operation relies on polymorphic evasion tactics: dynamically altering the subject line to slip past pattern-matching filters.

While the email claims to come from Amazon, the true sender address points back to infrastructure associated with a multi-cryptocurrency digital wallet application. Threat actors are likely abusing or spoofing subdomains on this legitimate service to hijack its domain reputation and coast past security gates. To further evade detection, the email hides its malicious payload behind a clickable embedded image rather than standard text hyperlinks. Once clicked, victims are redirected to a fraudulent site impersonating familiar news channels, which serves as a trusted front to host credential-harvesting phishing attacks.

Example 3: Japanese Text Obfuscation

Figure-3-Amazon-Prime-Day-Scams-Blog-Image

This pre-event campaign primarily targeted Japanese users to harvest credentials under the guise of account verification. Disguised as an official notice from Amazon, the email instructs recipients to verify their account details to ensure uninterrupted access to upcoming deals.

To bypass automated security scanners, attackers employed white-on-white text obfuscation, embedding invisible, random characters within the HTML body to disrupt machine detection while remaining completely invisible to human targets. Additionally, the message originated from a newly created domain engineered to bypass legacy domain-age checks, with its verification button redirecting users directly to an external credential-harvesting page.

How to Stay Safe This Prime Day

Understanding how cybercriminals construct these traps is half the battle. Here is how to keep your credentials safe when shopping this Prime season

  • Verify the Sender and URL: Check the actual email address, not just the display name. Legitimate Amazon communications always originate from @amazon.com or official country subdomains.

  • Navigate Directly: Never click "Update Payment" or "Claim Reward" links inside an email. Open your browser or the official Amazon app or website directly to inspect account alerts.
  • Watch for Pressure Tactics: Countdown timers, warnings of imminent account closure and claims of failed delivery are designed to bypass critical thinking.

  • Inspect the Link Destination: Hover over links before clicking to reveal the destination domain. Look for hyphenated variations (e.g., amazon-support-login.com vs. amazon.com).

  • Enforce MFA & Passkeys: Implement multi-factor authentication (MFA) across personal and corporate accounts to ensure that even if cybercriminals harvest login credentials, they cannot gain unauthorized access without the secondary verification factor.

See KnowBe4 Cloud Email Security in Action

Request a personalized demo today to see how KnowBe4's Cloud Email Security products will enhance your email security.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.