
Amazon and the FBI are warning that account attackers are actively targeting holiday shoppers. Amazon alerted 300 million customers in November 2025 after the FBI documented $262 million in account takeover losses across 5,100 complaints. The attacks use fake delivery notices, impersonation calls, and look-alike websites to steal credentials.
Customers Warned: 300 Million · Recent Alerts: Nov 2025 – Feb 2026 · Attack Type: Account Takeover · Impersonation Scams: Amazon Support, FBI Noted · Holiday Surge: Targeted Shoppers
Quick snapshot
- Amazon alerted 300 million customers about account takeover fraud (Constant Contact)
- FBI reported 5,100 ATO complaints since November 2025 with $262 million in losses (Malwarebytes)
- FBI released account takeover PSA on November 25, 2025 (The Record)
- Whether Amazon’s own systems were directly compromised in these attacks
- Exact recovery success rates for victims who report through IC3.gov
- Specific breakdown of international versus US-based victims
- Nov 24, 2025: Amazon customer warning email
- Nov 25, 2025: FBI ATO public service announcement
- Feb 2026: Forbes covers new Amazon attack warnings
- Holiday shopping season intensifies attack pressure on consumers
- FBI expects complaint volumes to rise as more victims discover fraud
- Security experts anticipate new impersonation tactics emerging
The key facts table below summarizes the official figures from Amazon, the FBI, and cybersecurity researchers.
| Metric | Value | Source |
|---|---|---|
| Affected Users | 300 Million | Constant Contact |
| Alert Dates | Nov 2025, Feb 2026 | Malwarebytes |
| Top Scam Type | Impersonation | Fox News |
| Official Source | Amazon Customer Service | SRIFCU |
| FBI ATO Complaints | 5,100 since Jan 2025 | Malwarebytes |
| FBI ATO Losses YTD | $262 million | Fox News |
| ATO Growth Rate | 21% (H1 2024 to H1 2025) | Malwarebytes |
| Fake Retail Domains | 19,000+ (2,900 malicious) | Malwarebytes |
How will I know if my Amazon account has been hacked?
Amazon sends security notifications when someone attempts to sign in from an unfamiliar device or location. These alerts typically arrive via email and sometimes as push notifications through the Amazon app.
Unexpected login alerts
If you receive an email claiming to be from Amazon about a new sign-in that you don’t recognize, that’s your first warning sign. According to Malwarebytes (cybersecurity analysis firm), attackers often use fake delivery notices and account-issue messages to phish victims. Amazon will never ask you to confirm a password or verify account details through a link in an email.
Unfamiliar orders or devices
Check your order history regularly, especially during the holiday season. The FBI warned that criminals transfer funds via cryptocurrency to obscure trails after account takeover, making quick detection critical. Fox News reported that holiday complaint surges tie to November-December activity per IC3 data.
Amazon sends real-time notifications when unrecognized devices attempt to access your account. If you didn’t authorize the login, act immediately.
Does Amazon email you if someone is trying to access your account?
Yes, Amazon does email customers about access attempts — but scammers have gotten skilled at mimicking these official messages. The key is knowing what legitimate Amazon communications look like.
Official security alert emails
Genuine Amazon security emails come from addresses ending in @amazon.com. The company warned customers to watch for fake delivery notices, account-issue messages, and look-alike websites designed to steal login credentials. Constant Contact documented Amazon’s customer alert warning against third-party ads and unofficial channel requests during the holiday period.
Verify sender domain
According to APCU Blog (credit union security analysis), the FBI emphasized that no legitimate institution asks for passwords, PINs, or MFA codes via email. If an email requests this information, it’s a scam.
Scammers impersonate Amazon support to steal credentials. Always check the sender domain before clicking any link.
How do I check if someone is using my Amazon account?
Amazon provides built-in tools to review account activity and manage connected devices. Here’s how to audit your account for unauthorized access.
Login and activity log
Navigate to Amazon’s “Login and Activity” page under Account Settings. You’ll see a list of recent sign-ins, including device type, location, and timestamp. Any entry you don’t recognize warrants immediate attention. Malwarebytes reported that credential stuffing — using compromised passwords across multiple sites — is a primary attack vector for account takeover.
Manage devices section
Under “Your Devices” in Amazon’s settings, you can view all devices currently linked to your account. From here, you can sign out of any device you don’t recognize. The FBI recommends changing your password immediately after removing unfamiliar devices, and using a unique password you haven’t used elsewhere. Fox News coverage of the FBI alert included guidance on resetting all credentials using exposed passwords after an incident.
How to make sure your Amazon account is secure?
Prevention is the strongest defense against account takeover. Amazon and the FBI both recommend specific security measures that dramatically reduce your risk.
Enable 2FA
Two-factor authentication (2FA) adds a second verification step beyond your password. Even if attackers obtain your password through phishing, they cannot access your account without the additional code. Amazon offers 2FA through authenticator apps, SMS, or email. Malwarebytes noted that brand impersonation attacks surged specifically because customers lack adequate protection beyond passwords.
Change password
Choose a strong, unique password that you don’t use on any other website. FortiGuard Labs identified over 19,000 new domains imitating retail brands during the 2025 holiday season, with 2,900 classified as malicious. SRIFCU reported that Amazon’s urgent alert emphasized the holiday cyberattack risk specifically during the Black Friday period.
Enabling 2FA adds friction to login, but the protection it provides against credential stuffing attacks makes the tradeoff worthwhile for anyone who shops online.
What is the first thing you do when you get hacked?
If you discover unauthorized access to your Amazon account, immediate action limits the damage. The FBI and Amazon have published clear recovery steps.
Change credentials
Start by changing your Amazon password to a strong, new one. Simultaneously, check connected devices and sign out of everything. Achieve CU (credit union security guidance) emphasized that you should reset all credentials using any password that may have been exposed in the breach. Review your payment methods and shipping addresses for any changes you didn’t make.
Contact support
Report the compromise to Amazon Customer Service and monitor your account for suspicious orders. The FBI recommends filing a report at IC3.gov to document the crime and potentially assist with fund recovery. Fox News reported that FBI IC3 received over 5,100 ATO complaints since November 2025, with losses exceeding $262 million.
The implication: scammers prefer cryptocurrency transfers because they cannot be reversed, making immediate action critical after discovering account compromise.
How to protect yourself step by step
Security researchers and law enforcement have outlined concrete steps to reduce your exposure to account takeover fraud during the holiday season and beyond.
- Enable two-factor authentication through Amazon’s security settings using an authenticator app rather than SMS for stronger protection.
- Audit active sessions monthly by visiting Login and Activity settings and removing devices you no longer use.
- Use unique passwords that aren’t repeated across sites — a password manager helps generate and store these securely.
- Verify all communication by checking sender domains — Amazon emails come from @amazon.com, never from free email services.
- Report suspicious activity immediately through Amazon’s Report Suspicious Activity page and file a complaint at IC3.gov.
- Consider alias emails for shopping accounts to limit breach exposure if one retailer is compromised.
What this means: these steps directly counter the primary attack vectors — credential stuffing, phishing emails, and impersonation calls — identified by both Amazon and the FBI in their 2025 alerts.
Account takeover timeline: 2025-2026
Digital account takeover attacks have accelerated significantly. Here’s how the threat landscape has evolved over the past year.
- H1 2025: TransUnion reports 21% increase in digital ATO compared to H1 2024, and 141% increase since H1 2021.
- November 24, 2025: Amazon sends warning email to 300 million customers about holiday cyberattacks.
- November 25, 2025: FBI releases public service announcement on $262 million stolen in ATO fraud ahead of holidays.
- November 27, 2025: Malwarebytes reports impersonation attacks targeting holiday shoppers.
- Feb 18, 2026: Forbes covers new Amazon attack warnings affecting customers.
The pattern: attack volume and losses have climbed steadily, with holiday shopping periods creating peak exposure windows for consumers.
Confirmed facts vs. rumors
Not everything circulating online about Amazon account security is accurate. Here’s what sources confirm versus what remains uncertain.
Confirmed
- Scammers impersonate Amazon support via phone and email
- Amazon sends security notifications for unauthorized access attempts
- FBI reported $262 million in ATO losses in 2025
- FortiGuard Labs identified thousands of fake retail domains
- FBI highlighted four major holiday scams: non-delivery, non-payment, auction fraud, gift card fraud
Unconfirmed rumors
- Whether Amazon’s own servers were directly breached this week
- Exact count of victims who recovered funds after reporting
- Specific international scam operations dismantled by law enforcement
Shoppers should be suspicious about delivery or account issue messages.
— Amazon Customer Service Alert, November 2025
No legitimate financial institution will ever ask for your password, PIN, or MFA/OTP code.
— FBI via APCU Blog Security Analysis
Related reading: Virgin Email Sign In: Ireland & UK Login Guide · HM Revenue & Customs – Phone Numbers, Address and Login Guide
Frequently asked questions
Does Amazon call you about suspicious activity?
No. Amazon does not initiate outbound calls about suspicious account activity. If you receive an unsolicited phone call claiming to be Amazon support, it’s a scam. The FBI warned that scammers use secondary impersonators, sometimes posing as law enforcement, to pressure victims.
Was Amazon hacked this week?
No confirmed breach of Amazon’s internal systems has been reported. What Amazon and the FBI alerted customers to is a surge in account takeover attacks using impersonation tactics — not a direct compromise of Amazon’s infrastructure.
Did Amazon get hacked today?
There is no verified report of Amazon being directly hacked. The warnings issued relate to fraudsters targeting Amazon customers through phishing, fake websites, and social engineering — not breaching Amazon’s own systems.
How do I check if anyone is logged into my Amazon account?
Visit Amazon’s Login and Activity page under Account Settings. You’ll see a list of recent sessions with device type, location, and timestamp. Remove any sessions you don’t recognize and change your password immediately.
Is account update Amazon legit?
Verify the sender address — legitimate Amazon emails come from @amazon.com. If the email asks you to confirm passwords, payment info, or MFA codes via a link, it’s a phishing attempt. Report suspicious emails through Amazon’s Report Phishing page.
What are Amazon security alerts?
Amazon security alerts are notifications sent when your account experiences a new sign-in, password change, or payment method update. They help you detect unauthorized activity quickly. Enable push notifications through the Amazon app for real-time alerts.
How to recover a hacked Amazon account?
Change your password immediately, remove unrecognized devices, update payment methods if needed, and contact Amazon Customer Service. File a report at IC3.gov to document the crime. Monitor your financial statements for unauthorized charges and consider placing a fraud alert with credit bureaus.