Do not click the message. Open the Amazon app or type Amazon’s known website address yourself, then check your orders, payments, messages, and security settings. “Amazon Prime email scam” describes a changing family of impersonation and phishing attempts—not one fixed email. The goal may be your Amazon password, a one-time code, payment details, identity information, or access to your device.
What the Amazon Prime email scam looks like
Impersonation emails commonly claim that something urgent has happened to your account. Examples include:
- A large order was placed and you must click to cancel it.
- Your Prime membership will be canceled unless you update billing information.
- Your account was locked after suspicious activity.
- Your Prime subscription expired or failed to renew.
- You are owed an Amazon refund or settlement payment.
- You must “verify” your identity, password, or payment method.
- You must call a “fraud department” immediately.
The FTC identifies fake Amazon security alerts and unauthorized-charge claims as recurring impersonation patterns. A message can look polished and use accurate logos, while a genuine Amazon alert can also arrive by email. The safe response is independent verification, not judgment based on appearance.
What the sender is trying to steal
Amazon account access
A fake sign-in page can capture your email address, password, and one-time verification code. An attacker may then place orders, change your recovery email or phone number, access stored addresses and payment methods, or try the password on other services.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Payment and identity data
Requests may include a card number, expiration date, security code, bank details, Social Security number, date of birth, government-ID information, or Amazon gift-card codes. Amazon Pay says legitimate communications should not request sensitive information such as Social Security numbers, birth dates, card numbers, PINs, or security codes by email: Amazon Pay security guidance.
Remote access and a second-stage phone scam
Some messages provide a phone number rather than a link. A fake “Amazon representative” may ask you to install remote-access software, share your screen, reveal a one-time code, or move money to “protect” it. The FBI describes this escalation as a common tech-support scam pattern: FBI tech-support scam guidance.
Warning signs: strong clues and weak clues
Strong warning signs
- Immediate deadlines, threats, or pressure to keep the matter secret.
- A request for a password, one-time code, gift card, bank transfer, or remote access.
- A login or payment link, unexpected attachment, or phone number supplied in the message.
- A destination whose registered domain is not controlled by Amazon.
- Unusual payment demands or a “guaranteed” refund.
- A request for sensitive identity information by email.
Inspect the complete destination domain, not just words such as “amazon,” “prime,” or “security” in a subdomain or link path. The FBI recommends avoiding unsolicited links and attachments and using contact details located independently: FBI spoofing and phishing guidance.
Rank #2
Weak clues that do not prove anything
Grammar mistakes, a generic greeting, a slightly wrong logo, spam-folder placement, an unfamiliar display name, or a sender ending in @amazon.com are not conclusive. Sender information can be spoofed, regional systems vary, and professional scam messages may contain flawless branding. Amazon specifically warns that attackers can fake sender information and direct users to fraudulent sites: Amazon phishing discussion.
How to verify the claim without clicking
- Stop interacting. Do not click, reply, call, download, or enter information. Do not use a number supplied in the email.
- Open Amazon independently. Use the official app or manually type your known Amazon web address. CISA recommends direct navigation rather than email links: CISA phishing guidance.
- Check Your Orders. Look for the alleged purchase, charge, cancellation, or refund.
- Check Message Center. Review Amazon communications in the account, but do not treat the absence of a matching message as the only test.
- Review Login & security. Check the account email, phone number, password settings, and recent security activity.
- Review payment methods and addresses. Remove unfamiliar entries and investigate unexpected changes.
- Use official customer service. Navigate there from Amazon itself if the account event remains unclear.
Amazon advises checking purchase, account, and other notices directly through Amazon.com or the app: Amazon’s scam-avoidance guidance.
What Amazon will not need from an email exchange
Treat requests for passwords, one-time codes, full card details, PINs, Social Security numbers, gift cards, bank transfers, or remote access as a stop signal. MFA makes an account harder to take over, but it does not make phishing harmless: a scammer can simply ask you to read the code aloud. Never disable MFA because a caller or email tells you to.
Rank #3
If you clicked, use the response that matches what happened
You clicked but entered nothing
Close the page and do not download anything it offers. Install pending browser and operating-system updates and run your normal security scan. Check Amazon directly for unfamiliar orders, addresses, payment methods, email changes, or security settings. Change your Amazon password if it may have been entered, copied, or exposed. Clicking alone does not prove that a device was compromised; risk depends on downloads, browser behavior, vulnerabilities, and what you did next.
You entered an Amazon password or shared a verification code
- Sign in directly to Amazon and change the password.
- Change that password anywhere else it was reused.
- Turn on two-step verification.
- Review orders, payment methods, addresses, email, phone number, and connected services.
- Secure the email account linked to Amazon if it may also be exposed.
- Contact Amazon through its official site if access or recovery details changed.
- Check card and bank statements for unauthorized activity.
You entered card or bank information
Call the issuer or bank using the number on your card or an official statement. Ask whether the account or card should be blocked or replaced, dispute unauthorized transactions through its established process, and monitor alerts. After securing Amazon, remove the exposed card from the account if appropriate. Recovery is not guaranteed; timing, payment method, issuer policy, and transaction circumstances matter.
Recommended Free Tools
You disclosed identity information
Use the FTC’s recovery process at IdentityTheft.gov. Consider a credit freeze or fraud alert as appropriate to your situation.
Rank #4
You installed software or allowed remote access
Disconnect the device from the internet if remote control is still active, uninstall unauthorized software, run a reputable security scan, and update the operating system and browser. From a different, trusted device, change exposed passwords and contact your bank. If the device handled sensitive work or financial information, obtain professional incident-response help.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Change your Amazon password and enable two-step verification
Password path
On Amazon, go to Account & Lists → Your Account → Login & security → Password: Edit, then save a new, unique password. Amazon documents this path at Amazon Pay account-security help.
Two-step-verification path
- Sign in directly to Amazon.
- Select Account & Lists, then Your Account.
- Open Login & security.
- Under Advanced Security Settings, select Edit.
- Select Get Started under two-step verification and follow the prompts.
Amazon may offer a phone number or authenticator app depending on the account interface and setup options. An authenticator app can be preferable in some threat models, but SMS is not universally unsafe; the essential rule is never to disclose a one-time code to a caller or email sender. See Amazon’s two-step-verification instructions.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Prevent the next takeover
Use a long, unique password for Amazon and every important account. A password manager such as Bitwarden or 1Password can help eliminate reuse, but it cannot recover an already compromised account or stop someone from voluntarily giving away an MFA code.
Where to report the message
| Situation | Report to |
|---|---|
| Message impersonating Amazon | Amazon’s reporting process; Amazon identifies [email protected] for suspected forgeries. Amazon suspicious-email reporting |
| U.S. phishing or impersonation attempt | FTC ReportFraud.gov; the FTC also accepts forwarded phishing emails at [email protected]. |
| Financial loss, account takeover, or internet crime | FBI Internet Crime Complaint Center |
| Exposed identity information | IdentityTheft.gov |
| Unauthorized card or bank activity | Your bank or card issuer, using independently verified contact information |
After reporting, delete the message. Do not forward it to friends or family in a way that could preserve a dangerous link.
Refund and settlement emails in 2026
Refund-themed messages deserve extra caution because eligible U.S. Prime customers began receiving Amazon settlement claim notices by mail or email in January 2026. That genuine event gives impersonators a believable pretext. Verify any claim through independently opened FTC or Amazon pages. The FTC says it is not contacting people about Amazon refunds, and neither the FTC nor Amazon will ask you to pay money to receive one: FTC Amazon refunds information.
Amazon says it initiated takedowns of more than 70,000 phishing websites and 14,000 phone numbers used in impersonation scams in 2025; those figures are Amazon’s own report, not an independent audit: Amazon scam-avoidance guidance.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Do this now
- Stop using the email’s links, attachments, replies, and phone number.
- Open Amazon independently and inspect orders, messages, payments, and security settings.
- Change the password and enable two-step verification if credentials or codes were exposed.
- Change reused passwords and secure the linked email account.
- Contact the bank or card issuer immediately if financial details were disclosed.
- Report the attempt, then delete the message.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




