NEWS

Prime Day Cyber Scam Alert

Prime Day sees an 80% surge in scams, with fraudsters employing new tactics like “poisoned” search results leading to fake support sites. Learn essential tips and tools to protect your online shopping and personal data.

By
LNGFRM Team
Published June 21, 2025
Abstract illustration depicting online data flow and security with icons for a padlock, a shopping bag, and a location pin connected by winding lines.
Illustration by Addison Smith for LNGFRM

The digital shopping bonanza that is Amazon Prime Day is once again upon us, promising four days of enticing deals from July 8 to July 11.

Yet, beneath the veneer of discounted gadgets and household essentials lies a shadowy, ever-present threat: the relentless surge of cybercriminals.

As consumers prepare to click their way to savings, a chilling reality check emerges – the very act of seeking a bargain can turn into a costly misstep, orchestrated by fraudsters who are, quite literally, following the money.

Last year’s Prime Day saw a staggering 80% increase in impersonation scams targeting Amazon customers.

Phone calls claiming to be from Amazon support, warning of fictitious account issues or undelivered orders, more than doubled.

These aren’t random, isolated incidents; they are calculated assaults designed to exploit trust and create panic.

As if on cue, while penning this very warning, my phone buzzed with an unsolicited call.

A robotic voice, feigning concern, inquired if I had placed an order for an iPhone 13.

The irony was palpable, a stark, real-time demonstration of the very menace Amazon is cautioning against.

It’s a testament to the sheer audacity and pervasive nature of these attacks.

An Amazon spokesperson confirmed the grim statistics: “In the weeks surrounding Prime Day in 2024,” they revealed, “Amazon customers reported an 80% increase in all impersonation scams that claimed there was an issue with their account.”

The top tactics, unsurprisingly, revolved around fabricated problems with orders, accounts, or payments.

This escalating threat demands more than just a passing glance; it requires a fundamental shift in how we approach online interactions.

Amazon, to its credit, is not standing idly by.

The retail behemoth has issued a comprehensive advisory, a digital shield against the most common forms of brand impersonation.

The core tenets are simple yet profoundly effective: never, under any circumstances, share your Amazon credentials with third-party tools or websites unless they explicitly support the secure “Login With Amazon” authentication process.

Always verify purchases directly on the Amazon app or website, resisting the urge to click on suspicious links in emails or text messages, or to divulge account information over the phone.

Amazon will only ever request payment within its official app or website, never through email or phone calls.

A critical piece of advice often overlooked: resist the scammer’s manufactured sense of urgency.

Take a breath, count to ten, and verify before you act.

And perhaps the most telling red flag: Amazon will never, ever ask you to purchase a gift card.

Furthermore, keeping your operating system and the Amazon app updated to their latest versions, coupled with activating two-factor authentication (2FA) on your account, are non-negotiable layers of defense.

Yet, even as we fortify our individual accounts, the battlefield expands.

Cybersecurity professionals often preach the mantra: “Trust nothing, verify everything.”

They advise hanging up on suspicious callers and independently looking up the official contact number to call back.

This, for years, has been sound advice.

But the digital landscape is a constantly evolving predator, and even this foundational wisdom is being undermined.

A recent report from Malwarebytes has cast a chilling light on a new, insidious tactic: the poisoning of search engines.

Cybercriminals are now leveraging sponsored search results on platforms like Google to direct unsuspecting users to meticulously crafted, fake support sites.

These aren’t crude phishing pages; they are sophisticated replicas, often displaying the legitimate brand’s URL in the browser address bar.

The subtle, yet devastating, difference? The displayed contact number belongs to the fraudsters.

This means that if you search for “Apple support” or “Bank of America customer service,” a sponsored ad might lead you to a site that looks indistinguishable from the real thing, but the phone number prominently displayed is the scammer’s direct line.

It’s a cunning psychological trick, exploiting our inherent trust in search results and the visual cues of legitimacy.

“The browser address bar will show that of the legitimate site, and so there’s no reason for suspicion,” warned Pieter Arntz, report author for Malwarebytes.

“The information the visitor sees will be misleading, because the search results have been poisoned to display the scammer’s number prominently in what looks like an official search result.”

This revelation underscores the urgent need for heightened vigilance beyond just Amazon.

The threat is ubiquitous, targeting any brand or service that commands public trust.

Fortunately, the cybersecurity community is also adapting.

Tools like Malwarebytes’ “Browser Guard” extension can now detect such “Search Hijacking” attempts, issuing a warning to the user.

Similarly, privacy-centric web browsers are stepping up their game.

DuckDuckGo, for instance, has recently updated its browser with a built-in “Scam Blocker” function specifically designed to combat online shopping threats.

This includes protection against phishing sites, malware, and, crucially, “sham e-commerce sites, fake cryptocurrency exchanges, scareware that falsely claims your device has a virus, and other sites known to advertise fake products or services,” as explained by Peter Dolanjski from DuckDuckGo.

As Prime Day approaches, the onus is on every consumer to become their own first line of defense.

The thrill of a bargain should never overshadow the imperative of security.

In a world where even the most trusted avenues of information can be compromised, the only true safeguard is a healthy dose of skepticism, coupled with an unwavering commitment to verification and the adoption of robust digital protections.

The deals may be fleeting, but the lessons learned from falling victim to a scam can last a lifetime.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like

Mohit Bansal: On Zero-Headcount Security Scaling

Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.

By Mike Malone
Published June 30, 2026
© 2026 LNGFRM. All rights reserved.