Wednesday, September 16, 2026
Follow on LinkedIn

New Phishing Attack Targeting Amazon Prime Users To Steal Login Credentials

A sophisticated phishing campaign targeting Amazon Prime users has emerged, leveraging counterfeit renewal notifications to harvest login credentials, payment details, and personal verification data.

Discovered by the Cofense Phishing Defense Center (PDC) on February 18, 2025, the attack employs multi-stage deception tactics.

This include the spoofed emails, fake security alerts, and fraudulent payment portals designed to mimic Amazon’s official interfaces.

Researchers at Cofense noted that the campaign’s technical execution reveals advanced social engineering strategies, with threat actors exploiting Google Docs redirects and QR code-based payloads to bypass automated security filters.

Phishing Campaign

The attack begins with a spoofed email masquerading as an Amazon Prime renewal notice.

Email Body (Source – Cofense)

The email body warns recipients that their payment method is invalid and urges immediate action via a “Update Information” button.

While the sender’s display name (“Prime Notification”) appears legitimate, the originating domain uses a lesser-known URL (hXXps[:]//docs[.]google[.]com/drawings/d/1rSqoqN1uTTbP4qnfKzx2ZbvSı), a critical red flag.

Clicking the button redirects users to a fake Amazon security portal hosted on Google Docs, which requests account verification under the pretext of preventing unauthorized access.

Fake Amazon Security Alert (Source – Cofense)
Example of obfuscated URL:
hXXps[:]//qr-codes[.]io/unPek2

This intermediate page primes victims for credential theft by mimicking Amazon’s security protocols. Users are then directed to a counterfeit login page that captures usernames and passwords.

Amazon Login Page (Source – Cofense)

Unlike generic phishing sites, this campaign employs dynamic HTML injection to replicate Amazon’s multi-factor authentication (MFA) interface, including CSS stylesheets and JavaScript validation scripts.

After harvesting credentials, the attack escalates to data exfiltration. Victims are prompted to “confirm their identity” by submitting their mother’s maiden name, date of birth, and phone number—details often used for account recovery.

Personal Information Phishing Page (Source – Cofense)

A subsequent page requests billing addresses, enabling threat actors to reroute physical mail or execute identity theft.

Address Phishing Page (Source – Cofense)

The final stage captures full credit card details, including CVV codes, through a counterfeit payment portal.

Payment Information Phishing Page (Source – Cofense)

The campaign’s infrastructure relies on decentralized hosting, with phishing pages distributed across Google Docs, QR code generators (qr-codes[.]io), and compromised domains in Sri Lanka (recordzonerequiredaccountpaneluseraccpymntnew[.]srilankaı).

The use of QR codes (hXXps://qr-codes[.]io/unPek2) complicates URL analysis for both users and automated scanners.

Amazon has reiterated that legitimate communications will never direct users to third-party platforms like Google Docs.

Users are advised to manually navigate to Amazon’s official site to verify account statuses. Organizations should deploy email security solutions capable of detecting domain spoofing and inspect embedded links for redirect chains.

Enabling MFA remains critical, as stolen credentials alone cannot compromise accounts with hardware-based authentication.

This campaign shows the persistent threat of phishing-as-a-service (PhaaS) platforms, which enable even low-skilled actors to deploy complex attacks.

Continuous user education and proactive threat hunting are essential to counter these evolving tactics.

Indicators of Compromise (IoCs)

  • hXXps[:]//docs[.]google[.]com/drawings/d/1rSqoqN1uTTbP4qnfKzx2ZbvSı
  • hXXps[:]//qr-codes[.]io/unPek2
  • hXXps[:]//recordzonerequiredaccountpaneluseraccpymntnew[.]srilankaı/verify=cr51_23764

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Tushar Subhra Dutta
Tushar Subhra Dutta
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Cyber Security Guide

Latest Cyber News

Expert Talks