For millions of shoppers, Prime Big Deal Days on 6 and 7 October are about grabbing a bargain before the festive rush. For cybercriminals, it is harvest season, and they’ve laid the groundwork well in advance.
Two separate studies published ahead of the event point in the same direction. KnowBe4‘s Threat Lab says Amazon impersonation attacks surged by 188% between late August and September. Check Point Research, meanwhile, found that newly registered Amazon- and Prime Day-related domains have risen for three months running, from 905 in July to 1,284 in September, a 42% jump, and 37% higher than the 937 recorded in September 2025.
The end goal is familiar: account takeover, payment card harvesting and malware distribution. What has changed is the polish, scale and regional precision with which the attacks are being delivered.
Building the infrastructure
According to Check Point, around 6.5% of the Amazon-themed domains registered in September were classified as malicious or suspicious by its ThreatCloud platform. That is one in every 16 new domains. KnowBe4’s own monitoring picked up more than 700 new Amazon-themed domains in a single three-week window ahead of the event.

New Amazon/Prime Day-related domain registrations, July to September 2026. Source: Check Point Research
Examples flagged as malicious between July and September include amazonprime-support[.]com, primevideoamazon[.]com, prime-amazonfr[.]com and amazonprimeusa[.]com. Researchers also found fake Amazon login pages targeting users in Japan, Vietnam and the UK.
Some of the activity is clearly coordinated. One cluster, which Check Point has dubbed the AmazonShopping/ShoppingOnAmazon Numbered Network, comprises eleven related domains, ten of them malicious, and appears designed to mimic storefronts and checkout flows. A second, the AmazonGlobal Numbered Domains, consists of five similarly structured domains aimed at international shoppers, all malicious. Researchers also uncovered complete fake Amazon storefronts in Germany and Japan, and even a site targeting Amazon’s delivery partner programme in India.
Engineered to evade
KnowBe4’s data suggests attackers are investing heavily in getting past email defences. Three-quarters (75%) of the Amazon-themed attacks it analysed were polymorphic, constantly changing display names, subject lines or sending domains to dodge pattern-matching. Almost two-thirds (64%) used technical obfuscation such as zero-width spaces and hidden characters, and more than 95% relied on links leading to fake payment gateways or credential-harvesting pages, complete with cloned logos, buttons and footer disclaimers.
The largest campaigns, themed around account security alerts or delivery updates, averaged 86 phishing attacks each. In one high-volume operation, attackers sent fake ‘suspicious login activity’ warnings from a sprawling mix of free webmail and burner accounts, rotating senders to dilute detection signals.

A credential-harvesting email posing as an Amazon security alert, urging recipients to ‘verify’ their account to keep access to Prime Day offers. Source: KnowBe4
Another campaign, aimed at UK and US mailboxes, used generative AI to churn out personalised deals while dynamically rewriting subject lines. Although it claimed to be from Amazon, the true sender traced back to infrastructure linked to a legitimate multi-cryptocurrency wallet app, likely abused or spoofed to borrow its domain reputation. The malicious link was hidden behind a clickable image rather than text, and victims were bounced to a fake news site acting as a trusted front for credential theft.
In Japan, attackers used white-on-white text, embedding invisible random characters in the HTML to confuse scanners while remaining unseen by the recipient. The emails came from freshly registered domains built to defeat legacy domain-age checks.
What the lures look like
Account and billing scares are the single biggest category, but freebies and delivery notices are not far behind:
| Lure theme | Share of global attacks |
| Prime billing, account renewal or ‘login detected’ | 31% |
| Free gift or reward | 29% |
| Delivery notice | 25% |
| Limited-time offer | 15% |
Share of global Amazon-themed phishing attacks by lure theme. Source: KnowBe4
A localised playbook
While campaigns are broadly sprayed at scale rather than individually targeted, KnowBe4 found attackers tailoring their lures to local habits and anxieties:
- United Kingdom: Delivery and parcel traps dominate, with urgent ‘confirm your delivery address’ and missed-parcel notices designed to push users to fake address-verification pages.
- United States: 76% of attacks focus on billing problems or membership renewals, playing on fear of losing Prime benefits.
- Germany: 85% of attacks were delivery-based. Germany was also hit by a wave of the Japanese campaign between 27 and 29 September, using ‘Amazon.co.jp’ display names laced with invisible characters.
- France: Although around 75% of Amazon attacks globally were in English or Japanese, over 90% of those aimed at French targets were natively translated, dangling ‘exclusive access’ and expiring deals.
- Netherlands: 90% of attacks pushed fake ‘Prime Day offers’. Dutch inboxes also received the French campaign from 22 September and the Japanese one in the same week as Germany, suggesting the latter was sent globally.
- UAE: Unlike the rest of EMEA, every attack was a ‘gift alert’ or ‘you have won’ lure, all in English and spread evenly across September with no peak week.
- Japan: High-urgency account verification and suspicious-login notices sent from newly created lookalike domains.
AI is erasing the old warning signs
Both firms highlight the role of generative AI. Check Point warns that AI tools let threat actors rapidly produce well-written, localised phishing messages and convincing replica websites at scale, stripping out the spelling mistakes and clumsy phrasing that shoppers have long relied on to spot a fake. The French campaigns’ native-quality translations and the personalised UK and US lures documented by KnowBe4 are cases in point.
Pressure builds on the businesses behind the sale
The risk does not stop with consumers. Check Point says financial services organisations, the banking and payments infrastructure that clears Prime Day purchases, faced an average of 2,650 attacks per organisation per week in September. That is up 14% on August and 66% year-on-year, far outpacing the 48% increase seen across all industries.
Consumer goods and services organisations, the retailers, marketplaces and electronics sellers actually running the sale, recorded 2,578 weekly attacks per organisation, up 22% month-on-month and 52% year-on-year. Check Point argues this underlines the need for retailers, payment providers and banks to identify and block malicious domains and phishing before they reach customers, rather than cleaning up afterwards.
Pause before you click
Lucy Gee, Lead Threat Analyst at KnowBe4, said: “As Prime Big Deal Days approach, cybercriminals rely heavily on our fear of missing out. The most important thing consumers can do is pause before clicking. If an email warns that your account is locked, your payment failed, or that you’ve won a free prize, don’t use the links in that message. Navigate directly to the official Amazon app or website to check your account status, hover over links to check the real web address, and remember: if a deal or offer looks too good to be true, it almost certainly is.”
Drawing on advice from both companies, shoppers should:
- Go direct. Access Amazon through the official app or by typing the address, never via links in emails, texts or social media adverts.
- Check senders and URLs. Hover before clicking and look out for hyphenated lookalikes such as amazon-support-login.com.
- Recognise pressure tactics. Countdown timers, delivery failure warnings and suspension threats are classic red flags.
- Don’t rely on bad grammar. AI-generated scams can look polished and professional.
- Turn on MFA or passkeys. Stolen passwords are far less useful without a second factor.
- Watch your statements and report anything suspicious straight away.
With malicious domains still appearing and phishing campaigns already in full swing, the message from researchers is clear: the deals may last 48 hours, but the fallout from a single careless click can last much longer.





