Fraudsters are moving ahead of Amazon’s Prime Day, with a sharp rise in fake domains, phishing emails and spoofed storefronts designed to steal credentials and payment data from bargain hunters.
Amazon Prime Day phishing domains rise before sale

That matters because Prime Day is one of the biggest online shopping events of the year, turning Amazon and its retail partners into a larger-than-usual target for cybercrime just as consumers are primed to click quickly on urgent-looking offers. Check Point Research said new Amazon- and Prime Day-related domains climbed for a third straight month, rising to 1,284 in September from 905 in July, a 42% increase, while 6.5% of those domains were flagged as malicious or suspicious.
The campaign is broad and increasingly professional. Check Point said it found fake Amazon login pages aimed at users in Japan, Vietnam and the UK, along with networks of related domains built to mimic online stores and payment flows. It also identified full-copy Amazon storefronts in Germany and Japan, plus a site aimed at the delivery-partner program in India.
The threat extends beyond consumers to the payments ecosystem and retail sellers that rely on the Prime Day traffic spike. Check Point said companies in the financial sector faced an average of 2,650 attacks a week per organization in September, up 14% from August and 66% from a year earlier, while consumer goods and services firms — including retailers and electronics sellers tied to the Amazon campaign — saw 2,578 attacks weekly, up 22% month on month and 52% year on year.
The timing is important for investors because online retail events concentrate transaction volume, customer acquisition and advertising spend into a short window, but they also amplify fraud risk, chargebacks and reputational damage. Amazon has previously warned in regulatory filings that it is affected by fraudulent or unlawful activities by sellers, while payment fees and third-party systems can add to operating costs.
The rise of generative AI is making the scams harder to spot, according to Check Point, because criminals can now produce polished, localized messages and convincing site replicas at scale without the obvious spelling and formatting errors that once gave them away. For shoppers, that raises the odds that a rushed click on a “too good to miss” deal turns into stolen card details or compromised accounts.
For Amazon, the bigger test will be whether it can keep Prime Day traffic moving without giving fraudsters a bigger opening. For investors, the issue is less about immediate revenue and more about trust, conversion rates and the extra security costs that come with a shopping event large enough to attract both buyers and attackers.
| Entity | Gains | Losses |
|---|---|---|
| Amazon shoppers | ▲Legitimate deals | ▼Fake sites and phishing |
| Amazon and sellers | ▲Sales volume from Prime Day | ▼Fraud-related trust risk |
| Payment processors | ▲Higher transaction flow | ▼More fraud and chargebacks |
| Cybercriminals | ▲Prime Day traffic and urgency | ▼Detection as defenses tighten |



