Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Comment: Amazon Hit By Extensive Fraud With Hackers Siphoning Merchant Funds
News & Analysis

Comment: Amazon Hit By Extensive Fraud With Hackers Siphoning Merchant Funds

ISBuzz TeamBy ISBuzz TeamMay 11, 2019Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Amazon authentication
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

loomberg reported yesterday that Amazon.com Inc has been reportedly hit by an “extensive” fraud, revealing that unidentified hackers were able to siphon funds from merchant accounts over six months last year. 

https://t.co/VGLGhCHqyn has been hit by an "extensive" fraud, revealing that unidentified hackers were able to siphon funds from merchant accounts over six months last year : https://t.co/E1nK4J8PT3 pic.twitter.com/GbFDRTXnEq

— News24 Business (@News24_Business) May 8, 2019

Expert Comments: 

Brian Higgins, Security Specialist, Comparitech.com:   

“I’m not at all surprised to hear that Amazon are exploiting children’s data in this fashion. Let’s also not forget that although this case has arisen in America, Amazon’s platform is global. The unscrupulous retention of data for potential commercial gain or advantage is common among all social media platforms and I’m delighted to hear that the practice is finally being challenged. A friend of mine died a couple of years ago but I still get regular messages from Twitter asking me to follow her. There is no proprietary, or common, mechanism for account disablement, let alone deletion even when the data owner is deceased. The recent European General Data Protection Regulation offers the ‘Right to Erasure’ for those under its purview but even that requires an unnecessarily onerous amount of dedication and tenacity on the part of the individual.   

Unfortunately, data is a valuable commodity in the digital economy and nobody will give it up without a fight. In Amazon’s business plan today’s children are tomorrow’s customers, and the more information they can gather the more stuff they can sell to them. I’m pretty sure there’s no minimum age limit on Ad Ware.”  

Dean Ferrando, Systems Engineer at Tripwire:    

“Regardless of the outcome of this investigation, it is encouraging to see that IoT devices are met with constructive criticism, rather than blindly trusted to be safe and compliant. Smart home appliances are a relatively new entry in consumers lives, and it perfectly understandable, and advisable, that users ask questions about how these devices work and how they treat their data. A reputable manufacturer such as Amazon will take the opportunity to make its processes transparent to its customers and to adjust its practices to ensure full compliance.” 

Corin Imai, Senior Security Advisor at DomainTools:

“Users of a recognised platform such as Amazon can often fall into a sense of false security and blindly trust the provider to keep their details and their accounts secured. The truth is that, despite the state-of-the-art security measures that these organizations put in place, breaches are inevitable.   

Users can take steps toward protecting their credentials by remaining vigilant when combing through emails. This attack, in fact, seems to have started with a phishing campaign that cast a wide net of potential victims and then narrowed its scope to the roughly 100 people that ended up accidentally sharing their credentials.   

Service providers should continue to promote phishing awareness among their users, and that they alert users as soon as the breach has been detected.” 

Paul Bischoff, Privacy Advocate at Comparitech.com:

“To be clear, Amazon was not hacked. Amazon says the affected accounts were likely compromised through phishing scams that tricked merchants into giving up their login information. Unlike hacking, which can be prevented through technological means, phishing is much more difficult for a company to prevent. The attack takes place beyond Amazon’s control and leverages social engineering rather than a security vulnerability. Amazon can’t stop merchants from being phished or prevent them from receiving phishing messages, because Amazon doesn’t control their email and messaging accounts.   

A few precautions could help prevent this sort of attack, though we don’t yet know all the details of how they occurred. Two-factor authentication would prevent unauthorised users from logging in on unfamiliar devices without a PIN code, for example. Amazon could require additional verification of some sort whenever a merchant attempts to change their bank account settings. But it’s really up to merchants to know how to spot phishing messages and handle them appropriately.”  

Corin Imai, Senior Security Advisor at DomainTools:

“Users of a recognised platform such as Amazon can often fall into a sense of false security and blindly trust the provider to keep their details and their accounts secured. The truth is that, despite the state-of-the-art security measures that these organizations put in place, breaches are inevitable.   

Users can take steps toward protecting their credentials by remaining vigilant when combing through emails. This attack, in fact, seems to have started with a phishing campaign that cast a wide net of potential victims and then narrowed its scope to the roughly 100 people that ended up accidentally sharing their credentials.   

Service providers should continue to promote phishing awareness among their users, and that they alert users as soon as the breach has been detected.”

Martin Jartelius, CSO at Outpost24 speaking from an EU perspective:   

GDPR stipulates the right to be forgotten and the right of erasure, as well as privacy by design. Clearly, this is in violation of a range of the requirements of the legislation, especially with regards to the retention. If getting in contact with support, resolve the right to be forgotten and that is still sufficient for that specific requirement. This is a good example of a service that, by its nature, is the very reason we need privacy legislation.   

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}