Amazon account - Someong just bought gift cards using my account.

25 Posts


This evening on the computer just got an email saying £50 had been put on my Amazon Gift Balance. Straight away went onto Amazon and yes its been added from my Current Account card thats in there. Whilst I was frantically figuring out what to do a £50 Google Play gift card appeared in my basket. I managed to cancel it out of there but it got put back in and paid for. I then changed my password quickly. Looks like I'd been hacked somehow.
Now before you think its a poor none techy person their computer must be compromised I`m an IT Support person of 30+ years, I've got Kaspersky Internet Security fully on etc etc. My Amazon account has got 2 factor authentication to my phone. So how did someone manage to figure out my password, bypass the 2FA which it will ask you for when you use a new browser and send the gift card to an unknown email address which doesnt even show up in the order. They also tried to archive both orders so I wouldnt notice it in there.
My computer has been scanned malware free with 3 different scanning programs. This isnt a case of someone getting a keylogger onto my machine as no way have they got my password. It just shows you that 2 factor authentication is fallible and these hackers can bypass it just like that. To prove this I also used the sign out of everywhere link on the Amazon website to sign my account out of every device. Now when I log back in using my computer and mobile app it asks for 2FA code. So how can a hacker then get into my account without the 2FA code. Simple answer, 2FA is just not a safe way of securing your account.
I've reported it to Amazon Customer Services and they have passed it onto their security Team. However I dont trust Amazon anymore and I`m not leaving any payment cards on the account every again.
let this be a warning that these so called security measurements are not that secure.
Now before you think its a poor none techy person their computer must be compromised I`m an IT Support person of 30+ years, I've got Kaspersky Internet Security fully on etc etc. My Amazon account has got 2 factor authentication to my phone. So how did someone manage to figure out my password, bypass the 2FA which it will ask you for when you use a new browser and send the gift card to an unknown email address which doesnt even show up in the order. They also tried to archive both orders so I wouldnt notice it in there.
My computer has been scanned malware free with 3 different scanning programs. This isnt a case of someone getting a keylogger onto my machine as no way have they got my password. It just shows you that 2 factor authentication is fallible and these hackers can bypass it just like that. To prove this I also used the sign out of everywhere link on the Amazon website to sign my account out of every device. Now when I log back in using my computer and mobile app it asks for 2FA code. So how can a hacker then get into my account without the 2FA code. Simple answer, 2FA is just not a safe way of securing your account.
I've reported it to Amazon Customer Services and they have passed it onto their security Team. However I dont trust Amazon anymore and I`m not leaving any payment cards on the account every again.
let this be a warning that these so called security measurements are not that secure.
1
Latest MSE News and Guides
Childcare budget boost
More support for children from nine months and those on Universal Credit
MSE News
Replies
4 debits last year for Amazon prime I did not make, was issues with a new card and bought something on 6th January this year, 7th January a debit for Amazon prime on my new card,
I now have my third new card in the space of 6 months.
I have no confidence in buying anything from Amazon till I get some guarantee
My issue has also be escalated to their security team
Also another weird thing with this Amazon purchase is I get an email for the first top up but I dont get an email for the purchase of the Google Play card. Yet my email address had never been changed!
I'm not waiting for a refund as my credit card sorted that
I just need to know why and will it happen again or not
It is likely your son did click something that was malicious in nature, and if using discord in a web browser this is even more likely. I guess if a user is browsing amazon on a compromised browser, or app, a similar attack could take place.