Skip to content

Security1 publisher2 min readPublished

Check Point flags one in 16 new Amazon-themed domains as malicious or suspicious before Prime Day

Check Point Research flagged 6.5% of September's 1,284 new Amazon- and Prime Day-themed domains as malicious or suspicious, about one in 16. Phishing aimed at the October 6-7 sale is already live, using old lures on batch-registered lookalike names that standard mail and DNS filtering is built to catch.

The Watch · Security desk

Illustration accompanying Check Point flags one in 16 new Amazon-themed domains as malicious or suspicious before Prime Day
Generated illustration

What happened

  • New Amazon- and Prime Day-themed domain registrations climbed for three straight months, rising 42% from 905 in July 2026 to September's total.
  • Check Point Email Security blocked September emails posing as Amazon that promised free gift cards or warned that the recipient's account had been locked.
  • Fake Amazon login pages were aimed at users in Japan, Vietnam and the United Kingdom, according to Check Point.
  • Researchers also found full fake Amazon storefronts in Germany and Japan, plus a site targeting Amazon's delivery partner program in India.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint If Check Point is right that generative AI strips spelling and phrasing errors out of lures, staff guidance built on spotting typos will catch fewer of them, and sender and domain checks have to catch more.
  • decision A blanket block on every newly registered Amazon-themed domain would mostly stop names ThreatCloud did not flag, since 93.5% of September's registrations fell outside its malicious or suspicious class.
  • constraint The September emails were caught by Check Point's own product, so the report measures what one vendor stopped; how often these lures get past other filters is unknown.

Applied to its own count, Check Point's share comes to about 83 flagged domains in September: 6.5% of 1,284 [1]. Its "one in 16" slightly understates that share. At 6.5%, the ratio is nearer one in 15 [2]. September's total was also 37% above September 2025, when Check Point counted 937 [3].

No software flaw is involved. The attack is a lookalike domain hosting a copied Amazon login, storefront or checkout page [5][7]. The payoff Check Point names is Amazon credentials, payment information and personal data [14].

The coordination shows in the batches. The AmazonShopping/ShoppingOnAmazon Numbered Network ran to eleven related domains, ten of them classified malicious. Check Point says the set is "likely designed to imitate online storefronts and checkout processes" [7]. A second group, the AmazonGlobal Numbered Domains, had five similarly structured names aimed at international shoppers, all malicious [8]. The individual examples Check Point published pair the brand with a word or a country tag: amazonprime-support[.]com, prime-amazonfr[.]com, amazonprimeusa[.]com and amazonprimewindows[.]com [5].

Malware is the hedged part of the report. Check Point says other campaigns "may also involve malware disguised as invoices, delivery notifications or refund-related communications" [10]. The examples it actually documents are credential and payment phishing [5][14].

The pattern is seasonal and follows Amazon's sale calendar. Check Point calls the event "a recurring flashpoint for financially motivated cyber activity worldwide" because it squeezes purchases, gift-card redemptions and logins into a 48-hour window [12]. The report documents coordinated registration and familiar lures. Check Point did not tie either cluster to a named group or publish victim counts [7][8].

What to watch

  • Whether Check Point or another researcher publishes full indicator lists for the AmazonShopping/ShoppingOnAmazon and AmazonGlobal numbered clusters before October 6.
  • October registration and flag-rate figures after the sale, measured against September's 6.5%.
  • Any published sample of the malware Check Point says may arrive disguised as invoices, delivery notices or refund messages.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories