Amazon Hit by Extensive Fraud with Hackers Siphoning Merchant Funds
bloomberg.com
bloomberg.com
In the vast majority of cases money is released within 2 weeks of a sale. The exceptions are if an account gets suspended, or if there's a sudden increase in sales and it's flagged, in which case they might hold it for another week or two.
The only time money is held for over a month is if the account was suspended and not reinstated by then.
Presumably it helps with inventory management too - like the loanee indicates the inventory they're buying which means Amazon can factor that in.
Then they charge interest ...
However, whilst this sounds good for Amazon, is it more efficient - in economic terms - or does it just reduce Amazon's risks and costs.
They have an offer on my dashboard that's 10% interest for 3x monthly subscriptions (not total monthly revenue), 20% interest for 6x. To me, it seems rather aggressive. I'd have to be super desperate to accept those terms.
Since the fraudsters never received the package I don’t think they gained anything directly by stealing from my partner’s debit card. So that made me think, how could they be gaining from this? I’m assuming some unscrupulous merchants or “marketing consultants” are using this kind of fraud to boost sales for themselves or their clients.
Also if you don't aggresively react to this (e.g. file a complaint, get your money back etc) they also get the info that you don't pay so much attention to these details, and that puts a bigger target in your head.
Token based 2FA is another story though... it definitely adds another layer of security to your passwords and amazon supports this format.
In the case of the OP's partner, my guess is that either they were phished into revealing their Amazon password or their password for Amazon was the same password used elsewhere and that source was hacked.
2FA is a general term. U2F is a type of 2FA. The other type, which is what I was referring to, is TOTP (Time-based one time password).
You are right that U2F is more secure. The primary security advantage is that there is no longer a shared secret that needs to be stored on each end. But saying 2FA is useless would be like also saying that U2F is useless since 2FA is a general term.
That said, in this case, TOTP would have likely prevented anyone from accessing the OP's partners account. Therefore, TOTP is not useless per your original comment.
https://m.youtube.com/watch?v=kGGMgEfSzMw&time_continue=1271