What you're describing is credit fraud. Amazon has no idea who authorized users of the card are. It's not required that the name on the card match the name of the person using it. Many places want it to match to prevent fraud as often times the end business is left with the loss of money and product but there's no legal or policy requirements. It's only that a person has been authorized to use it
CC numbers leaked from hacks that happen all the time. If this has happened twice in a row now, most likely the leak is on your side somewhere. Someone may have access to your systems or it could be a restaurant you frequent or any number if things. Amazon isn't the one to contact about fraud, your credit card company is the one to contact.
Their department has access to all the charges and fraud reports. Credit card companies do correlate fraud reports between them. One of the most simple and basic attacks is simply copying credit card numbers down at restaurants or any other place where your card may be out of your site for a few moments and it's totally normal for that to be the case.
You don't have any legal recourse against Amazon because they didn't do anything wrong. Unless of course you can show that they were the ones that perpetrated the fraud but them simply accepting a card it is appropriate for them to assume it was authorized to be used. Any legal recourse would be against your credit card company but in my experience I have never had to go the legal route with a credit card company. They are excellent at reimbursing for fraudulent charges and reissuing cards and tracking down the source of the fraud. If discover has not immediately reimbursed you for the charge on your card then they are the ones you need to talk to and point out these are fraudulent charges and the fraud happened twice. There should be no need for legal recourse because you have suffered no damages.