Two-for-one: Amazon.com’s Socially Engineered Replacement Order Scam
htmlist.com
htmlist.com
As to whether or not something should be done, this is a sensitivity/specificity tradeoff. Too far in the other direction of distrusting customers and Amazon ends up like Paypal.
In any case, some authentication aside from "Full Name" would be nice. When I was with Liquid Web, I had a pass phrase set up, which I could pass off as regular conversation even in a crowded room without anyone suspecting it was my authentication. That works best. Even a birth date and city of birth would be better than a name.
This is true. I got locked out of my Paypal account because I had the audacity to log in from a nearby country (Germany). Fair enough, though maybe a bit overzealous. To get control back they then had to charge a small, random amount of money to my account and phone my registered phone number to give me a code to input. Reasonable, perhaps, except that it didn't work! and to this day still hasn't. I can't count the number of times I entered in the code. So I just created a new account with an alternative email instead . . .
This was a few years ago admittedly, so maybe they're better now, but it's one thing to have overzealous policies and quite another to implement those policies poorly. And that's not even getting into the one time I actually needed PayPal buyer protection, because I'm sure we could all be sharing PayPal horror stories all day if we go down that road.
As the article points out, their web-based security seems pretty darn solid. Nearly any account change requires reauthenticating with your password, and only recently did they start to roll out support for a more persistent auth for viewing what most people would consider non-critical info (order history, etc). With the exception of a phone-based password reset - which should not cause a problem like the one described here - they could require even a web-based PIN (behind the login-wall, of course) for chat and phone support; live chat could skip this if the user already has a fresh auth.
I hope for everyone's sake that Amazon is able to prevent this kind of problem without harming their fantastic customer support. There's a reason I've averaged an order every 5.3 days this year (I can stop any time I want to, but thank you for your concern!)
I had a delivery of a game go missing (~$60 cost) so I opened a live chat and explained, then they shipped me a brand new order (which arrived!) without any hassle or confirmation that my prior delivery had really been stolen. This seems like a trivial thing to abuse (and I'm sure many do). After my free re-order was placed I thought "that was cool, I'll order from Amazon in the future just in case...".
But what I confirm is great customer service. Last week my sound card broke down after almost 2 years and it took about 5 minutes to get the return information and the according refund once the item showed up at amazon. No hassle what-so-ever with waranty issues and replacement of the original item, just a plain and simple refund.
That's what customer service should be like. And that things like that can be exploited is true, but that's equaly true for almost all other things. If it's a calculated trade-off from amazon's side there shouldn't be a problem.
I once ordered an item by mistake (oops, one click shipping!) I should have paid attention. I requested to return the item and fully expected to pay the shipping costs back. I explained that it is MY fault. They still told me that it wasn't a big deal and that they would cover the shipping back.
I'm not sure what the proper solution is. I don't want to lose that helpfulness, but I hate for them to get ripped off, too, due to assholes. They've been very good to me and have quickly addressed any issue I've ever had.
On the other hand, the stuff recommended in the blog posts would be easy to implement without really making it more of a hassle (only ship to places already listed, ask for more than name, mail and address, collate chats).
This seems like a trivial thing to abuse
(and I'm sure many do).
I can't speak for Amazon, but at my employer, when a customer phones up or e-mails the customer service rep immediately sees certain details - number of orders by address, lifetime spend, spend in last 6 months, age of account and address, percentage refunds, fraud flags and so on.Needless to say, the more legitimate an account looks, the easier it is for them to get no-hassle refunds.
Having shipping patterns change especially to a ship forwarding sites is highly suspect. There are databases that can help flag these either done commercial or collected internally. I'm sure Amazon has a pretty extensive list.
I used to think the same of Netflix DVDs when I had the 5 out service. For the life of that subscription I had 2 never show up. I talked to the CSR and he assured me they keep track of these things.
Amazon is one of the best companies in the world . I've been buying physical books from them for the last 8 years. I've recently started buying audiobooks at Audible, and have even more recently purchased the new Kindle Paperwhite, and have been burning through many, many ebooks. The one time I had a problem with a physical shipment, they resent the book, no-questions-asked. From the looks of this thread, their customer service has stayed amazing.
My favorite Bezos quote, showing an approach that, over the long term, is amazingly profitable: "There are two types of companies: those that work hard to charge customers more, and those that work hard to charge customers less. Both approaches can work. We are firmly in the second camp."
By the way, I agree with the OP, asking a simple question to verify the credit card number would not hurt the customer service process, and would probably prevent some fraud.
http://stallman.org/amazon.html
He cites DRM, remote wiping of Kindles, sweatshop conditions in some shipping facilities, cutting off service to Wikileaks, squeezing small publishers, not paying enough UK taxes, and being a member of a right-wing lobbying group.
"One of the most pleasant companies in the world to do business with" isn't really anything to do with the morality of their backend operations.
http://www.rawstory.com/rs/2012/05/24/amazon-becomes-18th-co...
Not anymore, at least.
About the other stuff, it doesn't really impact me as an Amazon user. The only thing I'm interested in is them squeezing small publishers, because I do want to make sure I keep having good content... but so does Amazon, so I trust them to work it out. I don't mind if Amazon becomes a large publisher themselves, it'll probably work in my favor.
In general, almost everything Stallman cares about is uninteresting to me, and the few stuff I think he's "right" about I think he takes to extremes that are, frankly, crazy.
As long as it's convenient. Not all DRM is equal. Even though I backup my Amazon books DRM-free, I only do it because it happens automatically when I connect my kindle to my PC. But compare that to the DRM in many PC games or the Audio CD DRM we had a few years ago. I'd rather skip a game than getting one that requires me to be online to play it in single player.
That said, Amazon definitely has problems. E.g., how they treat employees:
http://www.motherjones.com/politics/2012/02/mac-mcclelland-f...
Every time I login to gmail over the web from anywhere but my personal computer, I take an (at most) 5 second pause while Google SMS's my cellphone and has me enter the 6 digit code. Failing that, in my wallet, I have a list of 12 Backup "Nuclear Codes" should I for some reason lose my iPhone and need to login to email in the intervening period while I get it replaced.
Trivial to implement, very secure.
There is even a Unix login module for adding it to SSH.
It worries me that "consumer friendly" customer service leaks information like this, that could potentially lead to my AWS account getting suspended while fraud is investigated.
I've got real live client sites which I haven't (yet) migrated important S3/Route53/EC2/CloudFront services out of the "I'll just try this out on my account to see if it'll work" setup.
Sure, it can protect your account, but it can't protect Amazon unless they force everyone to use it (which would obviously not be good for building customer loyalty.)
I'm sure Amazon know how much this sort of fraud is costing them. I'm sure they've calculated that it's worth the cost, at least for now. Shrinkage is just another cost of doing business.
They (and most good businesses) would prefer the majority of their customer base be able to get refunds and deal with order issues swiftly than have to jump through hoops to prove who they are. Certainly an SMS PIN or other authentication method would make it more secure, but there is no further customer benefit. The monetary loss to Amazon is basically a rounding error so why make things more complicated?
Citation? I've never heard of such a policy. Every mall I've had knowledge of had a very extensive security organization that was pretty effective at targeting shoplifters-in-action.
Depends on where you go and which mall. Strip malls are a lot less effective with countering shoplifters than the 'real' malls.
I also talked to a science-fiction / hobby store owner years ago, who mentioned that most of the shoplifters they caught had also been their best customers. (His policy was to ban them from the store, though.)
It's probably true that Amazon can still offer generally competitive prices despite scams like this; but in principle, I agree with the OP. And not necessarily because it would mean slightly lower prices for myself or slightly higher profits for Amazon; but simply because I dislike knowing that I'm complicit in the scam for the sake of my own convenience. Especially when that convenience means having an item re-shipped to a different address that I never used before, which happens to be the address to a 're-shipping' organization.
In Amazon's case it's also possible to argue that the cost of fraud, waste and loss is passed on to honest consumers in the form of overall lower prices.
Customer service policies like this are a significant part of what allowed Amazon to grow to be the company it is today, and Amazon has used that power (some would say abused it), to drive prices lower than they would otherwise have been on many items.
> Especially when that convenience means having an item re-shipped to a different address that I never used before,
I'm personally very glad that they allow this, having had to had a broken Kindle replaced whilst on holiday in a different country.
What would the negative repercussions of Amazon only shipping to the original verified shipping address have been - waiting a week to get your free replacement kindle?
I'd say it's ridiculous to re-ship to a different address based on an unverified claim of non-delivery; especially for high-cost items.
And as I read much more when I'm on holiday, and one of the reasons I bought a Kindle in the first place was so I didn't have to carry dozens of books on such a trip, I'm very glad that they were willing to ship it to not only a different address, but a different country.
It is. But Amazon is a ridiculous company that doesn't follow the rules of common sense. Amazon would rather lose a little (in the scheme of things) to fraud and continually amaze its customers than to stick it to thieves and Amazon customers. The customer is king.
It's especially genius with the Kindle because even if it's sent to a thief they will probably make money on it from the Amazon purchases of whoever ends up with it.
If these are two of a tiny handful of instances where this has ever happened, and there's many thousands of people who have had replacements shipped to alternate addresses (e.g. work, or a holiday location) then the cost of implementing additional checks for this - even if that's just the man-hour cost of asking additional questions - could be far more than the size of the loss.
And that's ignoring any less tangible customer experience angles - there's several people in this thread alone who have said they are more likely to buy from Amazon again as a result of this kind of customer service. I had to chase a missing order up last week, and the simplicity of the interaction was amazing compared to the hours (or even days) of battling I've had with some other internet businesses when things have gone wrong, and that definitely has at least some impact on my future decisions to use the respective companies.
Unfortunately, that's externalizing the real cost to the customer of having their account flagged as "possibly fraudulent".
Is the fact that they used a dot-email the weak link here, and what thankfully allowed you to catch on to the problem early?
If that is the case, why would an attacker use a dot-email, when they could just use any email.
Amazon lets you chat without signing in and you can claim to have any email address you want at that point, so it's tricky to say if this was intentional (hoping the reps were "dot blind") or if it was just a mistake/bad initial guess.
It might have figured that this would be an acceptable loss given that it can only be exploited once a year.
I ask because I live overseas and use a forwarding service quite a bit, but several smaller shops do flat refuse to ship to me, meaning I have to ship to my dad's and have him send it to my forwarding service, which ups the price a bit. And it's kinda frustrating, as I do have the address registered with my banks.
At least reading a story like this one explains to me a bit why things are the way they are.
But the response does indicate whether the numeric portion of the street address matched and whether the zip matched. The merchant can choose to reject the order based on this information. In our case, we accept the order if either matches.
Many merchants also are looking at the IP location from which the order was placed. Depending on the country it may raise enough red flags to reject the order.
Thats unfortunate that it causes you the hassle. But from the merchant's perspective, especially if they have been burned before, ship forwarding services are high risk.
Look at it this way. When you place your order, to the merchant, your IP will be from overseas, the credit card will be based in the US, and you are shipping to a ship forwarding facility. This is very typical of what fraud looks like with stolen US cards. The problem is that merchants bear the responsibility and chargebacks are a big problem, so they may not want to take the risk.
i recently bought something and first emailed the shop asking if it was ok, pointing them to my online existence (blog etc). i don't really know if it helped (but they shipped - according to fedex the box arrived in santiago at 3am this morning - may be here today :o).
i don't use a shipping service, but was wondering about doing so (because they have clearer fees - dhl at least, in my experience, adds random extra "customs charges"). i guess i should not bother trying that.
i use a "virtual credit card" (a one-off for internet use, generated by my bank's web page, with an upper limit that matches the price, short expiration date, and valid only for single use). i feel pretty safe using that, but i guess that just protects me, not the seller (although if you can tell someone is using one then i guess it is not a stolen card). recently i have started adding my postcode to shipping details (they exist in chile, but most people don't use them and it doesn't appear on my credit card bill). i do always ship to my billing address.
i don't know what else i can do. i really appreciate companies that do ship - the internal market here in chile is limited, so this is pretty much the only way to indulge when i want something unusual.
[one positive note - a chinese company called audiogd that makes electronics (hifi dac) gave really excellent service, letting me disassemble their hardware and return only a single logic board that was faulty, rather than the entire (heavy, expensive to ship) product. i wish there were some way to reward companies like that. http://www.audio-gd.com/En%20audio-gd.htm ]
Tiny bit of extra hassle for the user but is made up for by the fact that Amazon wouldn't need to bother asking any security questions to verify identity.
In the transcript, you'll see that the rep tries to offer a password reset before relenting and just giving the scammer every single order number for the past two months. Big mistake.
The "skip sign in" button is absolutely the vector being used to run these scams, and that's an incredibly good point. Though I can see there being some trouble for users who want a number to call off a packing slip without having to open the Amazon site to trigger the call first.
They then claimed that the original account was lost due to the e-mail address being "hacked" and that they needed the order numbers. They then used the order numbers to request a replacement using their new account.
You lost me.
So customer Andy Blogger has account ablogger@gmail.com.
Fraudster Bandy Logger creates account at Amazon using email address ab.logger@gmail.com and the verification email is sent to Andy's account (as gmail is dot blind in email addresses).
How does fraudster Bandy confirm ownership of the Amazon account so he can log in and change the accounts email address? Doesn't he have to create the account with the re-shippers postal address, then confirm the account with an email address they control, then change the email address to the one for the Gmail account ... doesn't that look pretty damn suspicious.
How about recording a short video on account creation, speaking/signing name or something similar. Then reps could confirm owner ship via video chat. Sure it would still be possible to abuse but would be a lot harder.
I see limited options available to amazon if they want to reduce fraud at the same time increase customer satisfaction.
One option would be for amazon to only ship the replacement to the address(es) that are on the account or better yet, only to the shipping address previously given with the order. But again it could happen that the customer recently moved and forgot to update the address while ordering. Also could be that the customer made a genuine mistake with his shipping details and want to change (say wanted it to ship to his new office instead of to his home).
Another option for them is to call the customer on his given phone numbers. Again, the customer could be traveling overseas.
So ultimately amazon has to decide and I feel the best option for them is to lose money instead of troubling genuine customers.
As long as fraud is sufficiently low, it's worth it for Amazon to be as open as possible.
As a Canadian shopper, the abuse of these shipping depots is a bit concerning to me, as I've used one of the depots mentioned in the post. These are such high volume shipping locations (to so many different addressees), I'm sure Amazon has shipped tonnes of orders to these locations and I'm wondering if they've investigated them before? These centers are very easy targets for abuse and I know Nike keeps a database of these addresses and blacklist them.
I'm not sure if they do it to prevent grey market exports or fraud, but (from a consumer perspective), I hope Amazon doesn't go this route.
Also interesting to know about gmail "dot blindness" - kind of like "plus addressing" you could use it to track who adds you to spam lists, by giving out different versions of your gmail address to different vendors (not that most people have time for that - I've never done this).
Plus addressing looks like this: myusername+whatever@gmail.com sends to myusername@gmail.com, but some site's email regex check do not allow this, so dot addressing could be used instead.
If you try to set it up today, it won't work.
I had a new notebook shipped to my house. It cost about $1600 new. The tracking information said it was delivered, so I hurried home to get it as I didn't want it on my doorstep. I get there, and no box. I checked the deck out back (where the UPS guy would sometimes leave things), and nothing. Crap.
So I call Dell, and after working with them for 20 minutes, I have a new replacement on the way. I basically had to "super pinky promise" that the notebook never really made it to me.
10 minutes later, my neighbor comes by and says "Hey, got a package for you!". Holy moly... I just social engineered the poor Indian lady at Dell. After a quick call back, the replacement is canceled.
To this day, I'm both shocked and very happy that Dell made it so easy. I like that they trusted me (a return customer) and tried to do the right thing. However, that trust is so easy to exploit.
I'm not sure what the answer is here. In this case, I can't blame amzn. I mean, they are trying to be helpful. How do you setup a system that's truly helpful w/o leaving wide gaps for scammers? Things like 2-factor auth, sms codes, etc will annoy most non techies (IMO).
I really hope this gets stopped - I'd rather not have Amazon's generosity thrown down the drain because of a few scammers.
Nope. They get hacked because the security question ask for a pet name, or a school name, or a friend name. Freaking easy. They get hacked because support gives information without authenticating people.And so on.
Dear companies, stop doing that. Thanks.
I just got an email from Amazon customer service asking if my recent customer serivce inquiry was handled satisfactory. I've not contacted Amazon or ordered from them in quite some time. So I wrote them and told them that (I also linked to this blog post on htmlist). Their reply:
> Thanks for bringing this to our attention.
> It looks like one of our customers mistyped his or her e-mail
> address when placing an order with us. You have not been
> charged for anything as you didn't order.
mistyped their email address? This seems unlikely to me, as my gmail address is pretty unique and not likely "near" other people's addresses. I dunno, feels suspicious to me.
In this case, having an established order and delivery history and then to have it shipped to reshipping is odd and should've raised a flag.
I'm sure Amazon's fraud system knows about that address. But maybe that flag is not exposed or given to the csrs. That particular one in Oregon is used fairly frequently by fraudsters. We've seen it a number of times among our merchants.
Whois information is archived basically permanently by many online databases. Changing it doesn't help anything - the old values are easy to find.
The cool thing about dealing locally is that you no longer have to wade through bureaucracy to get customer service - you can walk up to a flesh-and-blood person and talk to them face to face! And, unless they have masks from "Mission: Impossible" you'll be very, very difficult to spoof!
The only time I buy from local stores is when I absolutely must have it that day. And it looks like Amazon might even be doing that soon.
The inconvenience of going there is far outweighed by the benefits. Perhaps that's why they have survived in the era of Amazon and Best Buy! But I really really encourage people to actively search for local independent photog places (I mean, not Scammy's, er I mean Sammy's) if you take photography seriously at all, the premium is worth it.
I looked, but I couldn't justify the extra $350 at this time.
Reminds me of classifieds like "will sell for $100. Serious buyer will get $30 discount".
Local stores are not all the same, of course. Some, perhaps many, local stores don't deserve to survive. They are poorly run and perfectly willing to scam people who don't know the market price of stuff. But still I'm eager to at least try to work with them to avoid living in a world of nothing but enormous, monolithic corporations. Granted retail isn't exactly my favorite industry - I'd much rather support small makers of things - but I still try.
The only reason I can think for someone to like haggling is it lets them think THEY got a good deal, and makes them feel better about themselves. However, it is almost always in the interest, and benefit, of the seller if haggling has to be done (they have more information than you do, unless you're willing to spend a lot of time and effort).
Gas and milk, sure. But lots of people still buy clothes from places where haggling is acceptable.
That's presuming they even stock what I want, which they usually don't.
Could you give an example of something you bought local to you that was ~4 times the price of Amazon and broke soon after you purchase it? Presumably you got your money back; I wonder how the store is staying open if they have to refund all their customers.
It's definitely an interesting question, but it's clear he was just hunting and pecking, which is why he wanted all the order numbers from November and December... not sure if he initiated a few other chat sessions to figure out what was in each order and found a high-ticket item to pursue, or what, but it's a good question... I don't know what made me an initial target at all.
Interestingly enough, Amazon offers a "Tweet this purchase" option which I did NOT avail myself of, but which would definitely exacerbate this problem.
(Also, my name is Chris Cardinal. I don't know the scammer's name, but of course he couldn't request Amazon to change the shipping address AND the name for the replacement order. That would be a bridge too far.)
1) first chat session with Amazon support to claim that he lost access to his email and needs order #s (which is what you've tested out, and it works)
2) subsequent sessions from different accounts with various dot placements to inquire about the status of specific order #s
3) when a high-value item is found, sticking to the original dotted address, and asking for replacement
Is your mailing address available from public sources?