Amazon orders subject to replacement fraud (still)
gmcbay.com
gmcbay.com
I was able to get a CSR to show me some of the logs of the chats with the scammer, which was particularly enlightening:
http://www.htmlist.com/rants/two-for-one-amazon-coms-sociall... (Thanks also for linking to my post in your article. It's insane this is still going on.)
I've changed my Amazon email address as you suggested in your helpful email and hopefully that will be enough since I don't think it would be practical to try to put my mailing address back in the bottle at this point.
I usually put a legitimate address that's in the same city (and sometimes the same general area). Where I actually live is completely irrelevant wrt DNS and I can think of no reason to have it trivially available to anyone who can do a WHOIS.
While most registrars would be perfectly fine, I worry about the one that is willing to take the domain for themselves (for a domain not worth going to court over).
While not exactly what happened, I remember the case of the @N twitter account be stolen (https://medium.com/@N/how-i-lost-my-50-000-twitter-username-...), and wonder if having your actual information on the registration would help or hurt a situation like that.
They really need to train their customer reps better. Good customer service is not black and white, you can keep out the frauds and still offer excellent service.
http://socialengineered.blogspot.com/
Thank god. Less scum out there doing shit like this, the better.
| Why is Amazon's security for replacement orders so lax?
Amazon values customer satisfiction above their fraud write-off.
| Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to?
Because the time between ordering an item, and defect can be sufficiently large to cover moves: people shift around all the time. It's entirely concievable you'd like to exercise replacement rights from Texas, even though you've ordered it from NY.
| How did the scammer know about my order in the first place to social engineer the replacement request?
Via: either buying order requests, using third-party honeypots to capture your info, using the domain registrar, or a combination of any of these.
| Why haven't Amazon black-listed the 13820 NE Airport Way; Portland, Oregon address as a destination for replacements? This package drop address shows up again and again when you Google around for people who have been hit by Amazon scams.
I suspect this might be http://reship.com/ (Alexa rank: 166K). This is entirely legit: if you're a UK customer who'd like to buy stuff that are exclusively US-only, reshippers are the cheapest way to do so. Based on their Alexa rank, I suspect Amazon makes quite a money on these customer segments. Blacklisting them also wouldn't help this case: reshipping companies can easily buy up a handful of different addresses in a range of cities, making this a game of whack-a-mole.
| Can I really trust this company to hold multiple credit card numbers of mine in their database, one click away from someone potentially ordering thousands of dollars of merchandise that they can apparently easily redirect to an address that should have been black-listed years ago, if there were any kind of sane security policy in place?
Note that no credit card, or password database has been compromised in executing this attack. This is social engineering corporate goodwill at it's vilest.
I suspect the root cause of this issue to be the friction-less execution of this engineering. A proper solution for this problem might be as simple as sending out an email with clickthrough-link-confirmation before replacement shipping; this would raise the bar from "knowing about an order" to "knowing about an order, and having an active compromise on the mark's inbox".
For the record, I don't understand why Amazon keeps allowing this. It seems like it could be fixed without much of a hit on customer experience, and the fraud ultimately does cost all of us more, as they have to cover those costs through higher prices.
But that's probably a big reason to _not_ let the orders through.
I don't see why anyone cares if Amazon is liberal in replacements. So long they're not somehow hurting your account standing with Amazon, it's Amazon's choice.
My experience has been positive with Amazon and there has been situations where they've gone out of their way to make the customer happy. I'm fairly confident that a situation like yours can be resolved with Amazon over phone.
It's not Netflix you don't need to stream anything any crappy connection will do.
I find it hard to believe you're unable to check your email for weeks. Unless you don't want to but then don't complain at that time.
And believe it or not there are still people in this world that may only have an email address with their employer which they don't access regularly outside of work.
And now back to the original article:
We are only getting one of many parts of this story, for all we know the scammer perfectly told a sob story about ordering a gift for their grandson who they haven't seen in several years and will be visiting soon but it didn't arrive in time for their trip and now would like it sent directly to the grandson while they are visiting him so they can still see the joy their gift will bring him.
My point is I don't assume that Amazon isn't trying pretty hard to prevent this fraud, and I don't assume scammers aren't putting in quite a bit of work to commit it.
Looks like you can buy order requests from people who social engineered order numbers out of amazon reps via chat. A rep from amazon provided someone who didn't authenticate themselves amazon order numbers [1].
> using third-party honeypots to capture your info, using the domain registrar, or a combination of any of these.
But how does a "third-party honeypot" capture your activity on Amazon? What does a domain registrar have anything to do with placing orders on Amazon?
[1] http://www.htmlist.com/rants/two-for-one-amazon-coms-sociall...
See someone make a blog post on their site about buying an Xbox from Amazon. Get WHOIS data from registrar. Have name and address of person who purchased Xbox. Use details to request replacement
To me, a simple resolution would be to escalate the "item not received," issue to a state side department (not in India, from what I'm understanding), track recent orders and customer interaction (super simple algorithm), and lastly and MOST importantly do not allow customer orders to be given out so freely with a verification of address and name (at least require an account pin or last 4 digits for the order in question).
If Amazon implemented at least these barriers, then the security of an account would fall where it should...back on the owner...not so easily be phished through Whois data, or just knowing someone has an Amazon account.
It's almost as if a black hat could use a phone book and tie names, with addresses and phone numbers and straight phish for data. This is just way too easy for fraud that the fact that it's Amazon is appalling.
I do get this, and as an Amazon customer, I'm glad this is their stance overall, but on the other hand it seems like they could handle this situation more securely than they do. It seems to me that you could have some sane middle ground where you do no-questions asked replacements, but with some caveats like no ability to change the address the item is being sent to from the original order unless the person you are communicating with can prove they are the account owner.
Maybe have a sort of two-factor system where the CSR can mark the order as "replacement approved" but you have to login to your Amazon account and take some action (just click a confirm button or whatever) to actually send the order out. At least in that case you wouldn't get cases like mine where someone managed to pull a replacement order without (seemingly) ever having actually had access to my Amazon account.
I fail to see what the "security" issue is, other than Amazon choosing to lose some money on fraud. That's not a security issue to anyone outside of Amazon, and Amazon seems clear in their stance.
Edit: A much bigger problem is Amazon's use of OnTrac, which repeatedly fails to make deliveries. Even in downtown SF.
I doubt this is the case. I've had to place chargebacks against Amazon to get my money back for purchases that were not delivered due to Amazon screwing up and telling the vendor that the software key(s) were not purchased.
For anything software related, they offer no refunds even when they and/or their vendor screw up to the point the product is unusable.
I have noticed that there doesn't seem to be any category of items sold by 3rd parties with more fraud than software, although this doesn't sound like such a case.
What does Amazon do after you place a chargeback against them?
From what I can tell, Amazon failed to process the chargeback correctly on their end and the order doesn't show it was ever done on Amazon's end. I'm not really surprised.
The last email I got from them on the subject was that the software was now available like 3-4 days after the dispute ended. I didn't even bother to download it since I just got it elsewhere with the refunded $$.
However, I didn't do the chargeback until after 3 separate CSRs [including 1 from the vendor] all told me they wouldn't do a refund.
There may be a difference between how they treat physical and digital purchases then, because my experience (and the experience of vast numbers of internet commenters) is that Amazon will refund or replace a physical order with basically zero investigation.
Frequently with physical products Amazon is able to place the majority cost [they only lose out on their commission] of the refund onto the supplier. [e.g. If Amazon's fraud check fails to catch a fraudulent order, they push the cost of the chargeback onto the supplier if it is a FBA or MFN item. They also do this if their system screws up and merges multiple products onto the same ASIN even tho they are different colors or whatever.]
My guess is the vendor in this instance was large enough Amazon had to make a different deal where Amazon was the one eating the refunds if it was Amazon's error. The vendor blamed Amazon. Amazon couldn't even figure out I issued a chargeback and successfully disputed it for my money back.
the scammer just needed the name, email and billing address
associated with their accounts
Guess what, eBay just leaked 150 million names, emails and addresses. This will be a goldmine for scammers.http://www.businessinsider.com/amazon-replacement-fraud-2014...
A story I've been meaning to write for a while, but aligns well with this: I bought a kindle a while back, with the (kinda expensive) case because I knew I would break the screen if I didn't.
I broke the screen anyways (some badly aligned books in my bag I think). I sent a kinda annoyed email at amazon about how their case didn't seem to help me much.
The next morning somebody from Amazon called me, trying to help me out with seeing if they could fix the screen (reboot style things). I was fairly confident I destroyed the screen, but they offered to replace it for me for free if I sent them back the old one at their cost.
The issue was that I was heading off to Japan the day after (from France), and so it would be a bit complicated for me to go to the post office on a sunday night to send it off. Instead, they offered to just send me the replacement to my address in Japan, no questions asked.
At no point did I prove anything about my story, I could have walked away with 2 Kindles (granted, one is probably blacklisted now, if I put it online). They did know I had bought one recently (which let them get my phone number through my account), but still.
Amazon has some pretty great customer service, and honestly requiring "proof" would, although for a rational human being would seem normal, have caused me great grief and I would just think about my 300g brick that I used for all of 1 week.
Anyways, I like Amazon a lot more than I probably should and take any opportunity to tell this story. Fraud is the small cost to pay compared to the goodwill you end up with by trusting (or at least pretending to trust) your customers.
The wifi on the replacement Kindle stopped working though... been too lazy to figure out why though.
It's worth raising that within the first year, after that they stop doing free replacements.
I had a kindle break after about a year and a month and they still sent me a free replacement. My father had his break after 2 years of heavy use, called Amazon and they offered him a discounted price on the Paperwhite.
It seems to be mostly triggered by BT/Virgin Media routers here in the UK:
To give you an example: http://www.amazon.co.uk/forum/kindle?_encoding=UTF8&cdForum=...
Seems like a blatant oversight in loss prevention and fraudulent data sifting. Not only does it admit that an account has been compromised in some shape (socially most likely), but it disappointingly shows incompetence in Amazon CSRs.
The amount of goodwill I have towards Amazon because of that experience is tremendous. I took out Prime, and I look there first for everything now. I can absolutely see that being worth the shrinkage.
Years and years ago I ordered a few items, mostly DVDs. I got the items. Months later I get an email from Amazon customer service saying I owe them money from that order because I never paid for it. I said "huh?" I call customer service and I found out it was because there was a chargeback. I didn't do a chargeback so I was confused.
Eventually I figure it out because the CC number shows up on the invoice with the last 4 digits. I accidentally transposed the last 2 digits of my CC number. I combed through my CC statements and found out that I indeed wasn't ever charged for the original items. Apparently the card was valid and was charged even though it was someone else's card. That means they didn't even do the least bit of checking to see if the billing address was the same or even name.
I call up and told them what happened. They just were dumbfounded and confused about the whole situation and didn't know how to handle it. They just kept insisting I return the items and they'll give me a refund. I think she was confused as to what I was even trying to tell her since I received the items. I said I didn't want to return them and even if I did they were now used items. They said "what's the problem then?" I told them they THEY sent ME and email saying how I owe money. I wanted to take care of it. Well finally the customer service rep just took down my right CC number and presumably wrote it in as a note in the logs or something.
I was never charged for the order.
---
Even more years ago my college boyfriend told me that when he was like 17 him and his friends played some kinda "prank" where they ordered some expensive cameras shipped to the school and put in some fake name and credit card. Apparently according to him the cameras shipped. Kids freaked out they would get in trouble, they told a science teacher. Science teacher took care of it and called Amazon before the cameras arrived to say that it was just some kids messing around.
Perhaps Amazon didn't validate at all. Who the hell knows?
In any case, I've changed both my password and my email address on Amazon, so if they did have access to the account that should solve that issue for now. The whole situation has made me paranoid enough that I'm considering creating a locked-down custom VM used solely for Amazon shopping.
Another reason why it'd be a replacement is because you don't get charged anything directly. They're betting you see the $0.00 charge, no bank activity, and you'll just brush it off like it was just a glitch. Not only this, but half the people who do this aren't even 18 and they're just reading tutorials on forums for how to get free stuff by social engineering or "hacking."
Hopefully they take your Amazon history into account when figuring this sort of thing out because I've been a customer for a very long time and have spent an amount of money that would likely seem obscene (if I totalled it up) over the years.
But of course they won't. Your experience with them clearly demonstrates that reality. No leg of that octopus knows what any of the other legs are doing.
The other way around (his address, my bank details) also works without any further verification.
So I could basically just enter someone's bank details and hope the order ships to my anonymous forwarding address before they notice. The victim will then order her bank to refund the fraudulent direct debit transaction (thanks to SEPA she now has 13 months to file the request). Amazon will probably suspend the account but the perpetrator will obviously not care.
Even if it's less convenient (because not instantaneous) Amazon should be doing something similar to what PayPal does: transferring a few cents together with a verification code to the account for verification.
This scenario would hopefully only work if the account itself was compromised. But when looking at how overcredulous customer support seems to be it might well be possible to pull this off without actual access to the account.
Only difference is I'm in the US and charging it to a credit card of his. And a Prime account is not required (we recently split the difference on getting one). And if they're looking for fraud, that we have the same last name, and his billing address is about a mile away, could reassure them.
Verifying via a few cents is enormous in terms of ease-of-use. Holy crap, now I have to log into my bank and check transactions just to buy some stuff? No thanks.
And, I know this isn't great logic, but I hope Amazon does nothing like PayPal.
They never told me what happened but I suspect someone in this shop took the money and declared the laptop returned.
The product is still a drop in the bucket for Amazon. Hopefully some of you actions will trigger their fraud protection dept. to blacklist the address or maybe they think it's not worthwhile blacklisting a whole address with multiple suites for a tiny amount. Anyway, I don't think it's reason enough to lose trust in Amazon. As long as they got the honest customer covered, it's OK to lose some when you are running a business of Amazon's scale.
As @sdrinf mentioned, it's social engineering at play. Maybe they can raise the bar to placing phone orders/replacements. Or maybe they think, they'll lose more business by adding a teeny hurdle than gain on fraud recovery.
A times B times C equals X. If X is less than... we don't care kind of thing (Fight Club recall reference)
Amazon would have to be taking in huge amounts of losses due to fraud to consider killing off all these customers.
Hey! What the heck? I'm in the security industry and had no idea about this new "secure server software" and why is the TLA SSL? What the heck? I've been on vacation for the last week, when did it hit?
On a serious note, I understand that some security teams hire non-technical types into the team but it's always the responsibility of senior staff to make sure they are at least understanding the basics, especially when communicating with customers. Say it with me: Secure Sockets Layer (SSL). There's a credibility problem here somewhere.
Second, they were not defining the acronym. They're just stating they have software to help secure things, and as an side it's called SSL. They mention SSL because some users may have heard of this and it signals that Amazon's doing the right thing.
The CSRs are in India and basically told to satisfy any "did-not-arrive shipments". The fact that they are also willing to ship to an alternate address is completely insane. But my scammer told them they were "on vacation" and appealed to that side of the customer satisfaction coin.
Any time I have had a problem with an Amazon item, they have made it insanely easy, and cheap, for me to get a new one.
With the Kindle 2 (first one with the directional nub) the screen was VERY fragile. I used the official case but just putting it in my bag caused the screen to crack 3x in a year. When this would happen, I'd call Amazon and they'd have a new one on my doorstep the next morning. Then I'd use that box to send the old one back, no questions asked. Sure I could have been a fraudster and probably could have somehow kept 2 Kindles, but I appreciated the customer service.
[Aside: no I'm not just an idiot, the Kindle 2 really was that fragile. I've had a Kindle of every generation and never broken any other screen, but broke that one 3x].
"Amazon orders are still subject to replacement fraud"
There, I won't have to sit there and swap emphasis in my head until it makes sense with that one.
They probably don't have much use on a web page except to sound like a newspaper headline.
But.. yeah, I can see how that would be confusing as a lead-in.
Obviously I'm not going to link to a scam site, but you can get in through and read the articles through Google so you don't have to register with them. I saw this site with another Amazon scam where people were requesting refunds saying not shipped, etc.
If I click on a picture to view a larger version of it, I should not have to hunt around the page for a blue button to stop viewing the large image.
My site (which is woefully unfinished even for its originally intended purpose) is primarily used as a photo-blog showing photo albums to remote friends and family. This rant was the first text-heavy traditional blog-post I've made to it. I need to put some work into making the UI make sense for posts made in that context.
If you really want you can have someone stake out the home and see who comes, but that's really something for Amazon + the Police to do.
I'm not really interested in staking out the address these items to sent to, as mentioned I think it is just some sort of remailer service anyway so it wouldn't be useful unless the police could get a warrant to figure out where the redirected packages went to. I don't really care that much because Amazon is the one who lost out here financially, not me; but I still do feel a tiny bit violated that my account was used for this.
Basically the original Paperwhite had a wifi bug where in a presence of certain SSIDs it would crash the wifi driver and the wifi would stop working entirely. So I would ring up amazon,explain the situation, they would send me a new paperwhite, the same thing would happen, rinse&repeat. They never acknowledged that it's actually a bug in their software,they just kept sending me new paperwhites. After I got 4 of them, I finally managed to convince the person on the phone that sending me new paperwhites does not fix my problem, and they agreed to send me the new paperwhite 2 - which did indeed fix the problem. I was told explicitly that I don't have to send the old kindles back - but they are blocked from joining the Amazon network again, so you can only use them offline. Still, looks like a massive waste for Amazon,but I guess it's like nothing for them.