Amazing that the scammer is even able to have the fraudulent replacement item sent to a different address than where the order was originally sent not once, but twice and an address not associated with the account nor confirmed/verified and could possibly be linked to multiple accounts.
Seems like a blatant oversight in loss prevention and fraudulent data sifting. Not only does it admit that an account has been compromised in some shape (socially most likely), but it disappointingly shows incompetence in Amazon CSRs.