Live data from Hacker News

Amazon orders subject to replacement fraud (still)

gmcbay.com

11–20 of 91 posts

Re: Amazon orders subject to replacement fraud (still)

#11
George, do you have any domains with your whois/registrar information matching your Amazon account information? I guessed that was the vector they used to attack me. I had several domains with my home address as my address, along with my email and name. Voila. The entire triangle of data the CSRs need.

I was able to get a CSR to show me some of the logs of the chats with the scammer, which was particularly enlightening:

http://www.htmlist.com/rants/two-for-one-amazon-coms-sociall... (Thanks also for linking to my post in your article. It's insane this is still going on.)

Re: Amazon orders subject to replacement fraud (still)

#14
Here's a working hypothesis:

| Why is Amazon's security for replacement orders so lax?

Amazon values customer satisfiction above their fraud write-off.

| Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to?

Because the time between ordering an item, and defect can be sufficiently large to cover moves: people shift around all the time. It's entirely concievable you'd like to exercise replacement rights from Texas, even though you've ordered it from NY.

| How did the scammer know about my order in the first place to social engineer the replacement request?

Via: either buying order requests, using third-party honeypots to capture your info, using the domain registrar, or a combination of any of these.

| Why haven't Amazon black-listed the 13820 NE Airport Way; Portland, Oregon address as a destination for replacements? This package drop address shows up again and again when you Google around for people who have been hit by Amazon scams.

I suspect this might be http://reship.com/ (Alexa rank: 166K). This is entirely legit: if you're a UK customer who'd like to buy stuff that are exclusively US-only, reshippers are the cheapest way to do so. Based on their Alexa rank, I suspect Amazon makes quite a money on these customer segments. Blacklisting them also wouldn't help this case: reshipping companies can easily buy up a handful of different addresses in a range of cities, making this a game of whack-a-mole.

| Can I really trust this company to hold multiple credit card numbers of mine in their database, one click away from someone potentially ordering thousands of dollars of merchandise that they can apparently easily redirect to an address that should have been black-listed years ago, if there were any kind of sane security policy in place?

Note that no credit card, or password database has been compromised in executing this attack. This is social engineering corporate goodwill at it's vilest.

I suspect the root cause of this issue to be the friction-less execution of this engineering. A proper solution for this problem might be as simple as sending out an email with clickthrough-link-confirmation before replacement shipping; this would raise the bar from "knowing about an order" to "knowing about an order, and having an active compromise on the mark's inbox".

Re: Amazon orders subject to replacement fraud (still)

#15
post #14

Here's a working hypothesis: | Why is Amazon's security for replacement orders so lax? Amazon values customer satisfiction above their fraud write-off. | Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to? Because the time between ordering an item, and defect can be sufficiently large to cover moves: peo…

Certainly a confirmation email should be sent when the address is new

Re: Amazon orders subject to replacement fraud (still)

#16
post #14

Here's a working hypothesis: | Why is Amazon's security for replacement orders so lax? Amazon values customer satisfiction above their fraud write-off. | Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to? Because the time between ordering an item, and defect can be sufficiently large to cover moves: peo…

Because someone can argue that they don't have access to their email right now (on a trip or something). Or that the associated email has "been hacked".

Re: Amazon orders subject to replacement fraud (still)

#17
> Amazon is out quite a bit of product and a lot of trust from me.

The product is still a drop in the bucket for Amazon. Hopefully some of you actions will trigger their fraud protection dept. to blacklist the address or maybe they think it's not worthwhile blacklisting a whole address with multiple suites for a tiny amount. Anyway, I don't think it's reason enough to lose trust in Amazon. As long as they got the honest customer covered, it's OK to lose some when you are running a business of Amazon's scale.

As @sdrinf mentioned, it's social engineering at play. Maybe they can raise the bar to placing phone orders/replacements. Or maybe they think, they'll lose more business by adding a teeny hurdle than gain on fraud recovery.

A times B times C equals X. If X is less than... we don't care kind of thing (Fight Club recall reference)

Re: Amazon orders subject to replacement fraud (still)

#18
post #16
post #14

Here's a working hypothesis: | Why is Amazon's security for replacement orders so lax? Amazon values customer satisfiction above their fraud write-off. | Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to? Because the time between ordering an item, and defect can be sufficiently large to cover moves: peo…

Because someone can argue that they don't have access to their email right now (on a trip or something). Or that the associated email has "been hacked".

> email has "been hacked".

But that's probably a big reason to _not_ let the orders through.

Re: Amazon orders subject to replacement fraud (still)

#19
post #14

Here's a working hypothesis: | Why is Amazon's security for replacement orders so lax? Amazon values customer satisfiction above their fraud write-off. | Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to? Because the time between ordering an item, and defect can be sufficiently large to cover moves: peo…

> | How did the scammer know about my order in the first place to social engineer the replacement request? Via: either buying order requests

Looks like you can buy order requests from people who social engineered order numbers out of amazon reps via chat. A rep from amazon provided someone who didn't authenticate themselves amazon order numbers [1].

> using third-party honeypots to capture your info, using the domain registrar, or a combination of any of these.

But how does a "third-party honeypot" capture your activity on Amazon? What does a domain registrar have anything to do with placing orders on Amazon?

[1] http://www.htmlist.com/rants/two-for-one-amazon-coms-sociall...

Re: Amazon orders subject to replacement fraud (still)

#20
post #14

Here's a working hypothesis: | Why is Amazon's security for replacement orders so lax? Amazon values customer satisfiction above their fraud write-off. | Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to? Because the time between ordering an item, and defect can be sufficiently large to cover moves: peo…

I can't even imagine the justification in a board meeting that allows for shrinkage on their scale for such an easy resolution.

To me, a simple resolution would be to escalate the "item not received," issue to a state side department (not in India, from what I'm understanding), track recent orders and customer interaction (super simple algorithm), and lastly and MOST importantly do not allow customer orders to be given out so freely with a verification of address and name (at least require an account pin or last 4 digits for the order in question).

If Amazon implemented at least these barriers, then the security of an account would fall where it should...back on the owner...not so easily be phished through Whois data, or just knowing someone has an Amazon account.

It's almost as if a black hat could use a phone book and tie names, with addresses and phone numbers and straight phish for data. This is just way too easy for fraud that the fact that it's Amazon is appalling.

Post reply on HN