Here's a working hypothesis:
| Why is Amazon's security for replacement orders so lax?
Amazon values customer satisfiction above their fraud write-off.
| Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to?
Because the time between ordering an item, and defect can be sufficiently large to cover moves: people shift around all the time. It's entirely concievable you'd like to exercise replacement rights from Texas, even though you've ordered it from NY.
| How did the scammer know about my order in the first place to social engineer the replacement request?
Via: either buying order requests, using third-party honeypots to capture your info, using the domain registrar, or a combination of any of these.
| Why haven't Amazon black-listed the 13820 NE Airport Way; Portland, Oregon address as a destination for replacements? This package drop address shows up again and again when you Google around for people who have been hit by Amazon scams.
I suspect this might be http://reship.com/ (Alexa rank: 166K). This is entirely legit: if you're a UK customer who'd like to buy stuff that are exclusively US-only, reshippers are the cheapest way to do so. Based on their Alexa rank, I suspect Amazon makes quite a money on these customer segments. Blacklisting them also wouldn't help this case: reshipping companies can easily buy up a handful of different addresses in a range of cities, making this a game of whack-a-mole.
| Can I really trust this company to hold multiple credit card numbers of mine in their database, one click away from someone potentially ordering thousands of dollars of merchandise that they can apparently easily redirect to an address that should have been black-listed years ago, if there were any kind of sane security policy in place?
Note that no credit card, or password database has been compromised in executing this attack. This is social engineering corporate goodwill at it's vilest.
I suspect the root cause of this issue to be the friction-less execution of this engineering. A proper solution for this problem might be as simple as sending out an email with clickthrough-link-confirmation before replacement shipping; this would raise the bar from "knowing about an order" to "knowing about an order, and having an active compromise on the mark's inbox".