Amazon Prime Video Phishing Emails Target Users With Real IBANs

Cybercriminals are targeting Amazon Prime Video subscribers with a sophisticated phishing email featuring genuine IBANs. According to Signal-Arnaques, the fraudulent messages claim accounts have automatically renewed, tricking panicked recipients into clicking malicious links designed to steal credentials and banking data.

Data leaks in France are giving cybercriminals new tools to craft convincing financial scams. Phishing campaigns now incorporate personal details pulled from stolen databases to lower their victims’ guard.

Phishing Campaign Targets Amazon Prime Video Users With Real IBANs

According to the platform Signal-Arnaques, a deceptive email campaign is currently making the rounds among streaming subscribers. The messages are designed to trigger immediate panic by claiming that an Amazon Prime Video subscription has automatically renewed following a trial period. Recipients are urgently directed to click a Gérer mon abonnement button to cancel a supposed annual charge of 69.90 euros.

What sets this scheme apart from typical phishing efforts is the inclusion of the victim’s actual International Bank Account Number. When targets spot their genuine IBAN embedded within the warning email, the illusion of legitimacy shatters their skepticism, pushing them to act quickly to regularize their accounts.

Dark Web Data Breaches Fuel Targeted Social Engineering Attacks

The private banking identifiers used in these fraudulent emails likely originated from data thefts traded on the dark web. Specifically, the recent compromise of the Fichier des comptes bancaires (Ficoba) exposed more than one million banking records, including RIBs, IBANs, postal addresses, and other personal identifiers.

Security experts note that embedding authentic personal details transforms standard mass-mailing fraud into targeted phishing. As cybersecurity firm Kaspersky explains, criminals leverage stolen records by using the information they find to resort to social engineering techniques to create tailored attacks that trick the target into believing they are receiving legitimate emails and requests.

Dangers Behind the Malicious Links and How to Protect Your Account

Opening the link inside the fraudulent message exposes users to security risks. Cybercriminals use the landing page to harvest Amazon credentials, hijack banking information, enroll victims in unwanted subscription services, or infect devices with malware to harvest data for future attacks.

To avoid falling victim to these tailored schemes, security advisories recommend ignoring panic-driven prompts entirely. If a notification raises concerns, users should bypass email links completely and check their subscription status by logging directly into Amazon via the official website. Checking the sender’s email address also reveals red flags, as fraudulent messages frequently originate from domains that have no affiliation with official company addresses like @amazon.fr or @amazon.com.

Scammers target Amazon Prime customers with fake recall messages

Keep reading


Discover more from Archyworldys

Subscribe to get the latest posts sent to your email.