- September 1, 2026
- By admin
- Scams & Safety
If you sell on Amazon long enough, an amazon seller phishing email will land in your inbox that looks better than the real thing. Same logo, same typeface, a case number in the subject line, and a deadline that gives you 24 hours to act. I have been selling and consulting on Amazon for sixteen years, and the fakes have gotten good enough that I no longer trust my gut on them. I trust a checklist instead, and that is what this post is.
The single rule that protects you: never act inside the email. Open a new browser tab, type Seller Central in yourself, and see whether the same message is waiting for you there. If it is not in Seller Central, it did not come from Amazon.
What a seller phishing email is actually trying to get
Almost every one of these messages is after one of four things, and knowing which one you are looking at tells you how worried to be.
- Your Seller Central password and two-step code. The classic. A fake login page harvests both, and the attacker logs in while your code is still valid.
- Your bank deposit details. Less common but far more expensive. The goal is to change your disbursement account so your next payout lands somewhere else.
- Documents. Invoices, utility bills, a photo of your ID or a business licence. These get resold or used to open accounts in your name.
- A payment. An “appeal service”, a “reinstatement fee”, a “brand registry processing fee”. Amazon does not charge you to appeal anything.
The emotional lever is nearly always the same: urgency plus fear of losing the account. That is deliberate. Scared sellers click. I wrote about the wider pattern of pressure tactics in my running list of Amazon seller scams, and phishing is just the version that arrives by email instead of by phone.
The seven checks I run before I click anything
1. Check the sending domain, not the display name
The display name is free text; anyone can type “Amazon Seller Performance” into it. Expand the actual address. Legitimate Amazon mail comes from amazon.com and a small set of Amazon-owned domains. Anything with a hyphenated lookalike, an extra word, a country suffix you do not recognise, or a free mail provider is fake. A message from a gmail or outlook address claiming to be Seller Performance is not a close call.
2. Hover every link and read the real destination
On a desktop, hover and read the status bar. On a phone, long-press to preview. What matters is the domain immediately before the first single slash. Everything after that slash can say whatever the attacker wants it to say, including the word amazon. If the domain is not one you recognise, stop there.
3. Look for the message in Seller Central
This is the check that ends the argument. Genuine performance notifications, policy warnings and account notices appear in Seller Central under your account’s message or performance area. If the email claims a suspension and Seller Central shows a healthy account and no notification, the email is fake. Go directly, never through the link in the email.
4. Treat attachments as hostile
Amazon does not need you to open a document to read a policy notice. Spreadsheets and PDFs asking you to enable content, and zip files of any kind, get deleted. If you have already opened one, change your password from a different device and run a scan before you log in again.
5. Distrust the deadline
“Your account will be deactivated in 24 hours” is a pressure device. Real Amazon notices do have timelines, but those timelines are visible in your account, and nothing legitimate collapses because you took an hour to verify. Slowing down costs you nothing and is the whole defence.
6. Read it out loud
Phishing copy is often translated or assembled from templates. Odd capitalisation, “Dear Seller Partner”, a mismatched case number format, a signature block with no team name. None of these prove anything on their own, but two or three together should end the conversation.
7. Ask what it wants you to do
Log in via this link, confirm your bank details, send your ID, pay a fee, or reply with account information. Every one of those is a red flag on its own. Genuine Amazon workflows happen inside Seller Central, not in your inbox.
If you remember nothing else: Amazon never asks for your password, never asks you to move to a personal email address, and never charges a fee to reinstate an account.
The three fakes I see most often
The suspension notice
“Your selling privileges have been removed” with a link to “submit your plan of action”. The link goes to a cloned login page. Sellers who have had a real suspension in the past are the most likely to fall for it, because they recognise the shape of the message.
The deposit-details update
“We could not process your disbursement, please confirm your bank account.” Sometimes it arrives with a spoofed reply-to so your response goes to the attacker. If the payout is genuinely held, Seller Central will say so in your account.
The fake support call-back
An email with a phone number to call about an “urgent case”. You call, a very polite person walks you through “verifying” your account, and asks for the code that just arrived on your phone. Amazon support does not work by call-back numbers embedded in unsolicited email. I covered the phone version of this in the scam calls sellers can safely ignore.
What to do if you already clicked
- Change your Seller Central password immediately, from a device you trust, going to the site directly.
- Check and reset two-step verification, and remove any device or authenticator you do not recognise.
- Open your account settings and confirm the deposit bank account and the email addresses on file are still yours. Attackers often change the notification email first so you do not see the alerts.
- Review user permissions. If anyone has added a secondary user, remove it.
- Check for new or edited listings and any changes to shipping addresses or returns settings.
- Report the message to Amazon’s phishing reporting address and then delete it.
- If bank details were changed, contact your bank the same day. Time matters far more than paperwork here.
Hardening the account so a bad click is survivable
You will click a bad link eventually. Everyone does. The goal is that the click does not cost you the business.
- Use an authenticator app rather than SMS for two-step verification where you can. SIM-swap attacks are rare but not fiction.
- Use a password manager. The underrated benefit is not the strong password, it is that the manager refuses to autofill on a lookalike domain. It spots the fake before you do.
- Give every staff member their own Seller Central user with the narrowest permissions that let them do the job. Shared logins make it impossible to tell what happened afterwards.
- Keep an account-health routine. Ten minutes a week inside Seller Central, looking at notifications, deposit settings and user list, means you spot changes fast rather than at month end.
- Write down the rule for your team: nobody logs in from an email link, ever. That single sentence, agreed in advance, stops most of this.
Where phishing fits in the wider risk picture
Phishing is one symptom of a bigger structural issue: on Amazon, your business lives on someone else’s platform, and the account is a single point of failure. That is not a reason to quit; it is a reason to run the account like it can be taken away. The full argument, including what I would do differently if I were starting again, is in the scams and account-safety guide and in my book pages on this site.
If a term in this post is unfamiliar – plan of action, account health, disbursement – the Amazon seller terms glossary has plain-English definitions for the vocabulary Amazon uses in these notices. Knowing the real words makes the fake ones easier to spot.
The short version
Do not act inside the email. Verify inside Seller Central. Treat urgency as evidence of a scam rather than evidence of a problem. Turn on the boring protections – authenticator app, password manager, separate users – so that the day you do click something you should not have, it is an annoying afternoon instead of a lost business.
Before you act on any message claiming to be Amazon
Phishing works because it arrives when you are busy. A written checklist beats judgment under pressure:
- The Red-Flag Field Guide — the warning signs, in the order they usually appear.
- Invoice & Compliance Pack — document templates for when Amazon asks you to prove a supply chain is real.
- Complete Due-Diligence Kit — all of the working documents in one bundle.
Related reading: Amazon seller scams to watch out for. The legitimate software we do recommend — and its real URLs, worth knowing so a fake one stands out — is listed in the partner directory.
Disclosure: tool links below are affiliate links. If you buy through one we may earn a commission at no extra cost to you. Nobody paid for placement or for a kinder write-up.
Both books, no sales call
The fee math, the sourcing checklists and the exit plan — from sixteen years of running and fixing Amazon accounts.
Amazon Seller’s Pocket GuideWhy Not to Sell on AmazonBefore you pay anyone to run your account: Is Amazon FBA a scam? The pitches and the FTC cases
