Amazon email redesign raises phishing concerns
Amazon’s simplified order confirmation emails are drawing scrutiny from cybersecurity specialists who warn that vague product descriptions could make phishing messages harder for shoppers to distinguish from genuine communications.
The redesigned emails replace specific product names and images with broad labels such as “Household item”, “Essentials item”, “Decor” or “Garden”. Customers must open Amazon’s app or website to discover exactly what has been ordered or shipped, a change the company says reduces the amount of personal information transmitted outside its own platforms.
Confusion over the system has grown as the classifications have sometimes appeared unrelated to purchases. Dan Landau, a 38-year-old marketing executive, ordered a portable photo printer but received an Amazon confirmation indicating that his “luggage” was coming. A separate purchase of pool-maintenance products was described under three different categories — “Decor”, “Outdoors” and “Garden”.
“The categories are very vague, and they seem to have little to do with what is actually being ordered,” Landau said.
Amazon customers have reported similar experiences since July, with detailed descriptions and product thumbnails disappearing from order messages and being replaced by generic classifications. Emails sent in June still commonly displayed the precise items purchased.
Amazon says the redesigned messages are intended to steer customers towards the “Your Orders” section of its app and website, where consolidated information about purchases and delivery status is available. The company also says reducing order information contained in email helps improve customer privacy by limiting data exposed outside Amazon-controlled services.
Cybersecurity specialists, however, say the trade-off could create another vulnerability. Genuine order emails traditionally gave shoppers an immediate way to recognise a legitimate purchase without clicking anything. Removing identifying details means customers who want to know what an email refers to may become accustomed to following links.
Arun Vishwanath, founder of the Cyber Hygiene Academy and an adviser to the US National Security Agency’s research-focused Science of Security and Privacy programme, said the approach could increase rather than reduce risk.
“It’s definitely not in the best interest of customers,” Vishwanath said. “If anything, it increases risk.”
Phishing campaigns commonly imitate legitimate corporate emails before directing recipients towards counterfeit websites designed to collect passwords, payment credentials or other personal information. Malicious links can also be used to deliver malware.
The problem is particularly significant for major online retailers because fraudulent order notices have long been among the most common impersonation tactics. Amazon-related scams frequently claim that an unfamiliar purchase has been made, that a delivery requires confirmation or that payment details must be updated.
Americans reported about $3.5 billion in losses from imposter scams during 2025. Amazon has also remained one of the businesses most frequently impersonated by fraudsters. Federal data for 2023 recorded roughly 34,000 reports involving scammers pretending to represent Amazon, placing it behind only Best Buy and its Geek Squad brand.
Amazon has argued that authentic communications remain identifiable and advises customers to verify purchases by opening its app or website directly rather than relying on links in messages. Legitimate communications can also be checked through the Message Centre within an Amazon account.
Security specialists nevertheless contend that changing the appearance and usefulness of legitimate messages can give criminals an opportunity. Erich Kron, a security awareness adviser at KnowBe4, said fraudsters commonly exploit periods when customers are adapting to unfamiliar formats.
“Anytime some change like this happens, bad actors are going to jump on it,” Kron said, adding that unfamiliarity can encourage mistakes.
The risk is greater on smartphones, where checking the actual destination behind a hyperlink is less straightforward than hovering over a link with a mouse on a desktop computer. Customers receiving a vague notice about an unidentified shipment could therefore click through simply to determine what is being delivered.
Another concern is credential reuse. Passwords obtained through counterfeit shopping pages can be tested automatically against banks, credit-card providers and other retailers through credential-stuffing attacks, potentially turning one compromised retail account into a wider financial-security problem.
There is no conclusive evidence so far that Amazon’s email redesign has produced an increase in phishing attacks. Abnormal AI, which develops artificial-intelligence-based email security systems, has not identified data establishing such a rise. Its assessment nevertheless indicates that the format could make imitation campaigns easier to construct.
Amazon has intensified efforts against impersonation fraud, including removing tens of thousands of phishing websites and fraudulent telephone numbers. The company says customers should never provide passwords, one-time authentication codes or payment information in response to unsolicited communications.
The redesigned emails replace specific product names and images with broad labels such as “Household item”, “Essentials item”, “Decor” or “Garden”. Customers must open Amazon’s app or website to discover exactly what has been ordered or shipped, a change the company says reduces the amount of personal information transmitted outside its own platforms.
Confusion over the system has grown as the classifications have sometimes appeared unrelated to purchases. Dan Landau, a 38-year-old marketing executive, ordered a portable photo printer but received an Amazon confirmation indicating that his “luggage” was coming. A separate purchase of pool-maintenance products was described under three different categories — “Decor”, “Outdoors” and “Garden”.
“The categories are very vague, and they seem to have little to do with what is actually being ordered,” Landau said.
Amazon customers have reported similar experiences since July, with detailed descriptions and product thumbnails disappearing from order messages and being replaced by generic classifications. Emails sent in June still commonly displayed the precise items purchased.
Amazon says the redesigned messages are intended to steer customers towards the “Your Orders” section of its app and website, where consolidated information about purchases and delivery status is available. The company also says reducing order information contained in email helps improve customer privacy by limiting data exposed outside Amazon-controlled services.
Cybersecurity specialists, however, say the trade-off could create another vulnerability. Genuine order emails traditionally gave shoppers an immediate way to recognise a legitimate purchase without clicking anything. Removing identifying details means customers who want to know what an email refers to may become accustomed to following links.
Arun Vishwanath, founder of the Cyber Hygiene Academy and an adviser to the US National Security Agency’s research-focused Science of Security and Privacy programme, said the approach could increase rather than reduce risk.
“It’s definitely not in the best interest of customers,” Vishwanath said. “If anything, it increases risk.”
Phishing campaigns commonly imitate legitimate corporate emails before directing recipients towards counterfeit websites designed to collect passwords, payment credentials or other personal information. Malicious links can also be used to deliver malware.
The problem is particularly significant for major online retailers because fraudulent order notices have long been among the most common impersonation tactics. Amazon-related scams frequently claim that an unfamiliar purchase has been made, that a delivery requires confirmation or that payment details must be updated.
Americans reported about $3.5 billion in losses from imposter scams during 2025. Amazon has also remained one of the businesses most frequently impersonated by fraudsters. Federal data for 2023 recorded roughly 34,000 reports involving scammers pretending to represent Amazon, placing it behind only Best Buy and its Geek Squad brand.
Amazon has argued that authentic communications remain identifiable and advises customers to verify purchases by opening its app or website directly rather than relying on links in messages. Legitimate communications can also be checked through the Message Centre within an Amazon account.
Security specialists nevertheless contend that changing the appearance and usefulness of legitimate messages can give criminals an opportunity. Erich Kron, a security awareness adviser at KnowBe4, said fraudsters commonly exploit periods when customers are adapting to unfamiliar formats.
“Anytime some change like this happens, bad actors are going to jump on it,” Kron said, adding that unfamiliarity can encourage mistakes.
The risk is greater on smartphones, where checking the actual destination behind a hyperlink is less straightforward than hovering over a link with a mouse on a desktop computer. Customers receiving a vague notice about an unidentified shipment could therefore click through simply to determine what is being delivered.
Another concern is credential reuse. Passwords obtained through counterfeit shopping pages can be tested automatically against banks, credit-card providers and other retailers through credential-stuffing attacks, potentially turning one compromised retail account into a wider financial-security problem.
There is no conclusive evidence so far that Amazon’s email redesign has produced an increase in phishing attacks. Abnormal AI, which develops artificial-intelligence-based email security systems, has not identified data establishing such a rise. Its assessment nevertheless indicates that the format could make imitation campaigns easier to construct.
Amazon has intensified efforts against impersonation fraud, including removing tens of thousands of phishing websites and fraudulent telephone numbers. The company says customers should never provide passwords, one-time authentication codes or payment information in response to unsolicited communications.