Decoding the world of cybersecurity

One in 16 new Amazon domains flagged as Prime Day approaches

Check Point Research says 6.5% of newly registered Amazon and Prime Day-related domains in September were malicious or suspicious as attacks against financial and consumer-facing organisations also increased.

One in 16 new Amazon domains flagged as Prime Day approaches
Summary
  • Check Point classified 6.5% of new Amazon and Prime Day-related domains registered in September as malicious or suspicious.
  • Amazon-related registrations rose 42% from July and 37% year on year ahead of Prime Big Deal Days.
  • Financial services organisations averaged 2,650 weekly attacks in September, while consumer goods and services organisations averaged 2,578.

One in 16 newly registered Amazon and Prime Day-related domains identified during September was malicious or suspicious, according to research published ahead of Amazon’s Prime Big Deal Days on 6 and 7 October.

Check Point Research recorded 1,284 new Amazon and Prime Day-related domains during September, up from 905 in July. The increase represents 42% growth over two months and 37% compared with September 2025.

Its ThreatCloud system classified 6.5% of the September registrations as malicious or suspicious, while researchers also identified counterfeit Amazon login pages targeting users in several countries, including the UK.

Separate clusters of similarly constructed shopping domains showed how attackers can register groups of sites around the same retail event rather than relying on a single page. The examples analysed by Check Point were designed to steal Amazon credentials, payment information or personal data rather than compromise Amazon’s own infrastructure.

Prime Big Deal Days creates predictable conditions for impersonation because a large volume of genuine logins, payment activity, order confirmations and delivery messages arrives within a short period. Fraudulent communication can therefore appear among transactions and notifications that customers already expect to receive.

Generative AI is reducing the value of some traditional warning signs. Attackers can produce grammatical, localised messages and convincing web copy quickly, making poor spelling or unusual phrasing less dependable as a way to distinguish legitimate communication from impersonation.

The infrastructure can also be replaced rapidly. Once a fraudulent domain is blocked, another registration can reproduce similar branding and content without requiring the attacker to rebuild a complex technical platform.

Check Point’s telemetry indicates that the enterprise exposure extends beyond Amazon-themed pages. Financial services organisations averaged 2,650 cyberattacks per organisation each week during September, an increase of 66% from the same month last year.

Organisations in consumer goods and services recorded an average of 2,578 weekly attacks, up 52% year on year. Both sectors sit close to the transaction flow created by a major online shopping event, covering payment processing, retail operations and customer-facing systems.

Those sector figures should not be interpreted as thousands of Prime Day-specific attacks against every bank or retailer. They measure broader attack activity recorded by Check Point and provide context showing that financial and consumer-facing organisations are already operating under elevated pressure.

The domain statistics also reflect Check Point’s own classification systems. A designation of malicious or suspicious is an intelligence assessment rather than a count of websites proven through criminal proceedings to have caused harm.

Even with those qualifications, the registration trend illustrates the low cost of building infrastructure around a recognised consumer brand. Attackers can use multiple domains simultaneously, abandon them when blocked and move victims through new pages while retaining the same underlying fraud model.

The effects can spread beyond the brand being impersonated. Stolen card information may involve issuing banks and payment processors, while compromised Amazon credentials can be combined with personal information obtained elsewhere to support account takeover or subsequent phishing.

Retail events therefore concentrate work across several defensive layers at once. Fraud teams monitor transactions, security teams track impersonation infrastructure and identity systems have to distinguish legitimate customers from attackers attempting to reuse stolen credentials.

Because much of the malicious infrastructure is registered before the sales event begins, the campaign cycle does not start when Prime Big Deal Days opens on 6 October. Check Point’s September data shows preparations taking place weeks in advance while organisations are still building the legitimate marketing activity that attackers intend to imitate.

The resulting overlap between genuine seasonal traffic and malicious infrastructure gives attackers cover in volume rather than requiring a particularly novel technical method.

×