The Real Cost of an Amazon Takeover
Most account breaches cost you time: a locked social media profile, an awkward password reset, maybe a few spam messages sent to friends. An Amazon breach costs you money, and it costs it fast. Your account almost certainly has a saved credit card, a shipping address, and one-click ordering switched on by default. An attacker who gets past your password does not need to guess a card number or wait for anything to clear. They log in, they buy gift cards or high-resale electronics, and the charge is already processed before you have opened your email. Amazon's own fraud teams see this pattern constantly: gift cards first, because they are instant, untraceable, and resellable within the hour.
If you sell on Amazon, the exposure is worse. A compromised Seller Central login can redirect payout bank details, meaning the attacker is not spending your money, they are rerouting your revenue.
Amazon's two-factor system is called Two-Step Verification (2SV), and setting it up properly takes about three minutes. That is a small price for closing off the fastest, cheapest fraud vector attached to your name.
Where Amazon Hides Two-Step Verification
The setting is not on the main account page, it is one level into security settings, and Amazon has moved it around enough over the years that longtime users often assume it does not exist.
- Sign in and go to Account & Lists, then Login & Security.
- Re-enter your password if Amazon asks for it again.
- Scroll to Two-Step Verification (2SV) Settings and select Edit or Get Started.
- Choose Authenticator app when Amazon asks how you want to receive codes.
- Scan the QR code with Google Authenticator, Authy, Microsoft Authenticator, or any TOTP app, then type in the six-digit code it shows to confirm.
Amazon still requires you to register a backup phone number during this flow, even if you pick the app as your primary method. That is fine, a phone number as a last-resort fallback is reasonable. Just make sure it is a number tied to a plan you actually control, not a family member's phone or a number you plan to cancel. TOTP codes generated by an app never touch a cellular network, which is the entire reason they resist SIM swap attacks. Our article on SMS 2FA risk covers why phone-based codes are the weaker option industry wide, not just on Amazon. To confirm any authenticator secret is working correctly, you can paste it into our free TOTP code generator and compare the output.
Where Amazon's Trusted Device System Breaks Down
Amazon remembers devices you have already verified, so day to day you are not typing codes constantly. The problem shows up in households that share a single Amazon account, which is extremely common with Prime. Amazon Household lets multiple people share benefits, but the login itself is still one account with one 2SV setup. If your spouse or a grown child regularly signs in on their own laptop or phone, each of those becomes a trusted device attached to your security. If one of those devices is lost, sold without a factory reset, or simply used on public wifi at a coffee shop, it is now a soft entry point that bypasses the very authenticator app you set up.
The fix is not complicated but rarely gets done: periodically visit Login & Security and check which devices and browsers are listed as trusted. Deregister anything you do not recognize, anything belonging to a device you no longer own, and anything used by someone outside the household. Old Fire TV sticks and hand-me-down Kindles are the most commonly forgotten trusted devices, since people forget a smart TV even logs into Amazon at all.
Seller Central Is a Different Risk Profile
If you run a storefront, do not treat your seller login like a personal shopping account. Seller Central already enforces 2-step verification, and the authenticator app option is the right call there too, but the bigger risk is staff access. Multiple employees often share logins or have broad permissions that outlive their actual job duties. Review user permissions on a quarterly schedule, remove access the moment someone leaves the team, and never let a single shared password sit behind a single 2FA method that only one person controls. A seller account is closer to a business bank login than a shopping cart, and a takeover there means diverted payouts, not just a few fraudulent orders.
Amazon's Phishing Playbook
Amazon is consistently one of the most impersonated brands in phishing, precisely because almost everyone has an account and expects order emails regularly. The recurring templates:
- "Your order for an iPhone 15 Pro, $1,299.00, has shipped." You never placed it. The email wants a panicked click on a "cancel order" link that leads to a fake login page.
- "Your account has been locked due to unusual activity." Urgency plus a login button, a template used against nearly every major brand.
- "Update your payment information within 24 hours to avoid suspension."
The defense does not require technical skill, just a habit change: never log into Amazon by clicking a link in an email. Open the app directly or type amazon.com into your browser yourself. Genuine order issues always show up inside Your Orders when you check that way. For the broader pattern recognition skill set, our guide to spotting phishing walks through the tells that apply across every brand, not just Amazon.
Gift cards remain the single most common fraudulent purchase on a hijacked Amazon account. They deliver instantly, cannot be reversed, and resell easily. A gift card receipt you did not generate is the clearest signal something is already wrong.
Recovering When You Lose Access
If your phone with the authenticator app is lost, stolen, or wiped, use the backup phone number you registered during 2SV setup to sign back in, then immediately add the authenticator app to your new device. If both the phone and the backup number are gone, Amazon has an identity verification recovery process, but expect it to take days rather than minutes, since Amazon has to confirm you are really the account owner without either of your usual proofs. This is exactly why keeping your recovery phone number current, and not a number you plan to drop next month, matters more on Amazon than on almost any other service. Our post on losing your 2FA device has a broader prevention checklist worth reading before it happens, not after.
One Setting Almost Nobody Checks
Beyond 2SV itself, Amazon lets you see and remove saved payment methods one by one under Login & Security and the payments section. Most people accumulate expired cards, an old work card, or a card tied to a canceled bank account over the years and never clean it up. Every stored card is a potential charge target if your account is ever breached through some method other than password guessing, such as a compromised email account used for a password reset. Trimming your saved cards down to the one or two you actually use limits the blast radius even if 2FA is somehow bypassed. It is a five-minute task that almost no security guide mentions, because it has nothing to do with passwords or codes, it is just inventory control on your own financial exposure.
If your Amazon password is reused anywhere else, rotate it now using our password generator, since credential stuffing attacks specifically target reused passwords from unrelated breaches.
Frequently Asked Questions
Will Amazon ask for a code on every single purchase?
No. Once a device is marked trusted, everyday shopping proceeds normally. Codes appear for new devices, new browsers, or logins that look unusual to Amazon's fraud systems.
Does 2SV protect Prime Video, Kindle, and Alexa too?
Yes, since all of those sit under one Amazon login. Two-Step Verification protects the whole account, including any device already signed in under it.
I run a seller account. What is different for me?
Seller Central already requires 2-step verification, so your job is choosing the authenticator app method and locking down staff permissions, since payout redirection is the real risk on a business account, not gift card fraud.
What happens if I lose my phone and my backup number is also outdated?
Amazon runs an identity verification recovery flow, but it is slow by design, since it has to confirm ownership without your usual proofs. Keeping your backup phone number current avoids ever needing this path.
Can I use the same authenticator app for Amazon and my other accounts?
Yes. TOTP is an open standard, so Amazon sits in the same app as Gmail, PayPal, or anything else, with no per-service app required.