Re anybody had this

Countries

Read only
Australia
Belgium
Brazil
Canada
Egypt
France
Germany
India
Italy
Japan
Mexico
Netherlands
Poland
Saudi Arabia
Singapore
Spain
Sweden
Turkey
United Arab Emirates
United Kingdom
United States
United Kingdom
imgSign in
user profile
Seller_4wvvlzteKjg62

Re anybody had this

Hello C…
You received this message because we are doing a security check. To prevent fraudulent activity, we need to open an investigation into this matter.Your account is not suspended, but in 48 hours after receiving this message, we reserve the right to suspend your account.
To confirm your identity, please copy the code below into your browser (in the address bar) and log in.
Copy the code WITHOUT SPACE, which is after “2E” (put the two groups together).
This is the code: vtp4%2E c%6Fm
Enter the code in your browser (Chrome, Mozilla, Safari) to confirm your account.
Please allow 2 hours for these actions to take effect.
We apologize for any inconvenience this may cause and thank you for your cooperation in reviewing this matter.
Thank you,
Amazon

1.1K views
27 replies
00
Reply
0 replies
user profile
Seller_7VbclcPFFRTnc

that looks extremely dodgy to me
anything in performance notifications ?

whats the email address its from ?

60
user profile
Seller_B3pYlmAHJFefl

Be careful,looks like a scam,maybe check with SS before doing anything.

00
user profile
Seller_Rds42gzScDQFa

Yeah right. As if Amazon don’t do enough to verify accounts. Delete delete delete.

00
user profile
Seller_4wvvlzteKjg62

Yep Deffo a Scam … Have had it verified by Amazon

Thanks for your replies

Al

20
user profile
Seller_LKjg1QRrO36Yq

I can’t see how copying a code from an email into ‘your browser (in the address bar)’ could possibly confirm your identity.
At best it might prove you received an email…

Copying something into the address bar sounds like an attempt to direct you to a malicious domain.

Was the email addressed to you by name or was it generic?

10
user profile
Seller_t8tPiUA5wff9m

Do you check the email it is from? It should show as something similar to
do-not-reply@amazon.co.uk

It should not look something like -
tic8yp5rm2jaluk-uczutm6mjjmraoye@googlegroups. com

In every email you get, Amazon or not, please look first at the address it is sent from.

00
user profile
Seller_BS5lg2keRs2QO

Out of curiosity, does anyone know why they split the code into two? I assume if they sent it as one string it’d get detected?

20
user profile
Seller_zhjiy4JuMEuyF

Being the nerd that I am, I can tell you those % bits are a way of smuggling characters through. When entered into an address bar they get translated.

%2E becomes a full stop

%6F becomes a lowercase o

So translate those two, remove the space in the middle and you have the URL it is trying to send you to (which I won’t type here).

Definitely a scam.

70