An unfamiliar order, changed delivery address or unexpected sign-in code can indicate account misuse, but it can also stem from another household user or a forged alert. Work from the actual Amazon account, not a support link in the message. Check orders and payment activity, secure the login and email, then review registered devices. If money moved, contact the funding institution through its own app. A password change alone may miss a still-registered device or a compromised email inbox.
Before you start
Use a trusted device that is not suspected of malware. Collect order numbers, shipping addresses, dates and any suspicious messages. If you share the account, ask other authorized household members without disclosing your new credentials. Do not send one-time sign-in codes to anyone claiming to be support.Do it step by step
- Open Your Orders and digital purchases on the correct Amazon marketplace. Mark each unfamiliar item, its status, address and payment method. Do not erase the records before contacting support.
- Open Login & security independently and change the password if that method is in use. Set up or review Two-Step Verification and the account's current passkey or code-based sign-in options. Check whether the email and phone number still belong to you.
- Secure the linked email account: update its password or MFA if exposed, review forwarding rules and recent logins, and remove unknown sessions. Recovery mail controlled by an intruder can undermine an Amazon-only password change.
- Review Manage Your Content and Devices. Deregister a device you no longer own or recognize after checking model and serial details. For a lost or stolen device, also use its platform's remote lock and review other signed-in apps.
- Contact Amazon Customer Service through the account about any unauthorized order or address change. Ask how to protect a pending shipment and preserve the case number. Coordinate with the card or bank for an actual charge.
- Monitor new orders, account changes and statements over the following days. Report impersonation calls or emails separately; attackers can exploit the case details to make a second scam seem authentic.