Business

Protecting an Amazon Seller Account From Phishing and Takeover

For most online sellers, the Seller Central login is the most valuable credential the business owns. It controls the listings, the inventory, the advertising budget and, most importantly, where the money goes when Amazon pays out. That makes it a target, and the attacks aimed at it have become harder to spot.

The good news is that most account takeovers are not sophisticated. They succeed because of a reused password, an email inbox with weak security, or a team member who shared one login with three other people. The steps below close those gaps without requiring a security team.

Why Seller Accounts Are Worth Stealing

A customer account gives an attacker a stored card and an order history. A seller account gives them a business. Once inside, an attacker can change the bank account that receives disbursements, alter listings, redirect advertising spend, or use the account’s reputation to run their own schemes until Amazon notices.

This is not theoretical. In a case that came to light through Amazon’s own filing in a UK court, attackers broke into around 100 seller accounts between May and October 2018 and diverted sales proceeds and loan funds to accounts they controlled. The method was spear phishing: messages convincing enough that sellers signed in through a link that captured their credentials.

Recognise How the Attacks Actually Arrive

Most attempts still start with a message. The common versions claim the account has been suspended, that a listing breaks a policy, that tax or banking information needs updating, or that a payment is on hold. Each one is built around urgency, because a seller who believes their income is at risk is more likely to click first and check later.

The quality of these messages has improved sharply. Security firm Guardio has said that 76% of phishing websites now use AI-generated content, which makes convincing copies of Amazon login pages cheap to produce at scale. Spelling mistakes and clumsy branding are no longer reliable warning signs.

The more dependable rule is procedural: never sign in through a link in a message. If an email says something is wrong, open a browser, type the Seller Central address directly, and check Account Health and the notifications there. If the problem is real, it will be visible inside the account.

Phone calls and messages from people claiming to be Amazon support follow the same logic. Amazon does not need your password or a verification code to help you, and nobody legitimate will ask for either.

Secure the Email Inbox Before Anything Else

The inbox tied to Seller Central is the master key. Password resets go there, verification messages go there, and Amazon’s notices about changes to the account go there. An attacker who controls that inbox can often take over everything else and quietly delete the warnings that would have alerted you.

Give that address a long, unique password, turn on two-step verification with an authenticator app rather than text messages, and review which devices and apps are signed in to it. Ideally, use an address reserved for the seller account alone, not one printed on invoices or used for supplier correspondence.

Use Two-Step Verification the Right Way

Seller Central requires two-step verification, but the method matters. Codes sent by text message can be intercepted through SIM swapping, where an attacker persuades a mobile carrier to move your number to a device they control. An authenticator app on a phone you keep with you is a stronger choice.

Keep backup methods current as well. A backup phone number belonging to a former employee, or a device nobody can find, becomes a serious problem the moment the primary method stops working.

Give Every Person Their Own Login

The most common weakness in growing seller businesses is a shared password. The founder, a virtual assistant, a freelance designer and an advertising contractor all use the same credentials, often passed around in a chat message. When that login is compromised, there is no way to tell who was the entry point, and no way to remove one person without changing access for everyone.

Seller Central user permissions solve this. Each person gets their own login, their own two-step verification, and access to only the sections their work requires. Someone managing advertising does not need to see or change deposit details. Someone uploading product images does not need reports that contain financial data.

The same rule applies to outside partners. Reputable agencies work through their own user accounts with permissions the brand owner grants, rather than asking for the owner’s password. ZonHack, an Amazon and Walmart store management agency, for example, accesses client accounts only through the user roles its clients set, and clients can change or revoke that access at any time. Any provider that asks for your primary login should be treated as a risk, however good their results look.

Finally, remove access when the work ends. Former staff and past contractors with live logins are among the easiest ways into an account, and among the easiest to fix.

Review Connected Apps and Integrations

Repricing tools, inventory software, review request tools and analytics dashboards often connect to Seller Central through authorised app access. Each connection is another door. Review the list of authorised applications regularly, remove anything no longer in use, and be cautious about tools from developers you cannot identify.

Watch the Settings That Move Money

Attackers who get in usually head for the same few places: the deposit method, the business contact details and the login email. Changing those lets them redirect payouts and cut the real owner off from notifications.

Check those settings on a fixed schedule, and treat any unexpected notice from Amazon about a change to banking or contact details as an emergency rather than an admin task. The time between a deposit change and the next disbursement is the window in which the damage can still be stopped.

Know What To Do in the First Hour

If you suspect a compromise, speed matters more than certainty. Sign in through a typed address, not a link. Change the Seller Central password and the email password, confirm that two-step verification still points to your own devices, and review the user list for accounts you did not create. Check the deposit method and recent listing changes, then open a case with Seller Support describing what you found.

Take screenshots before you change anything. If funds were redirected or listings altered, a clear record of what the settings looked like makes Amazon’s investigation faster.

Report emails that impersonate Amazon through the channels listed in Seller Central Help rather than simply deleting them. It helps Amazon identify and take down the pages behind them.

Make Security a Routine, Not a Reaction

None of these steps are complicated, and none of them require specialist software. What they require is consistency: unique passwords, proper two-step verification, individual logins with limited permissions, and a short monthly check of the settings that control money and access.

Sellers who get this right rarely notice the benefit, because the benefit is an ordinary month in which nothing happens. An account that has been locked down properly turns what could have been a costly, stressful incident into a phishing email that simply gets ignored.

Back to top button
Close