Apparently someone managed to call Amazon's support, tricked and convinced them into changing my account's email, ordered something, and eventually proceeded to delete my entire account.
Now Amazon's support refuses to help me for data protection reasons 😂
Looks like it's enough to know someone's address to hijack their #amazon account.
Update: support refuses to help me via email, because they need me to call and confirm my postal address to prove my identity.
They don't even seem to realize this is exactly where the entire dilemma started 😩
Also I simply don't know the postal address the hijacker changed my account to.
Last but not least, they can't help because the account is now deleted. They sure do seem to still store a whole lot of data associated with it still, though.
@fribbledom that is fucked up!
@fribbledom What the hell? 😮
@fribbledom Shit. :(
@Anke That sums it up quite nicely in a four-letter word. I actually came up with another four-letter word first, but yeah 😆
@ckeen Probably not, because I can't prove my identity to them. They seem to ask me for the postal address the hijacker entered.
@fribbledom email bezos and you're ok!!! ahahaha that's shitty on so many levels, amazon really sucks
@fribbledom Egh, Amazon support.. if you keep drilling down, you may eventually find someone actually understands the issue.
(I had a terrible time trying to point out I'd like packages for me left only at *this* address, not a neighbor)
@fribbledom I hope you are in the UK and can flag that to the ICO.
If you are in europe your local data agency should be able to help.
Thats clearly a data breach and amazon will comply to the investigation if the ICO is involved.
@fribbledom obviously that sucks big time :/
@fribbledom hmm didn't Amazon offer 2FA? I had thought it would be overkill, but now i'm seriously considering it 🤔
@fribbledom Ok, that sucks. :(
@fribbledom Ouch! "Call and confirm your postal address"? As if that's as secret as your password?
It sounds like a good thing (relatively speaking) that Amazon deleted your account. At least the thief can't run up more charges on you. But how stupid can big companies be?
@fribbledom If you can confirm your real address they should still be able to check that it was the old address on the account before it was attacked.
This might help me right now, but I feel like that's just making the problem even worse:
It's bad enough they accept my current address as a valid form of authentication, but now even all my previous addresses suffice, too?!
@fribbledom I'm betting the attacker had something more than your address - perhaps date of birth (hmm cake...)? Maybe an order number/item? Still, you can't expect Amazon to fix their screwup without some proof of something!
@penguin42 I'm happy to prove my identity to them, but they're not even accepting a proper form of identification.
Instead they ask me questions only the hijacker would be able to answer at this point.
Heck, even an email to the original address would suffice to prove it... you know, like virtually every other service handles such situations.
@fribbledom I'm now very happy that I recently turned on 2FA with Amazon.
I wish I had useful advice to offer, but dealing with them is always "interesting."
@fribbledom Write a detailed blog post of rants and submit it to Hacker News, if it ever hits the front page you issue will be resolved soon. It seems to be one of the few effective ways to deal with companies from the Silicon Valley...
@fribbledom Just their address?! That's hopeless.
@tatey I'm still a bit in shock myself. Probably not much harm done eventually, but it really makes me question Amazon as a company to handle all kinds of sensitive personal data.
@fribbledom That's terrible. They should be able to avoid basic social engineering attacks like that! So sorry you're suffering from their lack of security.
@fribbledom this is a HUGE security issue and you should be loud about it
@61 Just to be clear: the account got deleted by the hijacker, not by Amazon themselves. Seems it's a useful tactic to further complicate things for the rightful account holder.
@fribbledom ugh that's terrible!! I'm so sorry you're going through this.
@fribbledom Amazon is a literal Nazi company, so the sooner you'd leave it, the better.
@fribbledom I'm curious, are you an Amazon Web Services customer? Because that greatly raises the stakes on your Amazon account.
@nelson No, I'm not. Not with this account, anyway.
@fribbledom in my experience you can get support to bypass almost every security check, I've only ever used it to recover my own account but still. Humans are almost always the biggest security flaw.
@fribbledom You should refute the charge on your card or PayPal.
@fribbledom Oh fuck that's what horrible.
I'm going to go make sure I have de-DRM'd copies of all my Kindle purchases now.
@fribbledom Holy cannoli, that's awful.
Re: amazon refusing to help you for data protection reasons.
About 15 years ago my Yahoo account was hijacked and used to defraud someone USD$2000. I filed an FBI report, but Yahoo wouldn't give me back access to the account, because I couldn't prove I was the owner.
They wanted me to tell them the birthdate I supplied when I first signed up. I never tell any online company my true birthdate, for ID theft concerns. Who knows what birthdate I used when I signed up 7 years earlier.
Server run by the main developers of the project It is not focused on any particular niche interest - everyone is welcome as long as you follow our code of conduct!