"Your Amazon package could not be delivered": is that text a scam?
If you typed in a password, change it immediately and turn on two-step verification. If you entered card details, contact your card issuer using the number on the back of the card.
A delivery failure, a pending refund, or an order you don't recognize – here's how to check an Amazon message without exposing your account or your card.
Fake Amazon notifications work by imitating routine, believable events: a package that couldn't be delivered, an order you don't recall making, a refund that's supposedly pending, or a product recall asking you to confirm your payment details. The message can arrive by text, email, phone call, a messaging app, or even a browser notification. The destination is what varies: sometimes a copied sign-in page designed to steal your password, sometimes a form asking for a small "redelivery fee," sometimes a phone number answered by a fake support agent walking you through a "cancellation." Amazon's own guidance is blunt: verify suspicious communications independently, never through the link or number in the message itself.
The scam doesn't need a real order to exist. It only needs enough people to have an Amazon account that a plausible-sounding message reaches someone who's actually expecting a package. That's why these messages are sent in bulk rather than targeted at anyone in particular.
Because Amazon is used by so many households for both everyday purchases and subscriptions, almost any household will have something plausible going on at any given time – a delivery in transit, a recent purchase, a subscription renewal – which is exactly what makes a generic "there's a problem with your order" message land convincingly even when it's sent to millions of people at once.
The most common versions
Several variations show up repeatedly. "We couldn't deliver your package" asks for a small payment to redeliver it: the low amount is designed to feel too minor to be worth questioning. "Your refund is pending" asks you to "verify" a bank account or card; a genuine refund is always visible directly inside your order history, not something that requires you to submit new payment details by email. "An order was placed on your account" comes with a fake invoice for an expensive item and a "cancellation" phone number: the person who answers asks for passwords, verification codes, or remote-access software rather than actually canceling anything. "A recalled product qualifies for a refund" uses safety concerns as the urgency hook instead of a delivery problem.
How to verify safely
Close the message and open the official Amazon app, or type the address into your browser manually rather than tapping any link. Check Your Orders and Returns, the Message Center, in-app notifications, and your actual card or bank statement. If the order, charge, or refund the message describes doesn't show up anywhere in your real account, there's nothing to act on – don't fill out an external form just to be safe.
Warning signs
- A misspelled or oddly extended domain, or a shortened link hiding the real destination
- Pressure to act immediately, or a threat that the order will be cancelled
- A request for a one-time passcode, gift cards, cryptocurrency, or remote-access software
- A phone number that doesn't match Amazon's official support channels
Keep in mind that logos, sender names, and even the visual layout of an email can be copied convincingly, and caller ID on a phone call can be spoofed too – none of that is proof the message is genuine.
It also helps to remember that the destination matters more than the wrapper. A message can arrive through a completely ordinary-looking text thread, sit alongside genuine notifications, and still lead to a form that has nothing to do with Amazon. The channel a message arrives through is not a signal of legitimacy – only what happens after you open the linked page is.
If you already clicked
If you didn't enter any information, close the page and check your device for unexpected downloads or browser extensions. If you typed in a password, change it immediately and turn on two-step verification. If you entered card details, contact your card issuer using the number on the back of the card (not one from the message) and watch your statement closely. If you installed anything described as "support" or "remote access" software, disconnect the device from the internet and remove it as soon as possible.
Where to report it
Amazon has an official process for reporting suspicious emails, texts, calls, and websites that impersonate the company. It's also worth reporting the message as phishing directly to your email or mobile provider. If you lost money, contact your payment provider first and then file a report with local law enforcement: the faster you act, the better the odds of stopping or reversing a payment. Reporting the message even when you didn't fall for it still helps, since it feeds the pattern data that email and mobile providers use to filter similar messages for other people.
Variants you'll run into beyond email and text
The classic delivery text is only one delivery channel. The same script now arrives through several doors, and recognizing the pattern matters more than memorizing any single message. A phone call from "Amazon security" tells you someone bought an iPhone on your account and offers to "block the charge": the caller then asks you to read back a verification code that actually resets your password. A WhatsApp or SMS message offers part-time work "rating Amazon products," which starts with small payouts and ends with you depositing your own money into a fake task platform. A browser pop-up that appears while you're shopping claims you've won a "loyalty reward" – a free gadget for the cost of shipping – and harvests your card number through the shipping form.
Two quieter variants deserve special attention. The first is the brushing scam: a package you never ordered arrives at your door, sometimes with a QR code inside inviting you to "find out who sent this" or claim a gift. Scanning it leads to a phishing page; the package itself exists so a seller can post fake verified reviews in your name. You can keep the item, but never scan the code. The second is the fake Prime renewal call, where a recorded voice says your membership will renew at an inflated price and invites you to press a number to cancel. Pressing connects you to a live scammer whose real goal is remote access to your computer or your banking app.
How it plays out: a realistic example
Consider Ruth, 63, who is genuinely waiting on a birthday gift she ordered three days ago. A text arrives: "Amazon: your package is held at our facility due to an incomplete address. Confirm within 24 hours or it will be returned." The timing feels right, so she taps the link. The page looks exactly like Amazon's – logo, fonts, even a fake order number. It asks her to confirm her address, then requests $1.99 for "address verification." She enters her card details. Nothing dramatic happens, which is the point: she gets a "confirmed" screen and goes about her day.
Two days later there's a $487 charge from a merchant she's never heard of, and a genuine Amazon email about a sign-in attempt from an unknown device, because she reused her password on the phishing page. She spends the next week disputing the charge, changing passwords, and setting up two-step verification she wishes she'd had all along. The lesson: the scam never asked her for much, because $1.99 wasn't the prize. Her card number and password were. Any message that routes a payment or a login through its own link – rather than through the app she already has – deserves a hard stop, no matter how well-timed it feels.
Prevention habits that close the door
Beyond spotting individual fakes, a few one-time changes make this entire scam category much harder to land. Turn on two-step verification in your Amazon account today, under Login & Security – with it enabled, a stolen password alone can't open your account. While you're in settings, review the list of devices signed in to your account and remove any you don't recognize, and use a password on Amazon that you don't use anywhere else, so a leak elsewhere can't be replayed against your orders and saved cards.
Change how delivery information reaches you. If notifications only ever come from the official app, every delivery text becomes automatically suspicious: you no longer have to judge each one on its merits. Enable shipment notifications in the app, treat any SMS about a package as noise, and consider a virtual card number for online shopping if your bank offers one.
Finally, extend the protection to the people around you. The relatives most likely to be caught are often the ones who shop on Amazon occasionally, don't use the app, and would genuinely worry about a blocked delivery. Agree on a simple family rule that's easy to remember under pressure: no one ever pays a fee or enters a password from a message – orders are only ever checked inside the app. Helping a parent enable two-step verification takes ten minutes and removes the worst outcome of a moment's distraction.
Quick checklist
- Never pay a "redelivery fee" through a link in a text message
- Check refunds and orders inside the official Amazon app, not through the message
- Don't call a "cancellation" number listed in a suspicious invoice
- Treat requests for passcodes, gift cards, or remote access as a hard stop
- Report suspicious messages to Amazon and your email/mobile provider
Frequently asked questions
Does Amazon charge a redelivery fee through a text link?
Can a scam email contain my real name or order details?
Should I call the cancellation number listed in the invoice?
Daniel A. and Óscar S. run Breachfolio, a small independent site about security and AI. This article was drafted with AI assistance and reviewed by a person before it went live. We write from documentation, vendor sources and published research rather than from original lab benchmarks, and we link a source in the sentence that relies on it. How we work · About us
