Amazon is making its order confirmation emails harder to trust, giving scammers another reason to make fake ones look legitimate.
Instead of showing shoppers the exact product they purchased, Amazon’s newer order emails can display only broad categories, forcing customers to open the Amazon app or website to view the actual order details.
An Amazon spokesperson told The Verge that the company made the change to simplify communications and reduce the amount of customer information shared outside its own channels. The Verge further pointed out that the move is tied to the company’s effort to prevent external AI shopping agents from accessing detailed purchase data via email.
But the privacy move also removes details customers may use to distinguish legitimate order confirmations from generic phishing emails, making it more important to verify messages directly through Amazon.
The paradox Amazon is trying to deal with
Rather than resisting AI, Amazon is bringing it more deeply into its shopping business with Alexa for Shopping, which helps customers discover products, compare options, and make purchasing decisions.
The distinction is that while Amazon is willing to use customer shopping data to power its own services, it is less willing to make that same data easily available to third-party AI agents.
That matters because the inbox is becoming another place where AI services can interpret purchase information. Google’s Gemini features, for example, can use information from connected services such as Gmail, subject to the user’s settings and permissions.
For Amazon, that could mean greater competition over who controls the shopping experience and the customer data it produces.
And Amazon is not alone in having this concern. Retailers are increasingly seeking to leverage AI-generated shopping traffic while keeping customers, transactions, and the resulting data on their own platforms, because that information can strengthen personalization, loyalty, and other aspects of the business.
That is the paradox behind Amazon’s email change: retailers want AI to help sell their products, but they do not necessarily want AI companies to own the customer relationship or get unrestricted access to the data generated by those purchases.
Must-read security coverage
- UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case
- Blackpoint Cyber vs. Arctic Wolf: Which MDR Solution is Right for You?
- How GitHub Is Securing the Software Supply Chain
- 8 Best Enterprise Password Managers
How the change could complicate phishing checks
At the same time, Amazon’s privacy move creates a security problem Amazon may not have intended.
Amazon’s newer messages can replace a product’s name and image with generic descriptions such as “Beauty item” or “Hardware item,” leaving customers with far less information in the email itself.
Specific order details can give customers a quick way to compare an email with something they recently purchased. If an Amazon email says exactly what was purchased, a customer can immediately make a mental comparison with their recent orders. If the message simply says that a generic household or personal-care item was ordered, there is much less to verify without opening Amazon separately.
The change could therefore make generic order-confirmation phishing emails harder to dismiss immediately. Amazon is already a frequent target for brand impersonation, although there is no evidence cited here that attackers are exploiting this particular email change.
Staying safe: what can be done
Scammers typically send broad, untargeted campaigns and may not know whether a recipient is genuinely expecting an Amazon delivery, so an unexpected order message should be treated with suspicion even if it looks convincing.
Users who want to investigate an email can also inspect its full headers, which can expose information about where the message actually came from.
It is also worth hovering over links before clicking them to see where they lead, while avoiding any messages that ask for passwords, payment information, or other sensitive details.
Finally, enabling multi-factor authentication on an Amazon account can limit the damage if a phishing attempt does succeed in stealing a password. And if an email is clearly fraudulent, users can report it to Amazon rather than simply deleting it, helping the company identify spoofed messages targeting its customers.