I spent a little quality time this week almost social engineering my way into a client's Amazon account.
(Social engineering requires deception, and I told the truth. But what happened was pretty close. Keep reading.)
When a client told me she'd had some unauthorized charges on her Amazon account that day, I jumped into security audit mode. But everything checked out. Did she call a phone number or click a link someone had e-mailed to her? No. Did she have a unique, strong, and unshared password? Yes. Two factor authentication (2FA) in place? Yes. Any unauthorized logins to her e-mail? No. We found no obvious attack path in the evidence available to us. She had already done several important things right: a unique password, 2FA, and no suspicious email sign-ins visible in the activity we could review.
What had happened: she noticed unusual purchase activity, tried to log in to check it, and couldn't. She called customer service. The rep verified her identity, changed her password, signed out all current sessions, and canceled the orders that had been placed. (Kudos to her for catching the purchase alert and acting quickly.)
There was also an e-mail in her inbox from Amazon with a verification code generated while the hack was happening. She didn't see that until later. When we reviewed her two-factor settings, we found an unfamiliar authenticator app enrolled. (An authenticator app works in place of a phone number as the second authentication factor.) That means somebody had created a key to unlock her account.
Curiouser and curiouser.
We changed her password again, signed out all current sessions again, and turned off 2FA so we could rebuild it from scratch. Those changes locked her account, so we called customer service. I described what had happened and asked for help unlocking the account. The rep asked for her e-mail address and phone number, then unlocked the account so we could set up 2FA again and...
Wait. Hang on.
The rep asked NO OTHER QUESTIONS that would establish the caller was my client. Her account had been locked after multiple security changes, but the rep unlocked it on an e-mail address and phone number alone! And because we had her password, we were able to log in as soon as the account was unlocked! 😱
What we'd just accomplished was very nearly "social engineering": tricking somebody into handing over information, or taking an action, that enables access to a target (NIST, n.d.). Technically, we hadn't social-engineered Amazon; we were legitimate callers telling the truth, so we hadn't tricked anybody, and trickery is part of the definition of social engineering. But that aside, we'd just seen how little information a deceptive caller would need to get her locked account unlocked.
I still don't know exactly how her account was accessed, given that her password didn't seem compromised, but what I do know for certain is this: on our call, the recovery step appeared to depend on an e-mail address, a phone number, and a password. That concerned me. Perhaps there were other checks behind the scenes, but the rep never mentioned them. A malicious caller who already had her password might have tried the same route.
Amazon later told my client that an unfamiliar phone number had called customer service and received support on her account shortly before the unauthorized activity. Amazon is now investigating. This doesn't prove that the call caused the compromise, but it strongly supports our suspicion that the human support channel was involved.
We're through the cybersecurity looking glass. Human ingenuity and AI enhancements make hacking and social exploitation easier than ever before.
YOU CAN GET HACKED EVEN IF YOUR SECURITY IS HARDENED.
We found no malware or obvious compromise on her computer or in the other accounts we reviewed. The controls we could verify were in place. But still, somebody on the other side had made a key. The human layer that may have allowed this wasn't under her control; when a human is social engineered, bad things can happen no matter how much security is in place.
So here's the both/and: you can do everything right and still get hacked, AND you can catch the hack quickly if you pay attention.
What caught this was a client who paid attention to her alerts and reacted swiftly.
So: PAY ATTENTION.
Here's your homework:
1. Investigate your 2FA settings. Check your banks, e-mails, Amazon, payroll, basically anything that matters. Open the security settings and look at every phone number, authenticator app, and recovery e-mail in the account. Look for anything that doesn't feel right. If you find anything you don't recognize, dig deep to figure out any compromised information, shore up your security settings, and boot all current sessions.
2. An Amazon verification code you didn't request is a red alert. The code arrived while this was happening, but she wasn't in her e-mail and saw it only later. Think about where security alerts land and whether you'll see them quickly. If you do find a code you didn't request, reset that password immediately and go check your other accounts. And follow the NCSC's step-by-step account-recovery guide.
3. Make sure your passwords are unique, strong, and unshared. Use a password manager that generates unique, strong passwords for each account. Don't reuse passwords, and don't share them with other people.
4. Use passkeys rather than passwords. If your site allows it, generate a passkey. You don't need to understand how it works; just know it's better than a password and easier to use.
5. Keep an eye on anything having to do with your finances. Check your purchase history regularly. Not just Amazon; check e-mail (for messages about your financial accounts), bank statements, credit cards, anywhere that has to do with money. Turn on transaction alerts from your credit cards. If anything feels fishy, go check it out immediately.
6. Look at it from the other side of the looking glass. Who on your team is a good target? If an employee could unlock an account, send money, or change the bank details on an invoice, train them up on how to prevent fraud. Decide what proof they should require and what procedures must be followed to verify a caller, write this down as an SOP, and make sure they know they'll have your support in following protocol if the caller gets annoyed. The 2026 DBIR describes attackers getting in "by impersonating help desk agents or users needing a password reset." Being unhelpful for sixty seconds is a legitimate security control that should be rewarded!
After you do this, hit reply and tell me about the changes you've implemented. I read every message.
(And if you need help reviewing your accounts or tightening your security, reach out. This is exactly the kind of thing I help with.)
