{"success":true,"data":{"id":"amazon-account-verify-cross-domain","label":"Fake Amazon account-verification notice sent from a non-Amazon domain claiming the order or login was flagged and access will be suspended unless identity is verified via the embedded link — credential-harvest cross-domain phish. Real Amazon security mail originates from amazon.com / amazon.<cctld> only.","description":"Fake Amazon account-verification, suspicious-order, or \"your account has been put on hold\" notice sent from a non-Amazon sending domain (From / Reply-To / link domains do not align with amazon.com / amazon.<cctld>) demanding the recipient click a verification link to confirm identity, restore ordering, or release a flagged order — credential-harvest and card-skim cross-domain phish. Real Amazon security communications originate exclusively from amazon.com / amazon.co.uk / amazon.de / etc. with DMARC-aligned signing; account verification always returns the user to amazon.com via the Amazon app or Your Account page — never to third-party domains. The cross-domain mismatch is the defining signal. Distinct from generic e-commerce-account-verification-phish — this targets the Amazon brand / order-on-hold / cross-domain From-link mismatch pretext. Detection: Amazon brand vocabulary (account on hold, verify identity, suspicious order) + sender or link domain ≠ amazon.<tld> + no DMARC alignment with Amazon infrastructure. Trash score: +5. Source: GC1-R31; APWG Amazon phishing tracker 2025; Amazon anti-phishing reporting guidance; FTC online-marketplace impostor advisory.","tier":"warning","category":"other","isThin":false}}