forumNew topic

Amazon seller account hacked and orders altered, what should we do in the first hour?

UUğurMember
Job title
Outdoor advertising
Organization type
regional distributor
Joined
Feb 2024
Message
94
#1

We are a small-scale limited company based in Germany selling home textiles and kitchenware. We do an average monthly marketplace turnover of around 45,000 EUR. When we logged into our seller dashboard this morning, we were met with a nightmare. A session was opened without triggering the two-factor authentication prompt at login, and we saw that our registered bank account details (IBAN) had been changed.

To make matters worse delivery addresses for about 14 pending orders placed over the last 12 hours appear to have been tampered with and redirected elsewhere. We immediately changed the password and reviewed authorized users, but we're still not sure if an unknown active session is lingering in the system.

We're in the first hour of this and want to take the right steps without panicking. What is the step-by-step process for account recovery, freezing payouts, and explaining the situation to customers?

HHavva K***MemberCommunity member
Joined
Jul 2024
Message
111
Most Helpful#2

Short answer: First, call seller support using the emergency security line to request an immediate freeze on the account and a complete halt to all financial transfers. Next, terminate all authorized sessions and external integrations, cancel any unfulfilled suspicious orders, and notify customers officially.

Timing is critical during account recovery. First, open an urgent case with the platform's security and account health team to get written confirmation that payouts to the newly added bank account have been frozen. Go to user permissions in the dashboard and completely revoke any secondary email addresses or external app authorizations (API tokens) added by the attackers as backdoors. Also, inspect your corporate email server to see if any hidden outbound forwarding rules were set up; hackers commonly set up filters to block incoming replies from seller support.

On the order and customer side, absolutely do not print shipping labels for the 14 modified orders, and instruct your logistics team to halt those packages. Contact customers directly through the seller dashboard in a professional tone, stating that address confirmation is required due to an internal technical issue. File an official complaint with the local police cybercrime unit (Cybercrime) to obtain a formal report; this document will be your most critical legal evidence in any disputes with the marketplace regarding withheld funds.

İİbrahim T***ExpertCommunity member
Joined
Mar 2025
Message
22
#3

Terminate all active sessions immediately. Clear browser cookies and reset passwords across all devices within the company. Delay the disbursement date in the payments tab to prevent automatic payouts from triggering.

EElif Y***Member
Job title
Site Manager
Sector
Media and publishing
Organization type
20-person company
Joined
Mar 2024
Message
5
#4

If two-factor authentication was bypassed, it's very likely session hijacking via stolen cookies. One of your PCs might be infected with malware. As long as someone accesses the dashboard from that machine, attackers can re-authenticate even if you change the password. Disconnect the primary PC used for logins from the network right now and wipe it.

NNuri Y***ExpertCommunity member
Joined
Oct 2023
Message
246
#5

We had a similar incident last year where 18,000 EUR was about to be transferred out of our account. We called support within the first 40 minutes and managed to stop the transfer. However, getting the suspended account fully reinstated took 11 days, which cost us roughly 15,000 EUR in lost revenue.

MMustafa Ç***Member
Job title
Clinic manager
Sector
Glass
Organization type
two-branch business
Joined
Oct 2022
Message
49
#6

Did any staff click on fake shipment tracking or invoice update emails over the last few days? They usually can't get direct access to these dashboards without a phishing attack.

KKübra Ö***Member
Job title
Front office accounting
Sector
Real estate
Organization type
two-branch business
Joined
Jul 2024
Message
155
#7

don't panic but act fast. first thing call the warehouse and stop those 14 packages from leaving otherwise u lose both the inventory and the cash.

YYasemin Ç***New memberCommunity member
Joined
Jun 2026
Message
88
#8

When something similar happened to us we noticed it in the middle of the night. The attackers had slashed prices in half, racked up hundreds of orders, and routed the money to their own accounts. We were sweating bullets until morning when we could call the bank and the platform. You're very lucky you caught it early; acting within the first hour makes all the difference.

EElif T***MemberCommunity member
Joined
Apr 2025
Message
343
#9

Take these three steps without delay: 1) Suspend financial payouts through the platform, 2) Cancel any manipulated orders in the system that haven't shipped yet, 3) Take a screenshot of the altered IBAN details and file a cybercrime report with the police.

SSultan T***Member
Job title
Social media manager
Sector
Insurance
Organization type
8-person team
Joined
Nov 2024
Message
19
#10

I wouldn't rush to make an announcement to customers just yet. If the attackers still have access to the system, they might see your messages and scam the buyers through different channels. Make sure you regain full control of the dashboard first.

KKübra M***Member
Job title
Accounting Manager
Sector
Consulting
Organization type
early-stage startup
Joined
Oct 2023
Message
140
#11

You're right. Start with a small trial; don't commit to everything at once.

Most time waste accumulates in tasks waiting for approval. If you have questions, write them; I'll answer as best I can.

OOsman Ş***Member
Job title
Call center representative
Sector
Printing
Organization type
medium-sized business
Joined
Feb 2025
Message
17
#12

my questions are cleared up thanks.

YYavuz S***MemberCommunity member
Joined
Jun 2025
Message
3
#13

You're right.

FFurkan A***Veteran
Job title
Supply chain manager
Sector
Education
Organization type
boutique agency
Joined
Oct 2023
Message
1
#14

You're right. Solutions that work at a small scale collapse when you grow; I learned this late.

Don't hesitate to ask; those who don't ask always pay more. If I were you, I'd go this route.

İİbrahim Y***Member
Job title
Marketing manager
Sector
Electrical-electronics
Organization type
20-person company
Joined
Nov 2023
Message
95
#15

There's one point I'm curious about. Most time waste accumulates in tasks waiting for approval.

When making a decision, first look at what data you have on hand. If you post the result here, it will help others too.

MMerve Ç***Member
Job title
Technical service technician
Sector
Automotive aftermarket
Organization type
family business
Joined
Nov 2024
Message
27
#16

There's also a measurement aspect to this. Don't rely on a single measure; go layer by layer.

Taking notes for two weeks yields better results than a six-month estimate. This is my opinion, I'm not claiming it's absolute truth.

LLeyla O***Member
Job title
Field sales representative
Sector
Paper
Organization type
boutique agency
Joined
Feb 2024
Message
21
#17

I went through the same thing two years ago. The real issue isn't the number, but what it's based on.

Good luck with that.

FFatihExpert
Job title
Chief Technology Officer
Joined
Jun 2023
Message
204
#18

I feel the same way. When making a decision, first look at what data you have on hand.

Most incidents start with a leaked password, not a vulnerability. If I were you, I'd go this route.

ZZerrin U***MemberCommunity member
Joined
Oct 2024
Message
3
#19

Let's separate the concepts, they're getting mixed up. Don't hesitate to ask; those who don't ask always pay more.

Good luck with that.

İİsmail E***Member
Job title
Logistics planning
Sector
Energy
Organization type
medium-sized business
Joined
Jun 2025
Message
144

Doki · E-commerce infrastructure · 2023

#20

i'll try it.

Reply