Potential Cybersecurity Risk with Delivery Agents of eCommerce Platforms

mayank11280

Forerunner
Cybersecurity risk alert:

Amazon delivery associates may try to take control of your account through OTP. (Possible on other platforms also)

A very low value item was delivered to me the day before yesterday. No OTP was asked. The website shows item as “delivered”. Meaning, the product delivery process has been closed now. No further action is necessary.

However, yesterday I received a random OTP from Amazon. Soon after that I received a call from an unknown number (not from official Amazon provided number but personal number). The person said he is the delivery agent from yesterday and asked for the OTP to close the delivery. He clarified, he had forgotten to ask for it before. This felt sketchy. No OTP was required upon delivery.

Sketchy because:

1. Amazon makes a great deal about OTP being required during delivery through multiple emails, SMSs, WA messages and app notifications: none were received for this delivery.

2. OTP based delivery is required for high value items only, and largely for prepaid items: this was a low value, POD item.

3. For OTP based items, product delivery cannot be closed without it: this item was marked delivered immediately after the handover.

4. The message from Amazon mentions the purpose of the OTP in case of OTP based delivery. It is usually not mentioned for OTP based sign in. The message received didn’t mention anything about delivery.

Every day new forms of cybercrimes are coming to the fore.

As a rule of thumb: Please use caution and don’t share OTPs, especially when you don’t know the purpose of the OTP and the person you are sharing the OTP to.

Stay safe.
 
As a rule of thumb: Please use caution and don’t share OTPs..
over the phone

However, yesterday I received a random OTP from Amazon. Soon after that I received a call from an unknown number (not from official Amazon provided number but personal number). The person said he is the delivery agent from yesterday and asked for the OTP to close the delivery.
May not have even been the delivery guy but someone impersonating..

My call log is so full of these guys numbers over the years.
 
Last edited by a moderator:
I have been tricked like this before. The delivery person asked for OTP at the time of delivery. The SMS text clearly mentioned that it was a login OTP for Amazon account, and not to share it with anyone. I was in a hurry, and missed this part, shared the OTP. Realized this after about 15 minutes. Then had to dig through Amazon website to find an option to "Log out of all devices". Fortunately no cards were saved in the account, so no damage done. Complained to Amazon about this, they willingly or not, refused to understand the situation. Left it at that, did not have energy to pursue this further.
 
Last edited:
  • Wow
Reactions: mayank11280
over the phone

I can't think of any reason where OTP is asked over the phone.

Can you?

^Reference

May not have even been the delivery guy but someone impersonating..
This was the exact thing that rang the bell for me. Told him: “in the current situation I will not be able to share you the OTP” and hung up the call.
 
over the phone

I can't think of any reason where OTP is asked over the phone.

Can you?
Actually, yes.

There have been times when I had to share OTP over phone because I have been outside.

Has not been an issue if the call has been from official Amazon number.

As a rule of thumb: Please use caution and don’t share OTPs, especially when you don’t know the purpose of the OTP and the person you are sharing the OTP to.
That’s why I said this. Everyone’s situation is different but as a broad rule of thumb this helps.