Amazon said it had been hit by an "extensive" scam, revealing that unknown hackers were able to siphon funds from sellers'/merchants' accounts for over six months last year.

Amazon believes it was the victim of a “serious” online attack by hackers who breached about 100 seller accounts and transferred cash from loans or sales to their own bank accounts. The hack took place between May 2018 and October 2018, and Amazon’s legal department concluded that this was the appropriate time to go public with the matter.
Amazon said it is still investigating the compromised accounts and believes hackers were able to change account details on the seller’s central platform at its own companies Barclays Plc and Prepay Technologies Ltd., which is partly owned by Mastercard Inc., according to the filing. Amazon determined that the accounts were likely exposed by phishing techniques that tricked sellers into providing confidential account login information.
The case highlights how the world's largest online retail platform - designed to be automated with minimal human input - can be used by fraudsters and how it is very difficult for Amazon to find the perpetrators.
Amazon's lawyers asked a London to approve searches of account statements at Barclays and Prepay, which "have become part of the offence without reason."
Amazon needed the documents “to investigate the fraud, identify and prosecute the violators, trace the location of the misappropriated funds, put an end to the fraud, and prevent future violations,” the company’s lawyers said in the court filing.
The filing does not state how the suspected offenders were able to add details for the additional banks to the merchants' accounts.
