I received a notification that appeared to come from the official Amazon app. It showed Amazon's name and icon, but tapping it opened a suspicious scam website directly in Chrome. I haven't installed any unofficial apps or anything designed to imitate Amazon, and the phone is brand new with apps installed only through the Play Store. Chrome also didn't appear to have any open tabs. Could Amazon's notification system have been compromised, or is there another explanation for this?
2 Answers
This probably doesn’t mean Amazon was hacked. One possibility is that Chrome had previously loaded an ad or redirect, and the notification opened Chrome while the browser displayed that existing page. Try clearing Chrome’s browsing data, checking its notification and pop-up permissions, and running a Play Protect scan. It’s also safest not to enter any Amazon credentials on the page and to open Amazon manually through the official app instead.
The notification may have looked like it came from Amazon without actually being a normal Amazon message. Long-press the notification and check which app generated it, then review the notification history and installed apps for anything unfamiliar. You can also inspect the notification’s link without opening it. If the link was genuinely generated by Amazon, report it through Amazon’s security or customer-support channels, but a compromised phone, browser redirect, or misleading notification is more likely than Amazon itself being breached.

The phone is new and I’ve only installed apps from the Play Store, and Chrome didn’t show any open tabs. I’m still trying to work out what could have triggered it.