Amazon has urged its more than 300 million customers to be on high alert for scammers impersonating the company in a wave of holiday-season cyberattacks.

The advisory follows new figures from the FBI, which revealed that online criminals have stolen more than US$262 million (A$400 million) this year through “account takeover fraud.”

The agency has recorded more than 5,100 complaints since January, with attackers gaining access to online accounts to make unauthorised purchases or drain stored payment details.

Amazon said scammers are using increasingly convincing tactics, including fake delivery notifications, bogus account-problem alerts and unsolicited tech-support calls claiming to be from the retailer.

The company also warned customers to be cautious of social-media ads or sponsored search results offering Amazon deals that redirect to fraudulent websites.

The warning comes as online shopping activity surges in the lead-up to Black Friday, Cyber Monday and Christmas – a period traditionally linked to heightened cybercrime.

Security researchers say criminals are taking advantage of shoppers searching for steep discounts, with some leveraging AI tools to generate realistic fake order confirmations and retailer websites.

Amazon advised customers to only communicate through its official website or mobile app, enable two-factor authentication and consider using passkeys to prevent unauthorised access.

The company added that requests for urgent payments, gift cards or wire transfers should be treated as red flags.

Last year, Amazon blocked more than 55,000 phishing sites and 12,000 phone numbers used in impersonation schemes.

The FBI also urged consumers to monitor financial accounts, use unique complex passwords and avoid clicking on unfamiliar advertisements.

Australian retailers and banks have issued similar holiday warnings, with Scamwatch reporting a rise in phishing attempts tied to delivery services and online marketplaces.