An Amazon-looking verification prompt hosted as a Google Drawings graphic is not proof that its link leads to Amazon. In a campaign reported in August 2024, attackers used a Google Drawings-hosted image and a call to action that passed through WhatsApp’s l.wl.co redirect service and the short-link service qrco.de before reaching a fake Amazon sign-in page. The practical rule: check account alerts in Amazon’s official app or by typing its address yourself, not through an unexpected message link.
How the Google Drawings and WhatsApp phishing chain worked
Menlo Security reported that the campaign began with an email containing a graphic hosted in Google Drawings. The image imitated an Amazon account-verification prompt and displayed a “Continue Verification” call to action. The graphic’s link passed through l.wl.co, WhatsApp’s link-shortening and redirection service, and then qrco.de, another short-link service, before taking the recipient to a lookalike Amazon sign-in page. Menlo’s report was published on August 2, 2024, and its researcher blog post followed on August 7.
The fake page sought login credentials along with additional personal, billing, and payment information. The Hacker News’ August 8, 2024 report said that after collecting information, the page redirected victims to the genuine Amazon login page. That final redirect could make the sequence seem more plausible, but it did not make the earlier information collection legitimate.
Why trusted services appeared in the chain
Menlo described the technique as “Living Off Trusted Sites” (LoTS): familiar services were used along the route, while the brand impersonation and redirects obscured the attacker-controlled destination. Google Drawings hosted the graphic; it did not authenticate the link as an official Amazon page. Likewise, a short URL can conceal the address it ultimately opens.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Is this Amazon verification link real?
The reported email’s verification prompt was part of an impersonation campaign, not a genuine Amazon account check. A logo, Amazon-like wording, or a graphic hosted on a familiar platform cannot establish that the destination belongs to Amazon. The relevant question is where the link takes you after redirects—and an unexpected message is not a safe way to find out.
Can a Google Drawings link be a phishing scam?
Yes. A legitimate hosting service can store or display content that someone uses to direct viewers elsewhere. In this case, Google Drawings hosted the graphic, while the linked route continued through shorteners to a fake sign-in page. The hosting domain identified where the image was stored, not who controlled the final destination or whether the request was authentic.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Are WhatsApp shortened links safe to click?
A WhatsApp shortening or redirect link is not a safety guarantee. The reported campaign used l.wl.co as one step in a longer chain that also included qrco.de. Because the visible shortened address does not by itself reveal the final page, treat it as unverified when it arrives in an unexpected account-security message. The same principle applies to other link shorteners: the service’s familiar name does not certify the destination.
How to verify an unexpected Amazon account alert
- Do not use the message’s verification button or link, and do not rely on its logo, image, host, or shortened URL as proof.
- Open Amazon’s known official app, or type its address directly into your browser rather than following the message link.
- Check your account status and any security notices from within that independently opened service.
- If you entered credentials or payment details on a suspicious page, use the official service’s account-security and payment channels to respond. This is general safety guidance; the cited campaign reports do not document a tested recovery procedure.
What is known—and not known—about the campaign
The available incident reporting describes a campaign observed and reported in August 2024. It does not establish that the same infrastructure is active today, how many people were targeted or affected, or the amount of any losses. Nor does the use of Google Drawings, WhatsApp’s redirect service, or a shortener alone prove that a particular message is malicious. These details are reasons to verify independently, not a verdict based solely on the platform.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Where UK readers can report suspicious messages
For people in the UK, the EMCRC advises forwarding suspicious emails to report@phishing.gov.uk, forwarding suspicious SMS messages to 7726, and reporting fraud or cybercrime to Action Fraud. These are UK-specific routes, not general contacts for other countries.
Quick Recap
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

