Case study – Learn tech session, Housing 21
Most scam advice assumes the scammer is lying. Sometimes they aren’t. That is what made this one work, and it is why the resident nearly fell for it.
The session
We run learn techn sessions with Housing 21 residents. There is a loose syllabus, things we always cover, because everyone needs them, but the sessions are led by the people in the room, have actually brought with them, whether thats a device, or a question.
Most weeks we end up somewhere other than where the plan said. Today was one of those days.
One resident brought a phone call.
What she said
Someone from Amazon had been ringing her repeatedly. They told her that her account had been hacked and they were calling to help her sort it out.
She wasn’t sure. She thought it might be a scam, so she said so out loud.
What we found
We logged into her Amazon account together.
- Around £6,000 of goods sitting in the basket
- Six iPhones
- Ten Airbnb gift vouchers at £250 each
We checked her order history. Nothing had been placed. Nothing had shipped. Nothing had been charged.
So the caller was right. She had been hacked… By him.
Why the scam works
This is a deliberate design, not an accident.
- The attacker gets into the account. Usually a password reused from a site that has been breached.
- He loads the basket. He doesn’t order anything, because ordering triggers real Amazon security and a real delivery address he can’t control.
- He rings the account holder as “Amazon security” and tells her she has been hacked.
- She logs in to check. She finds the basket. Every word he has said is confirmed by what is on her own screen.
At that point his credibility is established by evidence, not by persuasion. The next instruction, read me this code, let me connect to your device, move your money to a safe account, arrives from someone who has already been proved right once.
- The basket is never the theft. It is bait to get the account holder onto a device-sharing call. Reported cases end with remote-access software installed, or with the victim convinced their bank is compromised and moving money to a “safe account”.
The usual advice is to watch for the lie. There was no lie to catch.
This is not a one-off
Which? tracks this as the “iPhone in your basket” scam and updated its warning in July 2026. The reported pattern is consistent: a caller from Amazon’s “fraud department”, the victim addressed by full name, call-centre noise in the background, and high-value goods or gift cards waiting in the basket when they log in to check. Some victims deleted the items and watched them reappear, because the attacker still had access.
So this was not bad luck landing on one resident. It is a live national campaign that happened to reach a housing scheme in Oldham on a Tuesday afternoon.
Which? guidance: Amazon ‘iPhone in your basket’ scam warning
What we did
- Changed the account password
- Used Amazon’s “Compromised account?” flow to sign out of all apps, devices and browsers
- Enabled two-factor authentication
- Emptied the basket, in that order, clearing it first achieves nothing, because an attacker who still has access simply refills it
- Checked for added delivery addresses and secondary contact emails
- Flagged that any password reused elsewhere needed changing, starting with her email account
Ten minutes, start to finish.
Why the tangent is the model
A fixed curriculum would not have found this.
If the session had been “today we are covering online shopping”, she would have followed along, learned something useful, and gone home to a phone that kept ringing. The £6,000 basket only surfaced because the session had room in it for someone to say this thing is bothering me and be taken seriously.
That is the trade. A tightly scheduled session is easier to plan, easier to evidence and easier to report on. It is also a session where nobody raises the thing they are actually worried about, because it isn’t on the agenda.
We keep the syllabus loose on purpose. The scheduled content is the floor, not the point.
The point
The technical fix was trivial. Nobody needs a training course to change a password, and the skills gap was never the issue here.
The issue was verification. She had a plausible story from a stranger on the phone, evidence on her own screen that appeared to confirm it, and no way to independently check any of it.
What she needed was someone she could ask. More precisely, someone she already trusted, available at the moment a stranger was working hard to sound trustworthy.
That is what Digital Champions do. Not fixing devices. Being the person who gets asked first.
Without that session in the diary, the calls would have continued, and the story would have kept holding up, because it was true.
Credit where it belongs
Housing 21 books these sessions every year, for residents across their schemes. That is worth saying plainly, because it is not the norm.
Most organisations buy digital support reactively, after something has gone wrong, and usually as a one-off. Housing 21 puts it in the calendar in advance and keeps it there. That is why there was a session running on the afternoon this woman started getting the calls, and why she had somewhere to take it.
Nobody gets to point at prevention and show what it stopped, which is exactly why it is hard to fund and easy to cut. Today it is possible to point at it: a standing booking, made months earlier for general digital confidence, caught a live account compromise before any money moved.
That is a good commissioning decision, and it deserves recognising as one.
It also goes beyond the booking. Housing 21 staff and residents know us on sight. They come into the shop. They turn up at our digital drop-ins. They stop us in the street. Our Digital Champions are recognisable in their brightly coloured hoodies with the logo on them, and that is not a branding exercise.
It is the mechanism. The whole scam depends on trusting a voice you cannot place, on the strength of a story you cannot check. The counter to that is not a leaflet. It is knowing, without having to work it out, that the people in the loud hoodies are the ones you can ask, because you have seen them in your own building, in the shop, at the drop-in down the road.
What to check on your own account
- Open your Amazon basket. If there is anything in it you didn’t put there, you have been accessed.
- Check saved delivery addresses for any you don’t recognise.
- Turn on two-factor authentication.
- If your Amazon password is used anywhere else, change those too. Start with your email, because that is the account that resets all the others, and because two-factor authentication does not protect you if someone is already reading your inbox and can see the code.
- Changing the password is not enough on its own. Use Amazon’s “Compromised account?” option under Login & Security to sign out every device and browser.
- Amazon will not ring you to tell you that you have been hacked. Nobody legitimate opens with a phone call.
- Report it to Action Fraud even if you lost nothing. Attempted fraud is still fraud, and the reports are what drive the warnings.
Inclusive Bytes delivers learning technology sessions across Oldham and with housing partners. If you want to become a Digital Champion, or bring a session
