My Amazon account got hacked into in July.
Received a call from a spoofed local number identifying as Amazon, so I answered.
They asked for me by name - which startled me because the phone scammers in India call randomly and don't know who they are speaking to, initially.
She asked me about my debit card number ending in xxxx, and she had the right info, this startled me as well.
She asks about an iphone I'm buying, blah blah blah.... while shes talking I log in to my Amazon acct and see the phone in my shopping cart. I'm a little freaked out.
Check my email and I see:
So I immediately hang up the phone and change all my important passwords - gmail, bitwarden, banks, amazon etc and activate 2FA wherever possible.
I still haven't figured out how they got into my account, but they did.
And no, I don't use the same password twice and they are always generated by bitwarden and look like this:
*thCvf7g%eOCFck^$b^42!5i