Defending attacks: sabotage, abuse and what actually works
- You recognise the typical attack types by their signatures.
- You know which defences work and which only keep you busy.
- You have monitoring that surfaces attacks in hours rather than weeks.
- You respond in a way that does not turn you into the rule-breaker.
In any niche with money in it there are competitors who want not only to sell better but to make you sell worse. This lesson is deliberately sober: it explains what such attacks look like, how to tell them from your own mistakes and how to defend yourself. It is not a manual for attacking anyone — every action described is a breach of Amazon's rules and will, in case of doubt, cost you the account.
The most common error of reasoning after a collapse is: “that was an attack.” Usually it was not. Before reading on, walk the fault tree from lesson 13. Only when it finds no cause and the signatures in this lesson fit is sabotage the likelier explanation.
1The attack types and their signatures
| Attack | What happens | Signature |
|---|---|---|
| Catalog manipulation | Strangers change the title, category, dimensions or images of your ASIN | A change you did not make, often overnight; category suddenly nonsensical |
| Variation hijacking | A foreign product is attached as a child to your family | A new child you do not recognise; reviews that do not match the image |
| Review attack | Several negative reviews in a short time, often with similar wording | Clustered over a few days, no verified purchases, interchangeable phrasing |
| Abusive complaint | A false IP or safety report against your offer | A complaint with no discernible rights holder behind it; often arrives bundled with other things |
| Price attack | A seller undercuts massively without being able to deliver | No stock, no history; disappears after days — once your repricer has followed |
| Order abuse | Large orders that are cancelled or charged back as fraud | Unusual quantities, the same delivery address, just before a ranking-relevant period |
| Image and copy theft | Your photographs appear on other sellers' listings | Identical images, sometimes with your logo; easily proven from the original files |
Attacks behave differently from mishaps. A mishap comes alone and has a backstory: something was changed, something ran out, something expired. An attack comes bundled, suddenly and with no backstory — three negative reviews on a Tuesday, plus a complaint and a new co-seller. It is not the individual event that gives it away but the simultaneity.
2The defences that actually work
Sorted soberly: what helps, what helps a little, and what wastes time.
| Measure | Effect | Why |
|---|---|---|
| Register the trademark and use Brand Registry | high | Markedly improves your position on catalog contributions (lesson 1) — the best protection against manipulation |
| Daily monitoring of your own ASINs | high | The difference between hours and weeks decides the damage |
| Keeping a change register | high | The only way to evidence that a change did not come from you |
| A price floor in the repricer | high | Renders price attacks pointless because your price does not follow (lesson 5) |
| Reporting reviews that breach policy | medium | Works on clear violations, not on merely negative opinions |
| Responding publicly to attacks | none | Costs time, moves nothing — and gives the attacker feedback |
| Counter-attacking | harmful | A policy breach with account risk; you move from victim to case |
On Tuesday morning the monitoring shows three anomalies on the AURELO set at once: the category has changed, an unknown child hangs in the variation family, and four one-star reviews without verified purchase arrived overnight. Individually each would be explicable. Together, in one night, it is a pattern. The response, in this order: check the change register (nothing from us), revert the catalog change with evidence, report the foreign child, report the reviews with reasons, document everything. Forty minutes in total — and the decisive advantage was that it surfaced on Tuesday morning rather than three weeks later.
3Monitoring: what you actually check daily
Useful monitoring is short and, in exchange, complete. Five points per core ASIN, automated or done by hand in five minutes:
- Title, main image, category, dimensions — the checksum glance: has anything changed that I did not change?
- The number of child ASINs in every variation family.
- The number of co-sellers and the lowest price.
- Review count and star rating, watching for sudden jumps.
- Featured Offer share — the fastest early indicator of all (Listing L14).
The value of this list is not its completeness but its repetition. An attack noticed the same day is an administrative task. The same attack running for three weeks has damaged reviews, ranking and stock — and you do not repair that damage with a report.
4When reviews are the target
The most common and most painful attack. What helps and what does not:
- Report, but properly: what is reportable are policy breaches — abuse, obviously wrong product references, evident competitor involvement, reviews without purchase. What is not reportable is a bad but honest opinion.
- Give reasons for every report individually. Bulk reports saying “these are all fake” get a blanket rejection.
- Reply publicly and factually. Not for the reviewer but for the next hundred readers (Growth L5).
- Accelerate genuine reviews. The most effective counterweight is dilution by real reviews — the one route that belongs to you and does not depend on someone else's decision.
Reporting everything at once and then following up daily. That produces a pile of identical tickets answered in bulk — and your genuine cases drown in it. One ticket per matter, with reasons, then patience. The same rule as with reimbursements (lesson 7): form beats volume.
5Your own defences: what makes attacks unattractive
- Your own ASIN rather than someone else's catalog entry. Co-selling on a foreign ASIN leaves you with almost no catalog rights — the cheapest structural protection there is.
- A registered trademark in every selling country, with matching classes (lesson 10).
- Serialisation under counterfeit pressure. It ends the argument about features.
- A price floor and a stock buffer. Two attacks — price pressure and manufactured stock-outs — lose their effect.
- Documentation as a habit. The register, the original photos, the invoices: everything you need in an emergency is created in normal operation or not at all.
- Daily monitoring of the five points per core ASIN in place.
- Change register maintained — proof that a change did not come from you.
- Price floor set in the repricer and protected against unserious sellers.
- Reviews reported individually and with reasons, never in bulk.
- Fault tree walked before assuming sabotage.
- Never retaliated — any countermeasure of the same kind is a policy breach.
- Everything documented: date, observation, screenshot, action taken.
6Expert insight: simultaneity as evidence
Individual events prove nothing — which is why sabotage reports so often go nowhere. A single one-star verdict is an opinion. A single new co-seller is competition. A single catalog change can be a system process. What makes sabotage provable is not the event but its simultaneity with others.
For that you need a timeline, and it has to exist BEFORE the incident. Keep a table per core ASIN with one row per day and these columns:
| Column | Why it belongs in the timeline |
|---|---|
| Date and time of the check | Without a timestamp no simultaneity can be evidenced |
| Checksum of the catalog fields (title, image, category, dimensions) | Shows changes without you having to read everything |
| Number of children, co-sellers, reviews, star rating | Four numbers in which nearly every attack shows up |
| Your own changes that day | Separates outside interference from your own work — the decisive column |
| Anomalies as free text | What no number captures: the wording of reviews, the name of a new seller |
In an emergency that table becomes a document Amazon can actually read: “On 14 March between 02:00 and 08:00 the category was changed, a child was added and four reviews without verified purchase were posted, simultaneously. Our change log shows that no change originated from us in that window.” That is something different from “we are being sabotaged”.
Three subtleties make the difference:
- Log the nothing too. A day without anomalies is an important row: it evidences that the check ran and the state was normal. A timeline with gaps invites every objection.
- Screenshots with timestamps. Numbers in your own table are your assertion; a screenshot of the detail page is evidence. Take them on anomalies immediately, not later.
- The timeline is also your self-protection. In the majority of cases it shows that the drop coincides with one of YOUR OWN changes — the new image, the changed price, the promotion that expired. That insight is more uncomfortable than an attack and far more common. Which is exactly why the “own changes” column is the most important one in the table.
Anyone under attack eventually hears the advice to hit back in kind — a complaint against the suspected attacker, a few reviews, a price below their cost. Every one of those is a violation, every one is logged, and none restores your revenue. In the end the difference between you and the attacker is what stands in your accounts — which is why the only right answer is: document, report, keep selling.
The pro track assumes the other three and repeats nothing from them. It opens once you have completed all three in full — every lesson quiz at 80 % or better, and every final quiz passed.
Not logged in? Your progress only counts with a free account.
Check yourself
6 quick questions — one at a time, instant feedback. With a free account your progress is saved.
Frequently asked
How do I tell a review attack from ordinary displeasure?
By three features together: clustering into a few days, missing verified purchases and interchangeable phrasing with no concrete product reference. If one of those is absent, genuine displeasure is the likelier explanation — and then the cause sits in the product or in an expectation your listing creates.
Is a monitoring service worth it?
From around twenty ASINs, yes, because the daily manual check stops being sustained — and that is exactly what creates the damage. Below that a five-column table and five minutes each morning suffice; the resulting timeline is more valuable than any alert anyway, because it also carries your own changes.
Can I do anything about a co-seller who has too little stock and cancels constantly?
Not directly — other people's cancellations are their account problem, not yours. What works is that your price does not follow and your stock holds: then you regularly win the Featured Offer back as soon as they cannot deliver. You can report conspicuous behaviour; the effect is Amazon's business, your preparation is yours.
The free Listing Check scores any ASIN from 0 to 100 in a minute — the fastest way to see whether the mechanics from this lesson actually hold on your own listing.
Go deeper: the complete guide to optimizing Amazon listings →
Everything in this academy comes from day-to-day selling practice — the same playbook behind Listimo, the tool that turns product photos into complete Amazon listings.