Experts warn Amazon’s simple email service is being abused to launch ‘massive volumes’ of phishing attacks


  • Attackers hijack exposed AWS credentials to send large phishing emails via Amazon SES
  • Malicious messages bypass SPF, DKIM and DMARC checks and land directly in inboxes
  • Researchers warn that the trend is growing and call for stricter IAM practices and key management

Amazon Simple Email Service (SES) is being abused to launch a “massive volume” of phishing attacks that easily bypass current defenses and expose victims to credential and identity theft risks.

Security researchers Kaspersky sounded the alarm in a new report, which noted, “In particular, we have recently observed an increase in phishing attacks that exploit Amazon SES.”

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top