Experts warn that Amazon’s simple messaging service is being abused to launch a “massive volume” of phishing attacks.


  • Attackers hijack exposed AWS credentials to send large-scale phishing emails via Amazon SES.
  • Malicious messages bypass SPF, DKIM and DMARC checks and land directly in inboxes
  • Researchers warn that this trend is growing, calling for stricter IAM and key management practices.

The Amazon Simple Email Service (SES) is being abused to launch a “massive volume” of phishing attacks that easily bypass current defenses and expose victims to the risk of credentials and identity theft.

Security researchers Kaspersky have sounded the alarm in a new report which notes: “Specifically, we have recently observed an increase in phishing attacks leveraging Amazon SES. »

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top