Experts warn that Amazon’s simple email service is being abused to launch a “massive volume” of phishing attacks



  • Attackers are hijacking exposed AWS credentials to send large-scale phishing emails through Amazon SES
  • Malicious messages bypass SPF, DKIM and DMARC checks and arrive directly in inboxes.
  • Researchers warn that the trend is growing, urging stricter IAM and key management practices.

The Amazon Simple Email Service (SES) is being abused to launch a “massive volume” of phishing attacks that easily bypass current defenses and expose victims to risks of credential and identity theft.

Security researchers Kaspersky sounded the alarm in a new report that noted: “Specifically, we have recently observed an increase in phishing attacks leveraging Amazon SES.”

Leave a Comment

Your email address will not be published. Required fields are marked *