Attackers Abuse Amazon SES To Send Authenticated Phishing Emails
ID: 5862acd7-eb75-5872-9f3a-16fec10807fb
STIX ID: report--5862acd7-eb75-5872-9f3a-16fec10807fb
Feed Name: Cyber Press
Threat Score
The report describes a growing trend where attackers exploit leaked AWS IAM keys to send highly convincing, authenticated phishing emails via Amazon Simple Email Service (SES), allowing messages to pass SPF/DKIM/DMARC checks and evade filters; it details how criminals harvest exposed credentials and recommends mitigations such as least-privilege IAM, role-based access, MFA, key rotation, IP restrictions, KMS, and user vigilance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
