logo

Attackers Abuse Amazon SES To Send Authenticated Phishing Emails

ID: 5862acd7-eb75-5872-9f3a-16fec10807fb

STIX ID: report--5862acd7-eb75-5872-9f3a-16fec10807fb

Feed Name: Cyber Press

Threat Score
60/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

Author: Varshini

...
...

The report describes a growing trend where attackers exploit leaked AWS IAM keys to send highly convincing, authenticated phishing emails via Amazon Simple Email Service (SES), allowing messages to pass SPF/DKIM/DMARC checks and evade filters; it details how criminals harvest exposed credentials and recommends mitigations such as least-privilege IAM, role-based access, MFA, key rotation, IP restrictions, KMS, and user vigilance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.