Scammers Weaponize Amazon SES to Bypass Security
ID: 8f5b509d-e277-5d7b-9288-6b2c324fcaf3
STIX ID: report--8f5b509d-e277-5d7b-9288-6b2c324fcaf3
Feed Name: securityonline.info
Kaspersky reports a surge in phishing campaigns abusing Amazon SES: attackers obtain leaked AWS IAM keys (via public GitHub repos, .env files, Docker images, or exposed S3/config backups), use SES to send SPF/DKIM/DMARC‑passing emails from Amazon IPs that evade filters, and run convincing BEC-style scams and forged financial documents to trick recipients into fraudulent wire transfers; recommended mitigations include least privilege, roles, MFA, key rotation, centralized key management, and user verification practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
