logo

Phishing at Cloud Scale: How AWS is Abused for Credential Theft

ID: 505aeb4c-9697-5084-b8fa-f19e0463fa20

STIX ID: report--505aeb4c-9697-5084-b8fa-f19e0463fa20

Feed Name: Cofense Blog

Threat Score
65/100

Date Published: 2026-01-28

Date Updated: 2026-04-27

Author: Cofense

...
...

This report analyzes how threat actors exploit AWS services—notably S3 buckets, SES (awstrack.me tracking links), and Amplify—to host and disseminate large-scale credential-phishing campaigns, outlines observed TTPs and example phishing pages from 2021–2025, highlights the abuse of trusted AWS infrastructure to evade email security controls, and summarizes AWS and vendor mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.