Kaspersky reported a rise in phishing campaigns that abuse Amazon Simple Email Service (SES) to deliver convincing messages through trusted cloud infrastructure. The activity is believed to be fueled by exposed AWS Identity and Access Management (IAM) access keys discovered in public GitHub repositories, .env files, Docker images, backups, and public S3 buckets. After validating stolen credentials—reportedly with automated secret-scanning and access-checking workflows—attackers use SES to send bulk phishing emails that can pass SPF, DKIM, and DMARC, reducing the effectiveness of reputation-based filtering.
Observed campaigns included fake DocuSign notifications that redirected targets to AWS-hosted credential-harvesting pages, as well as more advanced business email compromise attempts using fabricated email threads and fake invoices. Researchers urged organizations to enforce least-privilege IAM permissions, enable MFA, rotate keys regularly, apply IP-based access restrictions, and strengthen encryption controls around secrets. Amazon said it provides guidance for exposed credentials, responds to abuse reports, and directs suspected misuse of AWS resources to AWS Trust & Safety.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Amazon said it provides guidance on exposed credentials, responds quickly to abuse reports, and directs suspected abusive use of AWS resources to AWS Trust & Safety. The statement accompanied public reporting on the phishing abuse of SES.
Kaspersky assessed that the phishing activity is likely enabled by exposed AWS IAM access keys found in public assets such as GitHub repositories, .ENV files, Docker images, backups, and public S3 buckets. The researchers said attackers automate secret discovery, permission validation, and bulk email distribution, allowing malicious emails to pass SPF, DKIM, and DMARC checks because they originate from a trusted service.
Kaspersky reported an increase in phishing attacks in its telemetry that abuse Amazon Simple Email Service to send convincing emails that can evade standard security filters and reputation-based blocking. The campaigns included fake DocuSign notifications, AWS-hosted phishing pages, and more advanced business email compromise lures using fabricated threads and invoices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.