Amazon SES phishing attacks have been detected by Kaspersky in a wave of phishing and business email compromise attacks leveraging Amazon Simple Email Service (SES), a cloud-based email platform used by businesses and developers to send high-volume marketing, notification, and transactional messages. Because these emails originate from trusted Amazon infrastructure, they appear legitimate at a technical level, making them difficult to distinguish from genuine correspondence.

The attacks stem from stolen AWS credentials. Attackers obtain compromised AWS Identity and Access Management Keys found in public repositories, misconfigured cloud storage, and exposed configuration files. Using automated tools, threat actors identify valid keys and exploit them to send large volumes of malicious emails through Amazon’s legitimate infrastructure.

How Amazon SES Phishing Attacks Work

Attackers disguise malicious links behind trusted domains such as amazonaws.com using redirects and crafting convincing HTML email templates. Phishing pages are hosted on infrastructure appearing legitimate, increasing the likelihood that victims will enter credentials on fraudulent login pages.

One campaign observed by Kaspersky in early 2026 involved emails impersonating DocuSign, a document-signing platform. Recipients were prompted to review and sign documents, then redirected to fake login pages hosted on Amazon Web Services infrastructure designed to capture login credentials.

Business Email Compromise via Amazon SES

Researchers identified business email compromise attacks in which attackers impersonated employees and fabricated entire email threads with suppliers. These messages, typically sent to finance departments, requested urgent payments and included PDF attachments containing only banking details, with no visible malicious links. This approach makes detection significantly more difficult than typical phishing campaigns.

Why Amazon SES Abuse Represents an Escalation

Roman Dedenok, Anti-Spam Expert at Kaspersky, noted that while attackers have previously abused trusted platforms like Google Tasks and Google Forms using built-in notification mechanisms to deliver phishing links from legitimate domains, the abuse of Amazon SES represents a more advanced threat. “Instead of merely leveraging a platform’s notification features, attackers compromise cloud credentials and gain direct control over a trusted email-sending infrastructure,” Dedenok stated. “This allows them to scale attacks, fully customize messages, and deliver phishing emails that are hard to distinguish from legitimate business communications.”

Recommended Security Measures

Kaspersky recommends that organizations secure AWS access by minimizing permissions, replacing static IAM keys with roles, enabling multi-factor authentication, restricting access by IP address, and regularly rotating and auditing credentials.

Individual users should not trust emails based solely on sender name or domain. Users should treat unexpected messages with caution, verify requests through a separate communication channel, and carefully inspect links before following them, even if messages appear to originate from legitimate services.

About Kaspersky

Kaspersky, founded in 1997, is a global cybersecurity and digital privacy company. The firm has protected over a billion devices from emerging cyber threats and targeted attacks. Kaspersky serves millions of individuals and approximately 200,000 corporate clients with comprehensive security solutions including personal device protection, specialized business security products, and cyber immune solutions designed to combat sophisticated digital threats.