Thursday, September 10, 2026

Attackers Exploit Amazon SES to Send Authenticated Phishing Emails

According to researchers at cybersecurity firm Kaspersky, threat actors are abusing Amazon Simple Email Service (SES) to deliver highly convincing phishing emails that bypass traditional security controls, marking a common occurrence in email-based threats

The primary goal of any phishing campaign is to evade detection while tricking victims into revealing sensitive data.

To achieve this, threat actors continuously refine their techniques, using redirect links, QR codes, and more recently trusted cloud infrastructure.

Securelist researchers state there is a “steady trend” of phishing campaigns against Amazon SES, a legitimate cloud-based email delivery service widely used for transactional and marketing communications.

Amazon SES integrates seamlessly with AWS and is designed for reliable, high-volume email delivery. However, its legitimacy is precisely what makes it attractive to attackers.

Unlike traditional phishing campaigns that rely on suspicious domains, SES-based attacks originate from infrastructure that both users and security systems inherently trust.

Emails sent via Amazon SES pass standard authentication checks, including SPF, DKIM, and DMARC. They also often include “amazonses.com” in the Message-ID header, reinforcing their legitimacy.

As a result, these phishing emails appear technically authentic and are rarely flagged by email security solutions.

Researchers state that in early 2026, one of the most common themes in phishing emails sent with Amazon SES was fake notifications from electronic signature services such as DocuSign.

Phishing email imitating a Docusign notification (Source : Kaspersky).
Phishing email imitating a Docusign notification (Source : Kaspersky).

Attackers further enhance credibility by embedding links that appear to point to trusted domains such as “amazonaws.com.”

In reality, these links redirect users to malicious phishing pages. Combined with custom HTML templates, attackers can replicate legitimate brand communications with high accuracy.

How Attackers Gain Access

In most cases, attackers gain control of Amazon SES accounts through exposed AWS IAM (Identity and Access Management) credentials.


Phishing sign-in form (Source : Kaspersky).
Phishing sign-in form (Source : Kaspersky).

Access keys are frequently leaked in public repositories, environment files, Docker images, or misconfigured S3 buckets.

Threat actors actively scan for such exposures using automated tools like TruffleHog, which detects leaked secrets. Once valid credentials are identified, attackers verify permissions and email-sending quotas before launching large-scale phishing campaigns.

In early 2026, researchers observed widespread phishing campaigns impersonating electronic signature services such as DocuSign.

Victims received emails prompting them to review and sign documents. While the email headers confirmed delivery via Amazon SES, the embedded links redirected users to fake login pages hosted on AWS infrastructure.

Because the hosting domain appeared legitimate, many users trusted the process and entered their credentials, unknowingly handing them over to attackers.

Beyond standard phishing, Amazon SES is also being used in sophisticated Business Email Compromise (BEC) attacks.

In one case, attackers sent emails that appeared to be part of an internal conversation between an employee and a vendor regarding an overdue invoice. The email included forged message threads and attached PDF documents containing payment details.

These emails contained no malicious links, making them harder to detect. Instead, they relied on social engineering to convince finance teams to transfer funds to attacker-controlled accounts.

Mitigations

The PDF attachments didn’t contain any malicious phishing URLs or QR codes, only payment details and supporting documentation.

Forged financial documents (Source : Kaspersky).
Forged financial documents (Source : Kaspersky).

“AWS has clear terms that prohibit the use of our services to violate the security, integrity, or availability of others. When we receive reports of potential violations of our terms, we act quickly to review and take appropriate action. As always, we encourage all customers to follow recommended security guidance to help secure their accounts and prevent abuse. If anyone suspects that AWS resources are being used for abusive activity, they can report it to AWS Trust & Safety https://repost.aws/knowledge-center/report-aws-abuse. – AWS Spokesperson 

Unexpected requests, especially those involving documents or payments, should be verified through separate communication channels. Carefully inspecting links before clicking can help prevent credential theft.

As attackers continue to exploit trusted platforms like Amazon SES, both organizations and individuals must adapt their defenses to address this evolving threat landscape.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News