Kaspersky has uncovered a new wave of sophisticated phishing and business email compromise (BEC) attacks that exploit Amazon Simple Email Service (SES), a cloud-based email platform used for sending large volumes of transactional and marketing emails.
The cybersecurity firm warns that attackers are leveraging the trusted infrastructure of Amazon to make fraudulent emails appear legitimate and significantly harder to detect.
Exploiting Amazon SES infrastructure for cyberattacks
Amazon SES operates through highly trusted IP addresses and often includes legitimate identifiers such as “.amazonses.com,” which makes malicious emails difficult to distinguish from genuine corporate communications.
This level of trust in Amazon’s infrastructure allows cybercriminals to conduct large-scale phishing campaigns while bypassing traditional email security filters.
Stolen AWS credentials at the core of the attacks
According to Kaspersky, the attacks rely heavily on stolen AWS Identity and Access Management (IAM) credentials, often leaked through public repositories, misconfigured cloud storage, or exposed configuration files.
Once obtained, attackers use automated tools to identify active credentials and exploit them to send large volumes of phishing emails through Amazon’s legitimate cloud infrastructure.
Advanced techniques to hide malicious activity
Cybercriminals are masking malicious links behind trusted domains such as amazonaws.com, using redirect chains and carefully crafted HTML-based email designs to make the messages appear professional and credible.
In many cases, phishing pages are hosted on trusted cloud infrastructure, further increasing their legitimacy and making detection more difficult.
Campaigns impersonating trusted services like DocuSign
Kaspersky researchers also identified phishing campaigns impersonating widely used document signing services such as DocuSign.
Victims are typically asked to review or sign documents, but are redirected to fake login pages hosted on Amazon cloud services, where their credentials are stolen.
Business Email Compromise (BEC) attacks via Amazon SES
In addition to phishing, attackers are using Amazon SES to conduct Business Email Compromise (BEC) campaigns by impersonating company employees and creating fake email threads with vendors.
These attacks often target finance departments with urgent payment requests and include PDF attachments containing banking details, avoiding suspicious links to bypass security checks.
Security experts warn of increasing sophistication
Roman Dedenok, spam analysis expert at Kaspersky, said that abusing trusted platforms like Amazon SES represents an advanced evolution in cyberattacks.
He explained that attackers are no longer just using notification systems but are directly compromising cloud credentials to control legitimate infrastructure and send highly convincing fraudulent emails.
Kaspersky recommendations to reduce risk
Kaspersky advises organizations to strengthen their cloud security posture by:
- Minimizing AWS permissions and applying least-privilege access
- Replacing static IAM keys with role-based authentication
- Enabling multi-factor authentication (MFA)
- Restricting access by IP address where possible
- Regularly rotating and reviewing credentials
- Avoiding trust based solely on sender name or domain
- Verifying unexpected emails through alternative communication channels
- Carefully inspecting links before clicking, even from trusted services
Growing threat from cloud-based phishing
These attacks highlight a broader trend of cybercriminals increasingly abusing trusted cloud infrastructures to conduct phishing campaigns.
As cloud services become more deeply integrated into business operations, security experts warn that organizations must adopt stronger identity management and monitoring systems to defend against evolving threats.









