惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 【当耐特】
Microsoft Azure Blog
Microsoft Azure Blog
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
爱范儿
爱范儿
L
LangChain Blog
IT之家
IT之家
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog
Hugging Face - Blog
Hugging Face - Blog
G
Google Developers Blog
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
宝玉的分享
宝玉的分享
博客园 - 三生石上(FineUI控件)
D
DataBreaches.Net
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
Amazon Infrastructure Weaponized As Compromised Credentia...
Davey Winder · 2026-05-06 · via Forbes - Innovation
Amazon Web Services logo displayed on a smartphone with Amazon logo in the background.

Beware this uptick in Amazon SES attacks.

SOPA Images/LightRocket via Getty Images

Amazon is a giant in both online retail and cloud, with Amazon Web Services accounting for an estimated 30% market share in cloud infrastructure. As a market leader, it’s not unusual to hear of Amazon being the target of cyber attacks, but a new report from security researchers at Kaspersky has now revealed that Amazon’s own infrastructure is being leveraged to launch “an uptick in phishing attacks” that bypass standard security checks by appearing to be completely legitimate. Here’s what you need to know about the Amazon Simple Email Service and how it is being weaponized by attackers.

ForbesMicrosoft Says Edge Password Security Vulnerability Is ‘By Design’—Is It Time To Switch To Chrome?

How The Amazon Simple Email Service Is Weaponized By Attackers

When it comes to phishing campaigns, one of the main objectives for attackers is to bypass security measures so that their nefarious content drops into the victim’s view without being flagged as suspicious. We’ve seen many different methodologies used, including the use of QR codes and malicious web browser notifications. When it comes to email, however, one of the tactics increasingly employed by threat actors is the use not only of reputable sources, but of legitimate and trusted platform infrastructure. In the case of the newly published report, authored by Kaspersky analyst Roman Dedenok, it is the Amazon Simple Email Service that is being put to bad use.

Amazon SES is a cloud-based platform that is designed for reliable transactional and marketing message delivery, integrating seamlessly with products in the Amazon cloud ecosystem. “The insidious nature of Amazon SES attacks lies in the fact that attackers aren’t using suspicious or dangerous domains; instead, they are leveraging infrastructure that both users and security systems have grown to trust,” Dedenok warned in the Kaspersky report.

An Amazon spoksperson provided the following statement:

“AWS has clear terms that prohibit the use of our services to violate the security, integrity, or availability of others. When we receive reports of potential violations of our terms, we act quickly to review and take appropriate action. As always, we encourage all customers to follow recommended security guidance to help secure their accounts and prevent abuse. If anyone suspects that AWS resources are being used for abusive activity, they can report it to AWS Trust & Safety."

ForbesDon’t Ignore This X Hack Attack Warning—You Could Be NextBy Davey Winder

Having gained access to the Amazon SES platform by way of compromised AWS identity and access management credentials, specifically keys exposed by developers “in public GitHub repositories, ENV files, Docker images, configuration backups, or even in publicly accessible S3 buckets,” according to Dedenok, attackers are able to then “blast out thousands of phishing emails.” The most dangerous part being that these will pass email authentication and originate from non-blacklisted IP addresses. This because the Amazon SES emails use SPF, DKIM, and DMARC authentication protocols, and “almost always contain .amazonses.com in the Message-ID headers.”

It should be noted that these attack campaigns are not attempting to compromise your Amazon account as others have done with emails purporting to come from Amazon support, but rather to access data from other platforms and even engage in invoice fraud.

Amazon is far from unique in being targeted by attackers seeking to use legitimate services for phishing campaigns. I have reported on such attacks using PayPal and Google platforms, for example, but the Kaspersky warning is worth noting nonetheless. Not least, as Dedenok concluded, “phishing via Amazon SES is shifting from isolated incidents into a steady trend.” That said, Amazon told me that it was not seeing any evidence that supports this research conclusion, and the research itself provides no validation or data for the claim that this activity is increasing.