Thursday, 20 August 2026
Nigeria Communications Week
E-Business

Firm Warns of Phishing Attacks via Compromised Amazon Simple Email Service Accounts

Chike Onwuegbuchi11 May 20260 Comments
Firm Warns of Phishing Attacks via Compromised Amazon Simple Email Service Accounts
Kindly share this post

Kaspersky has detected phishing and business email compromise (BEC) attacks that are leveraging Amazon Simple Email Service (SES) – a cloud-based email service designed for businesses and developers…

Kaspersky has detected phishing and business email compromise (BEC) attacks that are leveraging Amazon Simple Email Service (SES) – a cloud-based email service designed for businesses and developers to send and receive high-volume marketing, notification, and transactional emails (for instance, password resets).

Because these emails are sent via a trusted service, they originate from reputable IP addresses, frequently include legitimate “.amazonses.com” identifiers. This makes phishing messages nearly indistinguishable from legitimate correspondence at a technical level. Users should treat unexpected emails with extreme caution.

The attacks are driven by the theft and exposure of credentials from Amazon Web Services (AWS). The attackers are using leaked AWS Identity and Access Management Keys – often found in public repositories, misconfigured cloud storage, and exposed configuration files. With automated tools, threat actors can identify valid keys and abuse them to send large volumes of malicious emails through legitimate infrastructure operated by Amazon.

Attackers disguise malicious links behind trusted domains such as amazonaws.com using redirects and by creating highly convincing HTML email templates. In many cases, phishing pages are hosted on infrastructure that appears legitimate, further increasing the likelihood of credential theft from victims.

One of the campaigns observed by Kaspersky in early 2026 involved emails impersonating document-signing platforms like DocuSign. Victims were prompted to review and sign documents, only to be redirected to fraudulent login pages hosted on an Amazon Web Services page designed to capture credentials.

Researchers also identified business email compromise attacks carried out via Amazon SES in which attackers impersonated employees and fabricated entire email threads with suppliers. These messages, often sent to finance departments, requested urgent payments and included PDF attachments containing only banking details – with no malicious links – making detection challenging.

“We’ve seen attackers abuse trusted platforms before – like in cases with Google Tasks and Google Forms - where scammers rely on built-in notification mechanisms to deliver phishing links from legitimate domains like @google.com, effectively bypassing email filters and exploiting user trust.

“However, the abuse of Amazon SES represents a more advanced stage of this trend: instead of merely leveraging a platform’s notification features, attackers compromise cloud credentials and gain direct control over a trusted email-sending infrastructure. This allows them to scale attacks, fully customise messages, and deliver phishing emails that are hard to distinguish from legitimate business communications,” commented Roman Dedenok, Anti-Spam Expert at Kaspersky.

C
Published by

Chike Onwuegbuchi

Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

More in E-Business
E-Business

The Biggest Cost of Nigeria’s Crypto Stamp Duty Not 1.5%, But What Happens Next

By Chike Onwuegbuchi17 Aug 2026

There is a strange thing about regulation: everybody wants clarity until clarity comes with a bill. Given that is probably why the conversation around Nigeria’s proposed 1.5% stamp duty on virtual asset transactions has quickly become a debate about the number. Is 1.5% too much? Will it make crypto more expensive? Will users simply move elsewhere?

E-Business

Analytics Intelligence Partners Open Access Data Centres to Advance Sovereign AI and Cloud Solutions Across Africa

By Chike Onwuegbuchi17 Aug 2026

Analytics Intelligence [AI], a leading provider of artificial intelligence and data analytics solutions, has entered into a strategic partnership with Open Access Data Centres (OADC), a WIOCC Group company, to develop sovereign AI and cloud solutions that enable African enterprises to deploy secure, scalable, and locally hosted AI infrastructure.