الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky Warns of Phishing Attacks Through Compromised Amazon SES Accounts

Kaspersky has detected phishing and business email compromise (BEC) attacks that are leveraging Amazon Simple Email Service (SES) – a cloud-based email service designed for businesses and developers to send and receive high-volume marketing, notification, and transactional emails (for instance, password resets). Because these emails are sent via a trusted service, they originate from reputable IP addresses, frequently include legitimate “.amazonses.com” identifiers. This makes phishing messages nearly indistinguishable from legitimate correspondence at a technical level. Users should treat unexpected emails with extreme caution.
The attacks are driven by the theft and exposure of credentials from Amazon Web Services (AWS). The attackers are using leaked AWS Identity and Access Management Keys – often found in public repositories, misconfigured cloud storage, and exposed configuration files. With automated tools, threat actors can identify valid keys and abuse them to send large volumes of malicious emails through legitimate infrastructure operated by Amazon.
Attackers disguise malicious links behind trusted domains such as amazonaws.com using redirects and by creating highly convincing HTML email templates. In many cases, phishing pages are hosted on infrastructure that appears legitimate, further increasing the likelihood of credential theft from victims.
One of the campaigns observed by Kaspersky in early 2026 involved emails impersonating document-signing platforms like DocuSign. Victims were prompted to review and sign documents, only to be redirected to fraudulent login pages hosted on an Amazon Web Services page designed to capture credentials.

A phishing email imitating a notification from DocuSign
Researchers also identified business email compromise attacks carried out via Amazon SES in which attackers impersonated employees and fabricated entire email threads with suppliers. These messages, often sent to finance departments, requested urgent payments and included PDF attachments containing only banking details – with no malicious links – making detection challenging.

An example of a business email compromise thread sent via Amazon SES
“We’ve seen attackers abuse trusted platforms before – like in cases with Google Tasks and Google Forms – where scammers rely on built-in notification mechanisms to deliver phishing links from legitimate domains like @google.com, effectively bypassing email filters and exploiting user trust. However, the abuse of Amazon SES represents a more advanced stage of this trend: instead of merely leveraging a platform’s notification features, attackers compromise cloud credentials and gain direct control over a trusted email-sending infrastructure. This allows them to scale attacks, fully customize messages, and deliver phishing emails that are hard to distinguish from legitimate business communications,” commented Roman Dedenok, Anti-Spam Expert at Kaspersky.
To avoid becoming victim of such attack schemes, Kaspersky recommends:
• Organizations should secure access to AWS by minimizing permissions, replacing static IAM keys with roles, enabling multi-factor authentication, restricting access (e.g., by IP), and regularly rotating and auditing credentials.
• Individual users should not trust emails based solely on the sender’s name or domain. Treat unexpected messages with caution, verify requests through a separate channel, and carefully inspect the links before following them, even if they appear to come from legitimate services.

Related Posts:

Madinet Masr Awards EGP 1.38 Billion for Origami at Taj City

إدراج 47 جامعة مصرية في تصنيف UI GreenMetric للاستدامة لعام 2026

حجر أساس لمشروع أعلاف باستثمارات صينية.. والزراعة تؤكد دعم الشراكة مع القطاع الخاص

Zoho Launches Agent-Ready Catalyst Platform for AI App Development

Turkish Airlines Named Europe’s Best Airline for the 11th Time

NILEWOOD Expands in Saudi Arabia at Saudi Wood Show 2026

Turkish Airlines and Air China Expand Codeshare Agreement

PATRIZIA appoints Hassan Awada as Senior Executive Officer to lead and accelerate Middle East expansion

آخر الأخبار
محافظ البنك المركزي يبحث مع مسؤول «التمويل الدولية» تعزيز التعاون المشترك وزير الأوقاف يلتقي المشرفات من الواعظات عبر تقنية الاتصال المرئي لمتابعة العمل الدعوي مصر تدين اقتحام المستوطنين الإسرائيليين للمسجد الأقصى المبارك بنك القاهرة وشركة فيزا يوقعان اتفاقية تعاون لدعم تطوير حلول ومنتجات دفع جديدة محافظ البنك المركزي ووزير الصناعة يطلقان صندوق إعادة هيكلة المصانع المتعثرة برأسمال مليار جنيه إف سي بايرن ميونخ يؤسس أكاديمية تعمل على مدار العام في الشرق الأوسط، ويقدّم نموذجه المتميز لتطوير ال... دولة الإمارات تجدد التزامها بالتنمية المستدامة خلال الاجتماع السنوي لمجلس محافظي البنك الآسيوي للاس... المكتب الطبي يعلن حصول «مستشفيات الشيخ خليفة» على اعتماد «مسار التميّز بامتياز» من «المركز الأمريكي ... مجموعة دلسكو تطلق برنامج «خطوة» للمواهب الوطنية لتطوير وتمكين الكفاءات الإماراتية شراكة بين "عزيزي" و"كوني" لتطوير أنظمة النقل العمودي في "برج عزيزي" أومودا وجايكو تستعد للكشف العالمي عن ‎OMODA X‎ وتقنيات هجينة وذكية جديدة في الصين مجلس الوزراء: تخصيص 150 فدانًا لـ "قصر العيني" في أكتوبر لا يعني التخلي عن موقعه التاريخي شركة «Rock Developments» تعزز ثقة عملائها وتحتفي بشركاء النجاح خلال «ROCK EXPO II» "مدن" تطلق المرحلة الأولى من مشروع "وديم غاردنز" أول مجمتع سكني في أبوظبي يتيح خيار الشراء بتمويل من... الاتحاد المصري لتمويل المشروعات يختتم اعمال المؤتمر العالمي لـ Cerise+SPTF 2026 بمشاركة دولية رئيس البورصة المصرية يستعرض تطورات السوق وفرص جذب الاستثمارات الأجنبية خلال مؤتمر «MEIRA» بدبي أوهانا للتطوير العقاري تطلق برنامجاً لتمكين الوسطاء العقاريين الإماراتيين خلال "ليفكس 2026" بنك ناصر الاجتماعي يطرح شهادة «رد الجميل» بعوائد مميزة بمناسبة اليوم العالمي للمسنين Workday تطلق أعمالها في الإمارات لدعم تحول المؤسسات في مجالات الموارد البشرية في عصر الذكاء الاصطناع... نيميتشك وتحالف البناء الأخضر السعودي يتعاونان لدعم البناء المستدام والرقمي في المملكة