Cybersecurity Alert: Amazon SES Exploited for Phishing Attacks
A recent report from Kaspersky highlights a surge in phishing attacks exploiting the Amazon Simple Email Service (SES). Cybercriminals are increasingly using this trusted resource to send convincing emails that bypass standard security filters, thanks to exposed AWS Identity and Access Management keys available in public repositories.
The attacks target businesses, using fake notifications that mimic services like DocuSign and advanced business email compromise methods. This allows attackers to fabricate email threads and trick finance departments into making fraudulent payments.
To mitigate risks, companies are advised to restrict IAM permissions, enable multi-factor authentication, and regularly update access keys. Given the potential for widespread harm, this incident is categorized as a High risk.
Amazon has urged users to report any suspicious activity related to AWS resources, emphasizing the importance of securing exposed credentials.
Source: View Original Report
