Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Threat actors are harvesting exposed AWS IAM access keys from public code repositories, then using those keys to send phishing and business email compromise emails through Amazon’s own Simple Email Service (SES). Because SES is a legitimate AWS service, these emails pass all standard email authentication checks, SPF, DKIM, and DMARC, making them indistinguishable from trusted senders at the email gateway layer. Organizations using AWS SES or those whose employees receive DocuSign-branded communications face elevated phishing risk that cannot be blocked by conventional email filtering alone.

Author

Tech Jacks Solutions