ctipilot.ch

Amazon SES abuse for authenticated BEC/phishing (Kaspersky, 2026-05-04)

campaign · technique:amazon-ses-bec-2026

Coverage timeline
1
first 2026-05-08 → last 2026-05-08
Briefs
1
1 distinct
Sources cited
18
17 hosts
Sections touched
1
research
Co-occurring entities
6
see Related entities below

Story timeline

  1. 2026-05-08CTI Daily Brief — 2026-05-08
    researchFirst coverage (96h old at publication; outside 72h window but first coverage). SES API credentials harvested from misconfigured S3/GitHub; SPF/DKIM pass; targets European finance/manufacturing; BEC and credential phishing. [SINGLE-SOURCE-OTHER]

Where this entity is cited

  • research1

Source distribution

  • securityweek.com2 (11%)
  • bankinfosecurity.com1 (6%)
  • securelist.com1 (6%)
  • access.redhat.com1 (6%)
  • bleepingcomputer.com1 (6%)
  • cloud.google.com1 (6%)
  • github.com1 (6%)
  • gizmodo.com1 (6%)
  • other9 (50%)

Related entities

All cited sources (18)

Items in briefs about Amazon SES abuse for authenticated BEC/phishing (Kaspersky, 2026-05-04) (2)

Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today `[SINGLE-SOURCE]`

From CTI Daily Brief — 2026-06-21 · published 2026-06-21 · view item permalink →

One Medical (Amazon) confirmed on 2026-06-13 that an unauthorised party accessed a legacy third-party file-storage system retaining archived records for One Medical Seniors (formerly Iora Health), during a 2026-06-08 to 2026-06-11 window, affecting demographic and clinical records for patients at nine clinics (BankInfoSecurity, 2026-06-19). One Medical states the breach is confined to that legacy system. Separately, ShinyHunters claims theft of 8.8 TB and set a 2026-06-22 negotiation deadline — today — but the company has not confirmed ShinyHunters' involvement or the data volume, and no sample has been released to validate the claim. [SINGLE-SOURCE] — see § 7.

Defender takeaway: ShinyHunters' maximalist-claim-then-short-deadline pattern recurred across multiple victims this week (Kodak, covered 2026-06-20, among them); the confirmed subset is consistently smaller than the claimed one. Audit legacy and "decommissioned" third-party storage that may still hold archival PII/clinical data outside normal operational scope, and keep those systems inside third-party risk assessments. The passing 06-22 deadline is the near-term monitoring trigger: data release would corroborate the 8.8TB vector, silence suggests a pivot to negotiation.

Amazon SES weaponised for authenticated phishing and BEC (Kaspersky, 2026-05-04, ~96 h)

From CTI Daily Brief — 2026-05-08 · published 2026-05-08 · view item permalink →

Kaspersky researchers documented a campaign technique using legitimate Amazon Simple Email Service (SES) accounts to deliver attacker-crafted phishing and business-email-compromise (BEC) lures. Because messages originate from genuine SES infrastructure, SPF and DKIM authentication passes and messages evade most email security gateway filters based on sender reputation. Attackers obtain SES API credentials from publicly exposed AWS configuration files (S3 bucket misconfigurations, leaked GitHub repositories). Observed campaign goals include invoice-fraud lures targeting finance departments and credential phishing pages hosted on AWS infrastructure. Kaspersky observed targeting of finance departments at European manufacturing firms. This report is approximately 96 hours old at publication; first coverage in this brief series.