Threat actors are increasingly utilizing Amazon Simple Email Service (SES) to launch sophisticated phishing campaigns. By using legitimate AWS infrastructure, these attackers bypass standard authentication protocols such as SPF, DKIM, and DMARC. This tactic makes malicious emails difficult to distinguish from legitimate correspondence, posing a heightened risk to organizational email security.
Relevant URL: https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/