The Containment Era is here. →Explore

Executive Summary

In May 2026, the threat actor known as PCPJack hijacked 230 cloud servers across Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to establish a covert SMTP email relay network. The compromised servers, located in the U.S., Europe, and Asia, were transformed into SMTP proxies, verified for mail relay capabilities, and synchronized to a downstream consumer every five minutes. This operation enabled the threat actor to send large volumes of emails while concealing their origin, potentially facilitating spam campaigns, phishing attacks, or other malicious activities.

This incident underscores the increasing sophistication of cloud-based attacks and the critical need for robust security measures in cloud environments. Organizations must implement stringent access controls, regularly monitor for unauthorized activities, and ensure that all cloud services are properly configured to prevent exploitation by threat actors.

Why This Matters Now

The PCPJack incident highlights the urgent need for organizations to secure their cloud infrastructures against sophisticated threat actors who exploit misconfigurations to establish covert operations, such as unauthorized email relay networks.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

PCPJack is a threat actor that hijacked 230 cloud servers across AWS, Google Cloud, and Azure to create a covert SMTP email relay network in May 2026.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware controls.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial access may have been constrained by enforcing strict identity-based access controls, reducing the likelihood of unauthorized entry.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been limited by enforcing strict segmentation policies, reducing the scope of accessible resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement may have been significantly constrained, limiting their ability to compromise additional servers.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's command and control communications could have been detected and disrupted, reducing their ability to coordinate compromised servers.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts may have been blocked, preventing unauthorized data transfer out of the network.

Impact (Mitigations)

The overall impact of the attack could have been significantly reduced, limiting the extent of data compromise and associated consequences.

Impact at a Glance

Affected Business Functions

  • Email Communication
  • Cloud Infrastructure Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive business communications and customer data due to unauthorized email relay.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within cloud environments.
  • Deploy East-West Traffic Security controls to monitor and restrict internal traffic, preventing unauthorized lateral movement.
  • Utilize Multicloud Visibility & Control solutions to gain comprehensive insights across cloud platforms and detect anomalous activities.
  • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data exfiltration.
  • Establish Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious behaviors promptly.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image