Sapior LogoSapior

Are These Agencies Offering AWS Vouchers Legit? Here’s How to Spot a Scam

Third-party agencies offering free AWS credits often turn out to be phishing operations. Here’s how to separate legitimate AWS promotions from scams.

If you’ve spent any time in developer communities, your inbox has probably been hit by a message like: “Get $5,000 in AWS credits instantly – just verify your account with our partner agency.” It sounds like a fast track to free compute. In reality, it’s almost always a trap.

We’ve watched these offers multiply in subreddits, Discord servers, and even LinkedIn DMs. The pitch is polished, the landing pages look convincing, and the sense of urgency is high. But on the other side of that link is rarely a legitimate AWS promotion – it’s a credential-harvesting operation or a front for credit fraud.

The Flood of Too-Good-to-Be-True Offers

Scammers have become remarkably good at mimicking official AWS branding. They spin up domains like `awscredits-accelerator.com` or `cloudgrant.host` and send cold emails that reference “AWS Activate for freelancers” or “AWS startup credits without a business.” These offers exploit a real need: AWS free credits are valuable, and the official path can feel opaque.

On platforms like Reddit’s r/aws, threads about voucher legitimacy appear weekly. The pattern is consistent. A user receives an unsolicited offer, often through a Telegram group or a “grant brokering” service. They’re asked to provide their AWS account ID, or worse, to hand over root credentials so the agency can “apply the credit.” The credits never materialize, and the account is ransacked for crypto mining or data exfiltration.

Anatomy of an AWS Voucher Scam

These scams follow a predictable structure. Recognizing the anatomy is your first line of defense.

Red Flags in Unsolicited Messages

**Urgency without verification.** Scammers insist the offer expires in hours, skipping AWS’s standard review process.

**Request for credentials.** No legitimate AWS partner will ever ask for your root credentials, IAM access keys, or MFA codes.

**Generic or slightly misspelled domains.** Look closely at the sender’s email domain. Real AWS communications come from `@amazon.com`, `@aws.amazon.com`, or `@awscloud.com`. A domain like `@awscredits.net` is a fabrication.

**Payment up front.** Offers that require a “service fee” or purchase of a “token” to unlock credits are pure scams.

**No traceable company information.** If the agency has no LinkedIn presence, no verifiable physical address, and no case studies, treat it as hostile.

Real-World Patterns from Developer Communities

Reddit and Hacker News are full of post-mortems. One recent thread described an “AWS credit broker” that directed users to a fake AWS console clone. The page captured the login, passed it to the real AWS, and then initiated EC2 GPU instances for mining. By the time the user received the billing alert, the damage was done. Another common variant involves offers posted in public Slack groups: “DM me for AWS credits. I work at [big company] and have unused codes.” The codes are often stolen or already redeemed.

The Legitimate Path: AWS Activate

AWS does provide free credits – but through a tightly controlled program. The official channel is **AWS Activate**, designed for startups and early-stage companies.

According to the AWS Activate documentation, credits are issued directly to your AWS account after you apply and are approved. There is no intermediary agency that “applies credits for you.” Approved partners, such as venture capital firms, accelerators, and incubators, can nominate startups for credits, but the actual credit issuance and management happens inside the AWS console. You’ll see the credits in your **Billing Dashboard** under the Credits section. If you can’t find them there, you haven’t received anything real.

An additional safety net is the **AWS Free Tier**, which doesn’t require any third-party interaction at all. It’s available to every new AWS account and includes services like EC2 t2.micro, S3, and Lambda – no voucher codes required.

What to Do If You’ve Been Targeted

If you’ve already clicked a suspicious link or shared partial account details, act immediately:

1. **Rotate all AWS access keys.** In the IAM console, deactivate and delete compromised keys.

2. **Review CloudTrail logs** for any unauthorized activity, particularly in unused regions.

3. **Check Identity and Access Management (IAM)** for unexpected users or roles; delete any you don’t recognize.

4. **Contact AWS Support** to flag the security incident and get billing protection guidance.

5. **Reset root account credentials** and enable MFA if not already active.

If you merely received the email and didn’t engage, report it to AWS by forwarding it to `stop-spoofing@amazon.com`.

Stay Skeptical. Use the Console.

The developer-tools ecosystem thrives on free tiers and startup credits, but the distribution model is rarely “message this agency.” SAPiOR, for instance, offers clear, transparent access to its browser automation infrastructure without back-channel deals. That’s the standard any credible infrastructure provider should meet.

When you see an AWS voucher offer, close the email and open your AWS console. If the credits aren’t there by the time you’ve logged in, they never really existed.

Are AWS Voucher Agencies Legit? How to Spot a Scam | Sapior