Zendesk Instances Leveraged in Mass Spam Campaigns
These articles are AI-generated summaries. Please check the original sources for full details.
Zendesk Spam Hints at Possible Relay Attacks
Zendesk, a popular CRM vendor, is experiencing a surge in spam emails originating from legitimate customer help desk instances, impacting numerous users. Reports indicate attackers are exploiting misconfigured email servers to relay spam, bypassing typical email filters, with one user reporting receiving 800 such emails.
Why This Matters
The reliance on CRM systems like Zendesk creates a single point of potential abuse for spammers, turning trusted domains into sources of malicious content. This undermines email trust and can lead to credential harvesting or malware distribution, costing organizations reputation damage and potential financial losses due to successful phishing attacks. The ideal model assumes secure server configurations, but widespread misconfigurations are a common reality.
Key Insights
- Relay spam attacks are not new: Zendesk issued an advisory regarding relay spam in December 2025.
- Abuse of help desks: Attackers exploit help desks to send spam messages, framing the target as the sender of the inquiry.
- Threat actor interest: Scattered Lapsus$ Hunters were observed preparing potential campaigns against Zendesk environments in November 2025.
Working Example
(No code provided in source text)
Practical Applications
- Use Case: ElevenLabs experienced a mass spam attack on its email ticketing system, requiring collaboration with Zendesk for resolution.
- Pitfall: Leaving default Zendesk configurations, such as unrestricted first-reply triggers, can allow unauthorized users to submit tickets and send spam.
References:
Continue reading
Next article
Microsoft & Anthropic MCP Servers at Risk of RCE, Cloud Takeovers
Related Content
Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign
Attackers misused Google Cloud Application Integration to send 9,394 phishing emails from Google domains, bypassing filters and stealing credentials.
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
Russian-linked phishing campaigns have compromised thousands of Signal and WhatsApp accounts by impersonating support services to seize control of high-value targets' communications.
Experts Report Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices
Cybersecurity researchers highlight a surge in botnet attacks exploiting PHP vulnerabilities, IoT weaknesses, and cloud misconfigurations, with DDoS capacities exceeding 20 Tbps and credential stuffing campaigns.