Zendesk ticket systems hijacked in massive global spam wave
pMicrosoft New Windows LNK spoofing issues arent vulnerabilitiesppFake AI Chrome extensions with 300K users steal credentials emailsppApple fixes zeroday flaw used in extremely sophisticated attacksppMicrosoft February 2026 Patch Tuesday fixes 6 zerodays 58 flawsppMicrosoft fixes bug that blocked Google Chrome from launchingppRussia tries to block WhatsApp Telegram in communication blockadeppBitwarden introduces Cupid Vault for secure password sharingppCritical BeyondTrust RCE flaw now exploited in attacks patch nowppHow to access the Dark Web using the Tor BrowserppHow to enable Kernelmode Hardwareenforced Stack Protection in Windows 11ppHow to use the Windows Registry EditorppHow to backup and restore the Windows RegistryppHow to start Windows in Safe ModeppHow to remove a Trojan Virus Worm or other MalwareppHow to show hidden files in Windows 7ppHow to see hidden files in WindowsppQualys BrowserCheckppSTOPDecrypterppAuroraDecrypterppFilesLockerDecrypterppAdwCleanerppComboFixppRKillppJunkware Removal ToolppeLearningppIT Certification CoursesppGear GadgetsppSecurityppBest VPNsppHow to change IP addressppAccess the dark web safelyppBest VPN for YouTubeppppPeople worldwide are being targeted by a massive spam wave originating from unsecured Zendesk support systems with victims reporting receiving hundreds of emails with strange and sometimes alarming subject linesppThe wave of spam messages started on January 18th with people reporting on social media that they received hundreds of emailsppWhile the messages do not appear to contain malicious links or obvious phishing attempts the sheer volume and chaotic nature of the emails have made them highly confusing and potentially alarming for recipientsppThe emails are being generated by support platforms run by companies that use Zendesk for customer serviceppAttackers are abusing Zendesks ability to allow unverified users to submit support tickets which then automatically generate confirmation emails sent to the email address the attacker enteredppBecause Zendesk sends automated replies confirming that a ticket was received the attackers are able to turn these systems into a massspamming platform by interating through large lists of email addresses when creating fake support ticketsppCompanies whose Zendesk instances were seen impacted include Discord Tinder Riot Games Dropbox CD Projekt 2kcom Maya Mobile NordVPN Tennessee Department of Labor Tennessee Department of Revenue Lightspeed CTL Kahoot Headspace and LimeppThe emails have bizarre subjects with some pretending to be lawenforcement requests or corporate takedowns while others offer free Discord Nitro or say Help Me Many are also written in Unicode fonts to bold or decorate the fonts in multiple languagesppExamples includeppBecause the emails come from legitimate companies Zendesk support systems they are bypassing spam filters making them more intrusive and alarming than ordinary spam mail However as the emails dont contain phishing links they appear to be designed to troll recipients rather than to engage in malicious behaviorppMultiple companies have confirmed they were affected by the spam wave including DropBox and 2K who responded to tickets to tell recipients not be concerned and to ignore the emailsppYou may have recently received an automated response or notification regarding a support ticket that you did not submit We want to clarify why this might have happened and assure you there is no cause for concern wrote 2KppTo remove barriers and enhance your experience our system allows anyone to submit a support ticket provide feedback and report bugs without having to sign up for a dedicated support account and verify their email address This open policy means that anyone can potentially submit a ticket using any email addressppPlease rest assured that we do not act on any account or process sensitive requests without authenticated direct instruction from the account holderppZendesk told BleepingComputer that have introduced new safety features on their end to detect and stop this type of spam in the futureppWeve introduced new safety features to address relay spam including enhanced monitoring and limits designed to detect unusual activity and stop it more quicklyppWe want to assure everyone that we are actively taking steps and continuously improving to protect our platform and usersppZendesk previously warned customers about this type of abuse in a December advisory explaining that attackers were using Zendesk to send mass spam emails through what it called relay spamppThe company says that organizations can prevent this type of abuse by restricting ticket creation to only verified users and removing placeholders that allow any email addresses or ticket subject to be usedppModern IT infrastructure moves faster than manual workflows can handleppIn this new Tines guide learn how your team can reduce hidden manual delays improve reliability through automated response and build and scale intelligent workflows on top of tools you already useppZendesk spam wave returns floods users with Activate account emailsppMicrosoft cancels plans to rate limit Exchange Online bulk emailsppMicrosoft Exchange Online flags legitimate emails as phishingppCloud storage payment scam floods inboxes with fake renewalsppMicrosoft fixes Outlook bug blocking access to encrypted emailsppNot a member yet Register NowppMicrosoft February 2026 Patch Tuesday fixes 6 zerodays 58 flawsppMicrosoft 365 outage takes down admin center in North AmericappMalicious 7Zip site distributes installer laced with proxy toolppBring observability to browserbased AI and user activityppDiscover how to scale IT infrastructure reliably without adding toil or burnoutppAre your credentials in stealer logs Scan your organizations credential exposure nowppOverdue a password healthcheck Audit your Active Directory for freeppBuild cyber resilience with Wazuh The opensource SIEM XDR for proactive protectionppTerms of Use Privacy Policy Ethics Statement Affiliate DisclosureppCopyright 2003 2026 Bleeping Computer LLC All Rights ReservedppNot a member yet Register NowppRead our posting guidelinese to learn what content is prohibitedp