Zendesk’s Phishy Business: How Scammers Turn Customer Support into a Scamport!

Zendesk’s platform has vulnerabilities that could let scammers impersonate trusted companies, leading to data theft and financial loss. Attackers exploit these gaps to create phishing emails and investment scams. CloudSEK’s report highlights the urgent need for vigilance, as unverified Zendesk subdomains can cleverly bypass spam filters and dupe unsuspecting users.

Pro Dashboard

Hot Take:

Zendesk: The Helpdesk of the Future… for Scammers! Who knew that customer support could get a little too supportive of phishing attacks? Time for Zendesk to hit the ‘troubleshoot’ button on its subdomain policies!

Key Points:

  • Zendesk’s platform can be exploited to facilitate phishing attacks and investment scams.
  • Attackers create authentic-looking URLs using free subdomains during trial sign-ups.
  • Phishing emails from Zendesk subdomains often bypass spam filters.
  • CloudSEK identified 1912 suspicious Zendesk subdomains since 2023.
  • CloudSEK recommends blacklisting unfamiliar subdomains and enhancing phishing detection measures.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?