A new wave of spam emails appears to be sweeping through inboxes around the world, causing concern and confusion. This time, reports indicate that the attacks are once again linked to automated emails generated through vulnerable or poorly configured Zendesk support systems, which many companies use for customer service.

Recipients describe a veritable “storm” of messages, with hundreds of notifications arriving within minutes, often with strange or even alarming subject lines.
Fake “Account Activation” notifications flood inboxes
Since yesterday, many users on social networks have reported receiving mass emails with titles such as "Account Activation", "Registration Confirmation" or other notifications that resemble responses from support departments.
See also: DEAD#VAX campaign deploys AsyncRAT via Phishing VHD files
What's strange is that the messages appear completely legitimate, as if they come from real companies that use Zendesk for ticketing. However, the recipients insist that they have never registered or submitted a support request.
Security researcher Jonathan Leitschuh wrote on LinkedIn that his email appears to be being used in a form of “DDoS” against support systems, with the aim of continuously triggering automated emails.
How to bypass spam filters
Unlike classic phishing campaigns, here the attackers do not send the emails directly. Instead, they exploit Zendesk's request submission forms.
Every time someone enters an email address into a support ticket, the system automatically sends a confirmation message. This allows attackers to turn legitimate corporate portals into spam relay machines.
See also: Chinese hackers Amaranth-Dragon exploit WinRAR vulnerability

Because the emails come from real domains and infrastructure, they often go under the radar of spam filters and end up directly in the inbox.
The déjà vu of January
The incident is reminiscent of a massive global spam campaign that was reported in January, when attackers exploited the ability to submit requests from unverified users.
The campaign began around January 18th and affected many companies, with users receiving hundreds of messages with strange themes.
Among the organizations that had confirmed they were affected were giants like Dropbox and 2K, who had asked users to ignore the emails.
Zendesk's moves and the gaps that remain
Zendesk said at the time that it was introducing new security measures, such as enhanced monitoring, sending limits, and unusual activity detection mechanisms.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, in an advisory notice of December 2025, it had warned its customers about the abuse of this type, which it called “relay spam”.
The company had proposed practical measures, such as allowing tickets to be created only by verified users and removing placeholders that allow any email or ticket subject.
See also: Abuse of Google & Microsoft to target corporate users
However, the new wave shows that attackers may still find ways to exploit exposed support portals.

What users can do
Experts advise users not to panic, but also to avoid clicking on links in such emails, even if they appear legitimate. Also, using filters, reporting as spam, and activating stronger protection mechanisms can reduce the annoyance.
Source: www.bleepingcomputer.com
