HomeSecurityNew Zendesk spam campaign - Users' Inboxes flooded

New Zendesk spam campaign – Users' inboxes flooded

A new wave of spam emails appears to be sweeping through inboxes around the world, causing concern and confusion. This time, reports indicate that the attacks are once again linked to automated emails generated through vulnerable or poorly configured Zendesk support systems, which many companies use for customer service.

Zendesk spam campaign

Recipients describe a veritable “storm” of messages, with hundreds of notifications arriving within minutes, often with strange or even alarming subject lines.

Fake “Account Activation” notifications flood inboxes

Since yesterday, many users on social networks have reported receiving mass emails with titles such as "Account Activation", "Registration Confirmation" or other notifications that resemble responses from support departments.

See also: DEAD#VAX campaign deploys AsyncRAT via Phishing VHD files

What's strange is that the messages appear completely legitimate, as if they come from real companies that use Zendesk for ticketing. However, the recipients insist that they have never registered or submitted a support request.

Security researcher Jonathan Leitschuh wrote on LinkedIn that his email appears to be being used in a form of “DDoS” against support systems, with the aim of continuously triggering automated emails.

How to bypass spam filters

Unlike classic phishing campaigns, here the attackers do not send the emails directly. Instead, they exploit Zendesk's request submission forms.

Every time someone enters an email address into a support ticket, the system automatically sends a confirmation message. This allows attackers to turn legitimate corporate portals into spam relay machines.

See also: Chinese hackers Amaranth-Dragon exploit WinRAR vulnerability

New Zendesk spam campaign - Users' inboxes flooded

Because the emails come from real domains and infrastructure, they often go under the radar of spam filters and end up directly in the inbox.

The déjà vu of January

The incident is reminiscent of a massive global spam campaign that was reported in January, when attackers exploited the ability to submit requests from unverified users.

The campaign began around January 18th and affected many companies, with users receiving hundreds of messages with strange themes.

Among the organizations that had confirmed they were affected were giants like Dropbox and 2K, who had asked users to ignore the emails.

Zendesk's moves and the gaps that remain

Zendesk said at the time that it was introducing new security measures, such as enhanced monitoring, sending limits, and unusual activity detection mechanisms.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, in an advisory notice of December 2025, it had warned its customers about the abuse of this type, which it called “relay spam”.

The company had proposed practical measures, such as allowing tickets to be created only by verified users and removing placeholders that allow any email or ticket subject.

See also: Abuse of Google & Microsoft to target corporate users

However, the new wave shows that attackers may still find ways to exploit exposed support portals.

New Zendesk spam campaign - Users' inboxes flooded

What users can do

Experts advise users not to panic, but also to avoid clicking on links in such emails, even if they appear legitimate. Also, using filters, reporting as spam, and activating stronger protection mechanisms can reduce the annoyance.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS