Massive Email Bombing Campaign Exploits Zendesk's Lax Authentication
HighWhat happened
Cybercriminals exploited a lack of authentication in Zendesk's customer service platform to flood targeted email inboxes with thousands of malicious messages from various corporate customers.
Who is affected
Organizations using Zendesk with configurations allowing anonymous support requests, including companies like CapCom, CompTIA, Discord, GMAC, NordVPN, The Washington Post, and Tinder.
Why it matters
This abuse can tarnish the reputation of affected organizations, disrupt operations, and potentially expose sensitive information through overwhelming email floods.
How it could have been prevented
Implementing authentication for support request submissions and disabling anonymous ticket creation would mitigate such abuse.
Relevant professional terms
- Email Bombing
- A type of attack where an overwhelming number of emails are sent to a target to disrupt their email service.
- Anonymous Ticket Creation
- Allowing support tickets to be submitted without verifying the identity of the requester.
Recommended reading: Cyberheist Smokescreen: Email, Phone, SMS Floods
