Attackers Exploit Zendesk Authentication Issue to Flood Targets’ Inboxes with Corporate Notifications
Cybercriminals have identified a vulnerability in Zendesk's ticket submission process, enabling the exploitation of the system to send misleading support messages to users.
Cybercriminals have identified a vulnerability in Zendesk's ticket submission process, enabling the exploitation of the system to send misleading support messages to users.
When configured to accept anonymous requests, Zendesk can be misused to generate large volumes of emails appearing to originate from legitimate corporate domains. This was highlighted earlier this week when numerous rapid-fire email alerts were sent to an individual from over 100 different Zendesk clients.
The messages utilized the branding and reply-to addresses of well-known brands, making it difficult to differentiate between spam and genuine notifications.
Zendesk allows some customers to accept support requests without prior verification. This setting is intended to reduce user friction but can be exploited by attackers to send emails from any email address with custom subject lines. When the auto-responder trigger for ticket creation is activated, the system sends confirmation messages appearing to be from the customer's domain.
This was highlighted earlier this week when numerous rapid-fire email alerts were sent to an individual from over 100 different Zendesk clients.
Recipients see legitimate corporate branding and familiar addresses, although the messages are created by malicious actors. Replies to these messages are sent back to the legitimate customer support inbox, further perpetuating the illusion of a valid support case.
Zendesk is investigating additional safeguards and recommends customers adopt authenticated ticket workflows, which require email verification before auto-responders are triggered. Customers are advised to adjust their settings to block anonymous ticket creation or to implement verification steps like email confirmations or CAPTCHA challenges.
Organizations using Zendesk and similar platforms should review their ticket submission policies to prevent exploitation by malicious entities.
Based on reporting by GBHackers.
