Sunday 26 July 2026 20:52:53 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

Security Awareness & Social Engineering

Inbox Under Siege: Zendesk’s Support Systems Exploited in Relentless Spam Barrage

Published: 05 February 2026 11:45Category: Security Awareness & Social EngineeringAuthor: CRYSTALPROXY

Subtitle: Attackers turn customer service portals into spam cannons, overwhelming inboxes and exposing cracks in popular support software.

It began with a ping-then a torrent. All over the world, unsuspecting users opened their inboxes to find them bursting at the seams with hundreds of “Activate your account” emails, each one seemingly from a different company. But none of these users had signed up for anything. Instead, they found themselves caught in the crossfire of a renewed cyber assault, as attackers once again weaponized Zendesk’s popular support ticketing system to unleash a global spam wave.

The Anatomy of a Spam Tsunami

The latest wave of spam-beginning abruptly this week-has left security researchers and ordinary users alike scrambling for answers. Reports flooded social media as inboxes filled up with automated messages, all triggered through Zendesk’s customer support portals. The emails, bearing subject lines like “Activate your account,” mimic legitimate system notifications, making them difficult to distinguish from real support communications.

Why is this happening? The answer lies in how Zendesk’s ticketing system works. Many companies allow anyone to submit a support request through a web form. Each submission triggers an automated confirmation email to whatever address is entered-no verification required. Attackers have seized on this design, feeding lists of victim email addresses into exposed forms en masse. The result: a deluge of confirmation emails from real companies’ domains, all landing directly in users’ inboxes and slipping past most spam filters.

Déjà Vu: Lessons Unlearned?

This isn’t the first time Zendesk has found itself at the center of a spam epidemic. In January 2024, a similar attack exploited the same vector, prompting Zendesk to promise new safety features: enhanced monitoring, activity limits, and improved detection of suspicious behavior. Yet, as this latest campaign proves, attackers are still finding ways around those safeguards.

The implications go beyond annoyance. Not only do these attacks erode trust in customer support systems, but they also risk masking more serious threats. When users are overwhelmed by spam, it becomes easy to miss legitimate alerts-or fall for phishing attempts camouflaged among the flood.

Zendesk has previously advised its customers to restrict ticket creation to verified users and to avoid allowing arbitrary email addresses or subjects. But not all organizations implement these controls, leaving their portals vulnerable to exploitation. As of publication, Zendesk has not commented on the renewed wave, but the company’s earlier guidance suggests that technical fixes alone may not be enough without stronger configuration and vigilance from its customers.

Conclusion: The Relentless Evolution of Abuse

This new spam tsunami underscores a hard truth about digital infrastructure: every convenience can be turned into a weapon. As attackers adapt and innovate, even well-intentioned systems like Zendesk’s support portals can become vectors for disruption. Until companies tighten the controls on their customer service entry points, inboxes everywhere may remain vulnerable to the next wave.

WIKICROOK

  • Spam wave: A spam wave is a sudden, large-scale burst of unsolicited emails sent to many users, often aiming to spread scams, phishing, or malware.
  • Support ticketing system: A support ticketing system manages, tracks, and organizes customer or internal support requests to streamline issue resolution and improve service efficiency.
  • Relay spam: Relay spam is the abuse of legitimate email servers to send unsolicited emails, making spam appear trustworthy and harder to filter or block.
  • Spam filter: A spam filter is software that detects and blocks unwanted or suspicious emails, helping protect users from scams and reducing inbox clutter.
  • DDoS (Distributed Denial of Service): A DDoS attack overwhelms a website or service with excessive traffic, disrupting normal operations and making it unavailable to real users.