Spammers abuse Zendesk to flood inboxes with legitimate-looking emails, but why?
嗯,用户让我用中文帮他总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”或者“这篇文章”这样的开头,直接写描述就行。好的,我先看看这篇文章讲了什么。 文章主要讲的是用户收到大量来自Zendesk的垃圾邮件,这些邮件来自像Discord、Riot Games、Dropbox这样的公司。Zendesk是一个客服软件平台,帮助公司管理客户沟通。用户投诉说他们收到了超过1000封这样的邮件,但奇怪的是这些邮件里没有恶意链接或钓鱼信息。 问题出在Zendesk允许创建虚假支持票,使用不属于自己的邮箱地址。系统会发送确认邮件给提供的地址,如果公司没有限制提交票给验证用户的话。Zendesk在12月警告过这种情况,称为relay spam,攻击者滥用合法的自动化流程。 邮件标题看起来像是点击诱饵,比如“免费Discord Nitro”之类的。虽然可能有人测试系统或破坏系统,但攻击者似乎没有明确的目的。Zendesk已经引入了新的安全功能来检测和阻止这种垃圾邮件,并建议公司限制提交票的用户和标题。 建议用户删除或存档这些邮件,不要点击链接或打电话,通过验证渠道联系公司。 现在我要把这些信息浓缩到100字以内。重点包括:垃圾邮件来自Zendesk实例的可信公司;攻击者利用创建虚假支持票;没有恶意内容; Zendesk已采取措施;建议用户处理方式。 可能的结构:描述问题、原因、影响、解决措施和建议。 最终总结应该是:用户收到大量来自可信公司的Zendesk垃圾邮件,攻击者利用虚假支持票发送确认邮件。虽然无恶意内容,但可能用于测试或破坏系统。Zendesk已引入安全措施,并建议公司限制提交权限。 </think> 用户收到大量来自可信公司的 Zendesk 垃圾邮件,攻击者利用虚假支持票发送确认邮件。尽管无恶意内容,但可能用于测试或破坏系统。Zendesk 已采取安全措施,并建议公司限制提交权限以防止此类事件发生。 2026-1-23 16:4:8 Author: www.malwarebytes.com(查看原文) 阅读量:3 收藏

Short answer: we have no idea.

People are actively complaining that their mailboxes and queues are being flooded by emails coming from the Zendesk instances of trusted companies like Discord, Riot Games, Dropbox, and many others.

Zendesk is a customer service and support software platform that helps companies manage customer communication. It supports tickets, live chat, email, phone, and communication through social media.

Some people complained about receiving over 1,000 such emails. The strange thing ais that so far there are no reports of malicious links, tech support scam numbers, or any type of phishing in these emails.

The abusers are able to send waves of emails from these systems because Zendesk allows them to create fake support tickets with email addresses that do not belong to them. The system sends a confirmation mail to the provided email address if the affected company has not restricted ticket submission to verified users.

In a December advisory, Zendesk warned about this method, which they called relay spam. In essence it’s an example of attackers abusing a legitimate automated part of a process. We have seen similar attacks before, but they always served a clear purpose for the attacker, whereas this one doesn’t.

Even though some of the titles in use definitely are of a clickbait nature. Some examples:

  • FREE DISCORD NITRO!!
  • TAKE DOWN ORDER NOW FROM CD Projekt
  • TAKE DOWN NOW ORDER FROM Israel FOR Square Enix
  • DONATION FOR State Of Tennessee CONFIRMED
  • LEGAL NOTICE FROM State Of Louisiana FOR Electronic
  • IMPORTANT LAW ENFORCEMENT NOTIFICATION FROM DISCORD FROM Peru
  • Thank you for your purchase!
  •  Binance Sign-in attempt from Romania
  • LEGAL DEMAND from Take-Two interactive

So, this could be someone testing the system, but it just as well might be someone who enjoys disrupting the system and creating disruption. Maybe they have an axe to grind with Zendesk. Or they’re looking for a way to send attachments with the emails.

Either way, Zendesk told BleepingComputer that they introduced new safety features on their end to detect and stop this type of spam in the future. But companies are advised to restrict the users that can submit tickets and the titles submitters can give to the tickets.

Stay vigilant

In the emails we have seen the links in the tickets are legitimate and point to the affected company’s ticket system. And the only part of the emails the attackers should be able to manipulate is the title and subject of the ticket.

But although everyone involved tells us just to ignore the emails, it is never wrong to handle them with an appropriate amount of distrust.

  • Delete or archive the emails without interacting.
  • Do not click on the links if you have not submitted the ticket or call any telephone number mentioned in the ticket. Reach out through verified channels.
  • Ignore any actions advised in the parts of the email the ticket submitter can control.

We don’t just report on threats – we help protect your social media

Cybersecurity risks should never spread beyond a headline. Protect your social media accounts by using Malwarebytes Identity Theft Protection.

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.


文章来源: https://www.malwarebytes.com/blog/news/2026/01/spammers-abuse-zendesk-to-flood-inboxes-with-legitimate-looking-emails-but-why
如有侵权请联系:admin#unsafe.sh