logo

Google: New UNC6783 hackers steal corporate Zendesk support tickets

ID: 21452207-dcdd-5a78-ba20-bc3679396b73

STIX ID: report--21452207-dcdd-5a78-ba20-bc3679396b73

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Google Threat Intelligence Group reports that UNC6783 targets BPOs to steal corporate Zendesk support tickets and other sensitive data via social engineering, phishing, spoofed Okta login pages (domains like <org>.zendesk-support<##>.com), and clipboard-stealing phishing kits that can bypass MFA; the actor has also distributed fake security updates to deliver RATs and subsequently extorts victims, with claims of large breaches (e.g., an alleged Adobe data theft). Mandiant recommends FIDO2 keys, live-chat monitoring, blocking spoofed domains, and auditing MFA enrollments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.