logo

Facilitating Phishing and Pig Butchering Activities using Zendesk Infrastructure [Bait & Switch Mode]

ID: dcfe5eda-71ab-502e-a6d4-69b2a029668c

STIX ID: report--dcfe5eda-71ab-502e-a6d4-69b2a029668c

Feed Name: CloudSEK Blog

Threat Score
50/100

Date Published: 2025-01-20

Date Updated: 2026-04-27

...
...

This advisory demonstrates how attackers can register Zendesk subdomains to impersonate companies and deliver phishing pages (including investment “pig butchering” scams). Based on XVigil’s capture of 1,912 matching instances, the report shows registration and invitation workflows, explains how tickets and links can land in recipients' primary inboxes without validation, outlines impacts (data theft, financial and legal risk), and recommends blacklisting unknown Zendesk instances, using XVigil detection, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.