Phishing Risks Rise as Zendesk Subdomains Facilitate Attacks
ID: 1b90e526-6579-5e7c-aa97-197d6976a09e
STIX ID: report--1b90e526-6579-5e7c-aa97-197d6976a09e
Feed Name: Infosecurity Magazine (News)
CloudSEK warns that Zendesk's free-trial subdomain registration and absent email verification enable attackers to register brand-like subdomains and craft convincing support emails and Help Center pages to conduct phishing and investment scams; 1,912 matching subdomains were identified, and mitigations recommended include blacklisting unfamiliar Zendesk subdomains, deploying phishing/URL detection, and regular employee training — no active campaigns have been observed but organizations are advised to act proactively.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
