logo

Spammers abuse Zendesk to flood inboxes with legitimate-looking emails, but why?

ID: 2863033d-bff6-5205-a5d2-807e623032d6

STIX ID: report--2863033d-bff6-5205-a5d2-807e623032d6

Feed Name: Malwarebytes Blog

Date Published: 2026-01-23

Date Updated: 2026-04-28

...
...

A widespread “relay spam” campaign is abusing Zendesk ticketing workflows to flood users’ inboxes with legitimate-looking emails from brands like Discord, Riot Games, and Dropbox by exploiting open ticket submission settings; while links point to legitimate ticket systems and no phishing or malware is observed, the activity is disruptive. Zendesk has deployed new safeguards, and affected organizations should restrict ticket creation to verified users and constrain ticket titles, while recipients should delete unsolicited messages and avoid interacting with any links or phone numbers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.