https://krebsonsecurity.com/2025/10/email-bombs-exploit-lax-authentication-in-zendesk/ Advertisement [3] Advertisement [2] Krebs on Security Skip to content * Home * About the Author * Advertising/Speaking Email Bombs Exploit Lax Authentication in Zendesk October 17, 2025 12 Comments Cybercriminals are abusing a widespread lack of authentication in the customer service platform Zendesk to flood targeted email inboxes with menacing messages that come from hundreds of Zendesk corporate customers simultaneously. Zendesk is an automated help desk service designed to make it simple for people to contact companies for customer support issues. Earlier this week, KrebsOnSecurity started receiving thousands of ticket creation notification messages through Zendesk in rapid succession, each bearing the name of different Zendesk customers, such as CapCom, CompTIA, Discord, GMAC, NordVPN, The Washington Post, and Tinder. The abusive missives sent via Zendesk's platform can include any subject line chosen by the abusers. In my case, the messages variously warned about a supposed law enforcement investigation involving KrebsOnSecurity.com, or else contained personal insults. Moreover, the automated messages that are sent out from this type of abuse all come from customer domain names -- not from Zendesk. In the example below, replying to any of the junk customer support responses from The Washington Post's Zendesk installation shows the reply-to address is help@washpost.com. [zendeskwapo] One of dozens of messages sent to me this week by The Washington Post. Notified about the mass abuse of their platform, Zendesk said the emails were ticket creation notifications from customer accounts that configured their Zendesk instance to allow anyone to submit support requests -- including anonymous users. "These types of support tickets can be part of a customer's workflow, where a prior verification is not required to allow them to engage and make use of the Support capabilities," said Carolyn Camoens, communications director at Zendesk. "Although we recommend our customers to permit only verified users to submit tickets, some Zendesk customers prefer to use an anonymous environment to allow for tickets to be created due to various business reasons." Camoens said requests that can be submitted in an anonymous manner can also make use of an email address of the submitter's choice. "However, this method can also be used for spam requests to be created on behalf of third party email addresses," Camoens said. "If an account has enabled the auto-responder trigger based on ticket creation, then this allows for the ticket notification email to be sent from our customer's accounts to these third parties. The notification will also include the Subject added by the creator of these tickets." Zendesk claims it uses rate limits to prevent a high volume of requests from being created at once, but those limits did not stop Zendesk customers from flooding my inbox with thousands of messages in just a few hours. "We recognize that our systems were leveraged against you in a distributed, many-against-one manner," Camoens said. "We are actively investigating additional preventive measures. We are also advising customers experiencing this type of activity to follow our general security best practices and configure an authenticated ticket creation workflow." In all of the cases above, the messaging abuse would not have been possible if Zendesk customers validated support request email addresses prior to sending responses. Failing to do so may make it easier for Zendesk clients to handle customer support requests, but it also allows ne'er-do-wells to sully the sender's brand in service of disruptive and malicious email floods. This entry was posted on Friday 17th of October 2025 07:26 AM A Little Sunshine Latest Warnings The Coming Storm Web Fraud 2.0 CapCom Carolyn Camoens CompTIA Discord GMAC NordVPN The Washington Post Tinder Zendesk Post navigation - Patch Tuesday, October 2025 'End of 10' Edition 12 thoughts on "Email Bombs Exploit Lax Authentication in Zendesk" 1. Phil October 17, 2025 Zendesk instance to allow anyone to submit support requests -- including anonymous users. -> That should be defaulted to off along with the ability to pick any email or should really in this day and age, the option should be removed altogether. It's just lazy programming. Reply - 1. Matt C. October 17, 2025 What I really hate is sites that only accept gmail as a valid email address -- even if you have your own domain. Clearly other email sites should work also (I'm not even talking about only comment sections or things Zendesk does; some places won't even let you do a damn thing unless 'google' is involved). Mentioning because, cool banner ad/conference thing and also relevant. Might check it out. Reply - 1. Catwhisperer October 17, 2025 But that's because they are in the Google ecosystem or are using a tool that authenticates to something that is in that ecosystem. For instance, Youtube. But I don't see that to be the norm, like on banking or overseas sites like BBC. Reply - 1. Matt C. October 17, 2025 I see the value of Google for a number of things. I was one of the people that had a Google email address when it was invite-only. It's changed a lot since then, though, and its 'motto' changed accordingly (but how much of that is due to users that most people don't categorize as 'bad users' but nevertheless introduce untrustworthiness into every environment they enter, knowingly or not?). Gmail has been consistently better for some things than others. But some things I just don't want Google to know about. Well, most things. And creeping AI sure makes that happen. There is more privacy for most people not in the United States. Most countries don't allow every person's name and personally identifiable information to be indexed eternally on websites and searchable on google for instance. In fact almost no other country does. Come to think of it, only the United States does. Reply - 2. mealy October 17, 2025 FWIR its default is validate but can be configured to non-validation 'for various business reasons'. So they give you the rope. I can see that being useful in some cases. You 'can' side-validate other ways. Throttling alone is obviously not enough to deal with bots, so if you leave it wide open it's exactly that. Optional feature meets abuse and becomes bug. Reply - 1. Matt C. October 17, 2025 Not to get into the whole 'bug' argument with you, but it's not really a bug OR a 'feature'. Reply - 2. John Murray October 17, 2025 Why Zendesk is NOT validating email addresses is beyond me Reply - 1. Matt C. October 17, 2025 I can see plenty of reasons for not validating email addresses. Doesn't make this, of course, more pleasant for Herr Krebs, but there are good reasons to not do so. Reply - 3. nja October 17, 2025 Not lazy programming, lazy management, this was a configuration option and I know our development team warns against this sort of thing and we are often ignored or overruled. Reply - 4. Impossibly Stupid October 17, 2025 > Camoens said requests that can be submitted in an anonymous manner can also make use of an email address of the submitter's choice. Then you haven't really made it anonymous, have you? Zendesk is hardly the only platform guilty of this, either. I've *frequently* given something like `justfixit@example.com` on feedback forms that "require" an email address when I do not want to engage with them beyond a simple bug report. It should come as no surprise that bad actors would instead use that mechanism as an attack vector. Validations are Mailing List Management 101, too. Zendesk is big enough to know better. I'd be curious if they gave you any details on what IP addresses were the source of the fake tickets. There really ought to be a followup on what *actual* actions they take against the abusers of their system. It's just not enough to be "actively investigating" mitigations. Reply - 5. Your friend Y October 17, 2025 Hey Kreb, did you notice anything that reminds you about the first generation Lizard Squad? Yes, you are correct. They now have more young guys working for them (do the dirty job and get busted by feds). But you do know all of them and pretty well. And no, MLT is not in that group as he is most likely under some bridge begging for a dose. Reply - 1. Not a great comic October 17, 2025 Far more noxious than them. Reply - Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment * [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] Advertisement [5] Advertisement Mailing List Subscribe here Search KrebsOnSecurity Search for: [ ] [Search] Recent Posts * Email Bombs Exploit Lax Authentication in Zendesk * Patch Tuesday, October 2025 'End of 10' Edition * DDoS Botnet Aisuru Blankets US ISPs in Record DDoS * ShinyHunters Wage Broad Corporate Extortion Spree * Feds Tie 'Scattered Spider' Duo to $115M in Ransoms Story Categories * A Little Sunshine * All About Skimmers * Ashley Madison breach * Breadcrumbs * Data Breaches * DDoS-for-Hire * DOGE * Employment Fraud * How to Break Into Security * Internet of Things (IoT) * Latest Warnings * Ne'er-Do-Well News * Other * Pharma Wars * Ransomware * Russia's War on Ukraine * Security Tools * SIM Swapping * Spam Nation * Target: Small Businesses * Tax Refund Fraud * The Coming Storm * Time to Patch * Web Fraud 2.0 Why So Many Top Hackers Hail from Russia [computered-580x389] (c) Krebs on Security - Mastodon