Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

2nd spam wave exploits unsecured Zendesk systems | brief | SC Media

Zendesk

Unsecured Zendesk instances are being exploited in a second wave of spam attacks, targeting organisations that have failed to implement basic access controls or have left default credentials active. This follows an earlier exploitation phase and indicates attackers are systematically working through accessible instances to inject spam content, likely leveraging the platform's visibility and customer-facing nature to distribute malicious messages at scale. The attacks exploit a straightforward vulnerability: administrative access left exposed through misconfiguration rather than zero-day exploitation, meaning the barrier to entry for attackers is negligible.

For CX teams, this represents a dual operational and reputational risk that extends beyond typical spam concerns. When support systems become vectors for outbound spam, customer trust erodes immediately—tickets and communications lose credibility, and your organisation risks being flagged as a spam source by email providers and security vendors. The question becomes whether your team's security posture is reactive (patching after breach) or preventative (enforcing MFA, rotating credentials, auditing access logs regularly). Given the pattern of attacks across Zendesk and similar platforms like Freshdesk, this is not an isolated incident but a symptom of widespread configuration debt in the CX stack.

The strategic implication is clear: security hygiene in customer-facing systems must be treated as a CX priority, not delegated entirely to IT. Administrators should audit instance access immediately, enforce multi-factor authentication, disable unused API tokens, and review user permissions against the principle of least privilege. The cost of remediation now is negligible compared to the operational disruption and customer communication required after a compromise. This incident also signals that attackers are moving down the sophistication curve—they no longer need advanced exploits when basic misconfigurations remain endemic across the industry.