Zendesk ticket systems have been compromised in a coordinated spam campaign that exploited the platform's core functionality to distribute unsolicited content at scale. The attack leveraged legitimate ticket creation mechanisms to bypass traditional security filters, allowing threat actors to flood support queues with spam whilst appearing to originate from within the system itself. This represents a shift in targeting strategy: rather than pursuing data exfiltration or credential theft, attackers focused on operational disruption and resource exhaustion—forcing support teams to manually triage thousands of fraudulent tickets whilst legitimate customer issues languished unaddressed.
The implications for CX operations are immediate and multifaceted. Teams relying on Zendesk's automation and routing rules discovered these mechanisms could be weaponised against them, creating a false sense of legitimacy that made filtering difficult. The attack raises a critical question for platform administrators: if ticket systems can be hijacked at this scale, what other workflow automation features within CX platforms might be similarly vulnerable? This incident sits alongside broader OAuth and authentication compromises affecting Salesforce and related ecosystems, suggesting a pattern of attackers targeting the trust relationships embedded in enterprise CX infrastructure rather than the platforms themselves.
For support leaders, the operational cost is substantial. Beyond the immediate labour burden of spam removal, teams must now evaluate whether their current ticket validation, rate-limiting, and anomaly detection rules are sufficient—or whether they've been operating under the assumption that Zendesk's infrastructure would prevent this class of attack. Organisations should audit their ticket creation policies, API access controls, and integration permissions immediately, particularly those with public-facing ticket submission forms or third-party integrations that could serve as attack vectors.
Zendesk tickets hijacked in massive spam campaign MSN
Zendesk tickets hijacked in massive spam campaign MSN