Zendesk security breach: global spam attack hits major companies

In today’s increasingly connected world, even customer support systems can become targets of sophisticated cyber attacks. In January 2026, a major spam campaign targeted Zendesk, a popular ticket management platform used by thousands of companies worldwide.

## The incident in detail

Starting from January 18, 2026, Zendesk ticketing systems were compromised in a massive spam campaign. The attackers exploited a vulnerability in the system that allows unverified users to submit support requests, which automatically generate confirmation emails sent to addresses specified by the attackers. Among the affected companies are major names like Discord, Tinder, Riot Games, Dropbox, CD Projekt, NordVPN, as well as government entities such as the Department of Labor and the Tennessee Department of Revenue.

Victims reported receiving hundreds of spam emails with unusual subject lines in short time intervals. What made this attack particularly effective is that the emails came from legitimate Zendesk systems, thus bypassing anti-spam filters. The campaign did not distribute malware nor contain phishing links, but rather messages with false requests for help or fake communications from law enforcement.

## The impact and implications

This incident highlights a significant vulnerability in customer support systems that many organizations consider reliable. When legitimate systems are exploited in this way, normal defense mechanisms such as anti-spam filters become ineffective, exposing users and companies to a high volume of unwanted communications. Furthermore, this type of attack can undermine trust in official communication channels and create confusion among users about which messages are legitimate.

## Countermeasures and protection

In response to the incident, Zendesk implemented several security measures to prevent similar attacks in the future, including advanced monitoring, limits on unusual activities, and new security features specifically designed to counter “relay” type spam. For companies using Zendesk or similar systems, it is advisable to verify their security configurations and consider implementing additional layers of authentication.

End users should remain vigilant about emails received, even if they appear to come from legitimate sources, and report suspicious activities to their respective service providers.

## Key points to remember:

  • Attackers exploited a legitimate Zendesk feature to send spam through official and trusted communication channels
  • The attack affected major technology companies and government entities, demonstrating that no organization is immune to these threats
  • The security measures implemented by Zendesk highlight the importance of continuous monitoring and updating of protection systems

Sources:
TechRadar Pro Security, “Zendesk tickets hijacked in massive spam campaign”
DataBreaches.net, “Zendesk ticket systems hijacked in massive global spam wave”
The Hacker News, “ThreatsDay Bulletin: Pixel Zero-Click”

Source: DataBreaches