Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Robot Dogs on Patrol: How AI Can Make Law Enforcement Safer, Smarter, and More Effective

      August 30, 2026

      Trump Launches Plan for U.S. Space Academy to Build America’s Next Space Workforce

      August 30, 2026

      Federal Appeals Court Backs State Authority Over Kalshi Sports Contracts

      August 30, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        ICE Explores Robot Dogs to Protect Agents During Immigration Enforcement

        August 30, 2026

        Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

        August 29, 2026

        Chinese Bot Network Targets U.S. Data-Center And Energy Debate

        August 29, 2026

        Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

        August 29, 2026

        American-Made Space Armor Heads to Orbit on SpaceX Mission

        August 29, 2026
      • AI

        ICE Explores Robot Dogs to Protect Agents During Immigration Enforcement

        August 30, 2026

        Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

        August 29, 2026

        Altman Concedes AI Industry Has Failed to Make Its Case to the Public

        August 29, 2026

        Chinese Bot Network Targets U.S. Data-Center And Energy Debate

        August 29, 2026

        Free AI Boot Camp Expands Technology Training for Chicago High School Students

        August 29, 2026
      • Security

        Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

        August 29, 2026

        Chinese Bot Network Targets U.S. Data-Center And Energy Debate

        August 29, 2026

        Password-Free Flock Cameras Raise New Questions About America’s Expanding Surveillance Network

        August 29, 2026

        Dallas Police Extend Flock Camera Data Retention to One Year

        August 29, 2026

        Uber Adds Live Video Monitoring for Teen Rides

        August 28, 2026
      • Health

        Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

        August 29, 2026

        Silicon Valley Parents Push Back Against Classroom Technology and AI

        August 27, 2026

        Moderna’s Cancer Vaccine Breakthrough Revives Hope for Personalized Oncology

        August 25, 2026

        AI Chatbots Expand Access While Raising New Mental Health Concerns

        August 23, 2026

        TikTok Agrees to $400 Million Settlement Over Children’s Privacy Violations

        August 23, 2026
      • Science

        Trump Launches Plan for U.S. Space Academy to Build America’s Next Space Workforce

        August 30, 2026

        Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

        August 29, 2026

        American-Made Space Armor Heads to Orbit on SpaceX Mission

        August 29, 2026

        Washington Deepens Strategic Rare Earth Investment to Counter China

        August 26, 2026

        SpaceX Confirms $100 Billion Louisiana Starbase Expansion

        August 26, 2026
      • Tech

        Gen Z’s Fading Handwriting Skills Raise New Concerns About Communication

        August 28, 2026

        OpenAI Infrastructure Shake-Up Continues as Data Center Chief Departs Ahead of IPO

        August 27, 2026

        New York Overtakes San Francisco as Largest U.S. Tech Talent Market

        August 25, 2026

        Google AI Bias Controversy Raises Fresh Questions About Reliability

        August 25, 2026

        San Francisco’s High-Tech Public Toilet Rollout Stalls After Repeated Breakdowns

        August 25, 2026
      TallwireTallwire
      Home»Tech»Zendesk Customers Under Siege As Scattered LAPSUS$ Hunters Launch Phishing Blitz
      Tech

      Zendesk Customers Under Siege As Scattered LAPSUS$ Hunters Launch Phishing Blitz

      Updated:January 4, 20264 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      Zendesk Customers Under Siege As Scattered LAPSUS$ Hunters Launch Phishing Blitz
      Zendesk Customers Under Siege As Scattered LAPSUS$ Hunters Launch Phishing Blitz
      Share
      Facebook Twitter LinkedIn Pinterest Email

      The cyber-crime collective known as Scattered LAPSUS$ Hunters (SLH) has begun targeting users of Zendesk in a fresh phishing campaign, according to a new alert by cybersecurity firm ReliaQuest. Researchers have identified more than 40 typosquatted and impersonating Zendesk-related domains created over the past six months — some hosting fake single sign-on pages to steal credentials, others used to submit malicious support tickets aimed at infecting help-desk personnel with malware such as remote-access trojans. The group reportedly exploited a support portal breach at Discord, exfiltrating sensitive user data, and has signaled plans for further campaigns through early 2026. Organizations are now being urged to treat customer-support platforms like Zendesk as critical infrastructure and apply the same security discipline as with core IT systems.

      Sources: TechRadar, CSO Online

      Key Takeaways

      – SLH registered over 40 fraudulent domains resembling Zendesk URLs, using them to harvest credentials via fake SSO portals or to deliver malware through spoofed support-ticket submissions.

      – The group’s modus operandi reflects a pivot toward attacking customer-support systems, considered “low-hanging fruit,” rather than traditional enterprise networks — evidencing a shift toward human- and infrastructure-centric social engineering.

      – Firms relying on SaaS-based help-desk platforms must elevate security: enforce robust MFA, monitor for typosquatted domains, restrict support-ticket privileges, and treat help-desk tools as part of their critical attack surface.

      In-Depth

      The fallout from the latest wave of cyber-threats is hard to overstate: after a string of high-profile breaches targeting major SaaS platforms, the group calling itself Scattered LAPSUS$ Hunters has turned its attention to Zendesk — a customer-support backbone for hundreds of thousands of businesses worldwide. The alarming discovery, detailed by security firm ReliaQuest, reveals more than 40 new domains bearing names like “vpn-zendesk[.]com” and “znedesk[.]com” — blatant typosquatting that mimics legitimate Zendesk URLs. Some of these domains host counterfeit single sign-on (SSO) portals, engineered to trick users into entering their credentials. Other domains are used to lodge fraudulent support tickets to real Zendesk portals, aiming to expose help-desk personnel to remote-access trojans or other forms of malware.

      This campaign marks a cunning evolution of tactics: after all, email has long been the primary vector for phishing. By shifting toward support-portal infrastructure, SLH is exploiting systems that organizations frequently overlook — assuming they’re safer or less critical than email or external web applications. In many firms, support portals are handled by lower-privileged staff or third-party agents, and may lack the same security hardening as core platforms. That creates an enticing attack surface for social-engineering operators who are adept at impersonation and credential-theft schemes.

      The timing is significant, too. SLH’s interest in Zendesk coincides with their alleged involvement in a recent data breach at Discord, where hackers reportedly accessed Discord’s Zendesk-based support system and walked away with names, email addresses, IPs, billing info, and even government-issued IDs. While SLH has denied responsibility for that specific breach — calling the attribution “hilarious” — the technical footprint of the Zendesk-spoofing domains matches their known pattern: typosquatting, registration through NiceNic, masked Cloudflare nameservers, and US/UK contact info. That strongly suggests this is not a random act, but a coordinated operation following similar efforts against other SaaS platforms earlier in 2025, such as Salesforce and Gainsight.

      For companies still treating their help-desk tools as ancillary, this should be a wake-up call. As ReliaQuest warns, the next few months — especially the upcoming holiday season — are a prime time for SLH to strike, particularly when incident-response teams may be under-staffed or distracted. The group itself reportedly notified followers on Telegram that “3–4 campaigns” are in progress and urged IR staff to watch their logs through January 2026.

      What should organizations do? For starters, treat customer support platforms with the same security rigor as core infrastructure. Require hardware-based multi-factor authentication for all accounts with administrative or support privileges. Enable strict session-timeout policies and IP allow-listing whenever possible. Deploy domain-monitoring tools or subscribe to a digital-risk-protection service that can alert you when typosquatted versions of your SaaS domains appear. Restrict who can submit support tickets, and apply content filtering and link-scanning to detect potentially malicious attachments or URLs.

      This may not stop every attempt — where human trust is involved, there will always be risk — but implementing those layers of defense will dramatically raise the cost and complexity of a successful attack. In today’s threat environment, it’s no longer sufficient to harden firewalls and patch servers; organizations must remember: the weakest link may be the help-desk portal itself.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleYouTube Rolls Out TV-Targeted Features Amid Growing Living-Room Shift
      Next Article Zillow Pulls Climate-Risk Scores From Listings After Agents Push Back

      Related Posts

      ICE Explores Robot Dogs to Protect Agents During Immigration Enforcement

      August 30, 2026

      Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

      August 29, 2026

      Chinese Bot Network Targets U.S. Data-Center And Energy Debate

      August 29, 2026

      Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

      August 29, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      ICE Explores Robot Dogs to Protect Agents During Immigration Enforcement

      August 30, 2026

      Darth Vader Satire Puts San Diego’s Flock Surveillance Cameras in the Spotlight

      August 29, 2026

      Chinese Bot Network Targets U.S. Data-Center And Energy Debate

      August 29, 2026

      Smartwatch Research Finds Seniors Can Accurately Sense Mental Decline

      August 29, 2026
      Popular Topics
      Series A Viral starlink Startup Tim Cook Software Samsung Satya Nadella Space Series B trending UAE Tech Stocks spotlight Tesla SpaceX Taiwan Tech Tesla Cybertruck Sundar Pichai Satellite
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.