Zendesk users targeted by Scattered Lapsus$ Hunters hackers and fake support sites


  • Hackers targeting Zendesk users with typosquatted domains to steal credentials
  • ReliaQuest found over 40 spoofed domains linked to Salesforce campaign similarities
  • Attackers submit fake Zendesk tickets to spread malware and steal support staff access.

The notorious Scattered Lapsus$ Hunters gang, which targeted Salesforce users, is now also targeting Zendesk users in an attempt to steal login credentials and access their sensitive information, experts have warned.

Security researchers at ReliaQuest say that in the last six months, more than 40 typosquatted domains have been registered to spoof Zendesk. In some cases, domains contained brand names (e.g. businessname-zendesk[dot]com), and in other cases they were relatively generic (vpn-zendesk[dot]com, for example).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top