Zendesk users targeted by Scattered Lapsus$ Hunter’s hackers and fake support sites


  • Hackers targeting Zendesk users with misspelled domains to steal credentials
  • ReliaQuest found more than 40 spoofed domains linked to Salesforce campaign similarities
  • Attackers submit fake Zendesk tickets to spread malware and steal support staff access

The infamous Scattered Lapsus$ Hunters gang, which famously targeted Salesforce users, is now also targeting Zendesk users to try to steal login credentials and access their sensitive information, experts have warned.

Security researchers from ReliaQuest claim that over the past six months, more than 40 typosquatted domains have been registered spoofing Zendesk. In some cases, the domains contained trademarked names (for example, businessname-zendesk[dot]com), and in other cases they were relatively generic (vpn-zendesk[dot]com, for example).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top