A new study has claimed that Zendesk’s SaaS infrastructure is being targeted by scammers and hackers.
Produced by CloudSek, the study claims that bad actors are using Zendesk’s SaaS free trial offer to imitate genuine brands in an attempt to mislead unsuspecting users.
In particular, CloudSek believes that the vendor is susceptible to phishing campaigns.
In a nutshell, attackers are using the free trial to register brand-like subdomains to create convincing interfaces for phishing, data theft, and financial fraud.
Targeted subdomains combine the impersonated brand’s name with numbers to appear legitimate to users.
The report states that there have been several reported cases of Zendesk clients being targeted by suspect domains in the past six months.
While this is clearly an area of concern for the vendor, CloudSek posits that the fake domains could also be used to deploy "pig butchering" scams, as explained by the report author, Noel Varghese.
Pig Butchering
Named after the practice of fattening a pig before slaughter, pig butchering scams involve fraudsters building trust with random targets before tricking them into fake investments and disappearing with their money.
While the report was keen to emphasize that, to the best of the firm’s knowledge, Zendesk has not currently been impacted by any scams of this kind, CloudSek believes that the free trial weakness makes the SaaS provider vulnerable.
In exploring the possibility, CloudSek provided a demonstration of how a potential phishing attack targeting XYZ Company could exploit Zendesk as an infrastructure platform and leverage fake domains to propagate pig butchering scams.
Below is a brief summary of how the scam could work in practice:
- Zendesk Account Setup: The attacker registers a Zendesk account using a subdomain that mimics the target company’s name.
- Fake Subdomain Creation: Admin access allows the attacker to invite users and send phishing emails disguised as legitimate ticket notifications.
- Phishing Setup: Invitations include links to phishing pages pretending to be support tickets.
- Data Collection: Tools like RocketReach help gather employee email addresses, targeting specific users for phishing.
- Exploitation: Zendesk’s lack of email verification enables attackers to send phishing links to any added email address.
In this hypothetical example, a disposable email address was added as a member to the Zendesk portal, which received a phishing page masquerading as a legitimate support ticket assignment.
This demonstrates how easily Zendesk’s infrastructure can be misused for phishing attacks when proper safeguards are not in place.
Observations and Recommendations
First and foremost, the fact that all email correspondence (tickets) from attacker-controlled Zendesk domains lands in the Primary Inbox instead of being marked as spam, poses a significant risk.
As demonstrated above, this can lead to employees mistaking these phishing campaigns for legitimate communication from their organization.




