{"id":16642,"date":"2023-01-24T14:32:35","date_gmt":"2023-01-24T13:32:35","guid":{"rendered":"https:\/\/www.show.it\/zendesk-hacked-after-employees-fall-for-phishing-attack\/"},"modified":"2023-01-24T14:32:35","modified_gmt":"2023-01-24T13:32:35","slug":"zendesk-hacked-after-employees-fall-for-phishing-attack","status":"publish","type":"post","link":"https:\/\/www.show.it\/en\/zendesk-hacked-after-employees-fall-for-phishing-attack\/","title":{"rendered":"Zendesk Hacked After Employees Fall for Phishing Attack"},"content":{"rendered":"<p><strong>Customer service solutions provider Zendesk has suffered a data breach that resulted from employee account credentials getting phished by hackers.<\/strong><\/p>\n<p>Cryptocurrency trading and portfolio management company Coinigy revealed last week that it had been <a href=\"https:\/\/insights.coinigy.com\/zendesk-security-disclosure\/\" target=\"_blank\" rel=\"noreferrer noopener\">informed by Zendesk about a cybersecurity incident<\/a>.\u00a0<\/p>\n<p>According to the email received by Coinigy, Zendesk learned on October 25, 2022, that several employees were targeted in a \u201csophisticated SMS phishing campaign\u201d. Some employees took the bait and handed over their account credentials to the attackers, allowing them to access unstructured data from a logging platform between September 25 and October 26, 2022.<\/p>\n<p>Zendesk told Coinigy that, as part of its ongoing review, discovered on January 12, 2023, that service data belonging to the company\u2019s account may have been in the logging platform data. Zendesk said there was no indication that Coinigy\u2019s Zendesk instance had been accessed, but its investigation is still ongoing.\u00a0<\/p>\n<p>Zendesk does not appear to have published any statement or notice related to this incident on its website and the company has not responded to SecurityWeek\u2019s inquiry.<\/p>\n<p>However, based on the available information, it\u2019s possible that the attack on Zendesk is related to a campaign named <a href=\"https:\/\/www.securityweek.com\/twilio-cloudflare-attacked-part-campaign-hit-over-130-organizations\/\" target=\"_blank\" rel=\"noreferrer noopener\">0ktapus<\/a>, in which a threat actor that appears to be financially motivated targeted more than 130 organizations between March and August 2022, including major companies such as Twilio and Cloudflare.\u00a0<\/p>\n<p>The 0ktapus attackers used SMS-based phishing messages to obtain employee credentials and victims included cryptocurrency companies.\u00a0<\/p>\n<p>Twilio and Cloudflare discovered breaches in August, but there was no indication that the campaign was not ongoing, so it\u2019s possible that the same hackers targeted Zendesk a few months later.\u00a0<\/p>\n<p>While Coinigy appears to have been notified by Zendesk about the data breach only in January 2023, other victims appear to have been informed much sooner.\u00a0<\/p>\n<p>The US-based cryptocurrency exchange Kraken informed customers<a href=\"https:\/\/twitter.com\/thewildcarder\/status\/1594361736949276674\/photo\/1\" target=\"_blank\" rel=\"noreferrer noopener\"> about a Zendesk breach <\/a>that involved phishing and unauthorized access to the Zendesk logging system back in November. Kraken said at the time that while accounts and funds were not at risk, the attackers did view the content of support tickets, which contained information such as name, email address, date of birth and phone number.<\/p>\n<p>This is not the first data breach disclosed by Zendesk. In 2019, the company revealed that it had become aware of a security incident that <a href=\"https:\/\/www.securityweek.com\/zendesk-discloses-old-data-breach-affecting-10000-accounts\/\" target=\"_blank\" rel=\"noreferrer noopener\">hit roughly 10,000 accounts<\/a>.\u00a0<\/p>\n<p><strong>Related: <a href=\"https:\/\/www.securityweek.com\/zendesk-vulnerability-could-have-given-hackers-access-customer-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">Zendesk Vulnerability Could Have Given Hackers Access to Customer Data<\/a><\/strong><\/p>\n<p><strong>Related: <a href=\"https:\/\/www.securityweek.com\/recently-disclosed-vulnerability-exploited-hack-hundreds-sugarcrm-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Recently Disclosed Vulnerability Exploited to Hack Hundreds of SugarCRM Servers<\/a><\/strong><\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/zendesk-hacked-after-employees-fall-for-phishing-attack\/\">Zendesk Hacked After Employees Fall for Phishing Attack<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.securityweek.com\/\">SecurityWeek<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Customer service solutions provider Zendesk has suffered a data breach that resulted from employee account credentials getting phished by hackers. Cryptocurrency trading and portfolio management company Coinigy revealed last week that it had been informed by Zendesk about a cybersecurity incident.\u00a0 According to the email received by Coinigy, Zendesk learned on October 25, 2022, that [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16643,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[27,82,76,69,17],"tags":[],"class_list":["post-16642","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybercrime","category-data-breach","category-data-breaches","category-featured","category-phishing"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16642","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/comments?post=16642"}],"version-history":[{"count":0,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/posts\/16642\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media\/16643"}],"wp:attachment":[{"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/media?parent=16642"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/categories?post=16642"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.show.it\/en\/wp-json\/wp\/v2\/tags?post=16642"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}