Scattered Lapsus$ Hunters Take Aim At Zendesk Users
The Scattered Lapsus$ Hunters group may be targeting Zendesk users in a new campaign, after a fresh batch of phishing domains and malicious helpdesk tickets were discovered, according to ReliaQuest.
The threat intelligence firm said it found over 40 typosquatted Zendesk domains and URLs featuring different organizations’ names or brands (i.e., organization-zendesk.com) that were created over the past six months.
Some domains, like znedesk[.]com and vpn-zendesk[.]com, host phishing pages like Zendesk single sign-on (SSO) portals designed to harvest credentials.
All domains observed by ReliaQuest were registered through NiceNic and have US and UK registrant information and Cloudflare-masked nameservers.
“These elements are reminiscent of the recent Scattered Lapsus$ Hunters campaign that targeted customer relationship management platform Salesforce in August 2025,” ReliaQuest explained.
“The domains we uncovered while investigating the August campaign shared similarities with the Zendesk domains: formatting, registry characteristics, and the use of deceptive SSO portals.”
The firm also claimed to have evidence that the threat group is submitting fraudulent tickets to Zendesk portals operated by clients of the SaaS customer service platform.
“These fake submissions are crafted to target support and help-desk personnel, infecting them with remote access trojans (RATs) and other types of malware,” it said.
“Targeting help-desk teams with these kinds of tactics often involves well-crafted pretexts, like urgent system administration requests or fake password reset inquiries. The goal is to trick support staff into handing over credentials or compromising their endpoints.”
The campaign may already have its first victim, after Discord revealed a breach via a third-party customer service provider last month. Threat actors compromised its Zendesk-based support system, stealing user data including names, email addresses, billing information, IP addresses and government-issued ID information, ReliaQuest said.
The attacks on Zendesk customers follow those targeting Salesforce , Salesloft Drift and Gainsight , described as “high-value SaaS platforms with widespread organizational adoption and access to downstream customer data” by Reliaquest.
However, the Zendesk campaign could also be the work of a copycat group, the company admitted .
The security vendor urged organizations to:
Image credit: Shaheerrr / Shutterstock.com
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
