frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Tell HN: Another round of Zendesk email spam

97•Philpax•16h ago•47 comments

Ask HN: Is Connecting via SSH Risky?

11•atrevbot•8h ago•18 comments

Ask HN: Who wants to be hired? (February 2026)

136•whoishiring•2d ago•441 comments

Ask HN: Has your whole engineering team gone big into AI coding? How's it going?

3•jchung•6h ago•1 comments

Ask HN: Who is hiring? (February 2026)

305•whoishiring•2d ago•465 comments

Ask HN: Mem0 stores memories, but doesn't learn user patterns

9•fliellerjulian•15h ago•6 comments

We built a serverless GPU inference platform with predictable latency

3•QubridAI•6h ago•1 comments

Ask HN: Where does operational truth live before it reaches "systems of record"?

2•former-aws•14h ago•3 comments

Ask HN: Do you still use physical calculators?

58•speedylight•5d ago•124 comments

Ask HN: Is there anyone here who still uses slide rules?

120•blenderob•1d ago•121 comments

Google Cloud suspended my account for 2 years, only automated replies

159•andylizf•4d ago•99 comments

YC S26 Application: "Attach a coding agent session you're particularly proud of"

4•simplydt•18h ago•1 comments

Kernighan on Programming

166•chrisjj•2d ago•59 comments

Ask HN: When will LLMs generate professional-level CAD models?

8•dsrtslnd23•18h ago•5 comments

Ask HN: Does anyone have interests in anything besides AI?

8•drsalt•9h ago•7 comments

Ask HN: Are ISPs "evil" and who runs the Internet?

5•tavro•22h ago•2 comments

How do you manage context/memory across multiple AI tools?

7•arapkuliev•22h ago•5 comments

Ask HN: Cheap laptop for Linux without GUI (for writing)

11•locusofself•1d ago•15 comments

Ask HN: OpenClaw users, what is your token spend?

14•8cvor6j844qw_d6•2d ago•6 comments

Ask HN: Have you been fired because of AI?

15•s-stude•2d ago•15 comments

Ask HN: Anyone have a "sovereign" solution for phone calls?

9•kldg•1d ago•1 comments

GitHub Actions Have "Major Outage"

52•graton•2d ago•17 comments

Ask HN: Has anybody moved their local community off of Facebook groups?

21•madsohm•3d ago•15 comments

Ask HN: What weird or scrappy things did you do to get your first users?

13•preston-kwei•2d ago•8 comments

Ask HN: Tech Debt War Stories

6•erubini_fg•1d ago•8 comments

Ask HN: Does a good "read it later" app exist?

5•buchanae•1d ago•16 comments

Ask HN: Are you still using spec driven development?

6•cherry_tree•2d ago•5 comments

My small SaaS got recommended my Google in the AI search overview

4•kaave•2d ago•3 comments

Signal Is Down

40•Daniel_sk•1d ago•10 comments

Why do people still talk about AGI?

42•cermicelli•3d ago•64 comments
Open in hackernews

Tell HN: Another round of Zendesk email spam

97•Philpax•16h ago
Looks like there's another round of Zendesk email spam happening. I've gotten hundreds over the last half-hour.

Comments

noname120•16h ago
Yeah same here, specifically on my (public) GitHub email address
petetnt•16h ago
Started getting these too just now
spike_protein•15h ago
I've got four emails, and I've no idea what’s going on. (I have a public email address on GitHub)
bentley•15h ago
It seems to have started two weeks ago. A spammer realized that one can find a Zendesk‐based help forum, open a new ticket without an account, fill the ticket with spam URLs, and put an email address scraped from GitHub commit logs in the author email field. Zendesk would “helpfully” send the “author” the contents of the ticket, becoming in effect an open relay for spam emails. Two weeks ago is when the spammer started the attack in earnest: I received hundreds of these spam emails, typically one or two per Zendesk‐hosted help forum, sent to email addresses that I’ve only ever used on GitHub. It was discussed a bit on HN: https://news.ycombinator.com/item?id=46685768

Since then, Zendesk seems to have strengthened their system so that opening a ticket requires account activation first. Leading to today, when I’ve received thousands of signup attempt emails (again, typically one or two per Zendesk‐hosted forum). This is way more emails than I got last time. I hypothesize that the spammer is doing a “last gasp” attack: now that Zendesk has burned the exploit by no longer including the ticket text in the emails, the spammer is trying every Zendesk site it knows in hopes that some of them are slow to update and still forward the ticket text to the victim.

alejo•11h ago
What would be the goal of all this? Just for the fun of it?
spike_protein•7h ago
It's not for fun. They are hijacking a trusted server (Zendesk) to smuggle phishing links past my spam filter. Since Zendesk blocked the text relay, their bot is now just spamming signups as a side effect of the failed exploit.

[Ref](https://support.zendesk.com/hc/en-us/articles/8257723564186-...)

[Ref 2](https://darknetsearch.com/knowledge/news/en/zendesk-ticket-s...)

axka•15h ago
I'm getting emails titled "Activate account for ...", and addressed to random names of web services at my domain (e.g. reddit@example.org). Also Twitch-related names like pog, kekw and xqc.

Also super annoying are crypto scams sent from an Italian ISP's (tiscali.it, shame on you) email service, even though I tried to contact the ISP, but that's unrelated to this.

trevyn•15h ago
Yep, same here, with those exact prefixes...
bitwize125•15h ago
sounds like a sign up bomb for github addresses, these are typically used to hide new login notifications by threat actors
hampus•15h ago
If your email service supports Sieve scripts (for example, Fastmail or Proton Mail), you can use this filter [1] that I made. It's very aggressive and will block all emails that originate from Zendesk, so you'll need to disable it whenever you're actually expecting mail from Zendesk.

[1]: https://gist.github.com/hampuskraft/780c8fbcc4042689153533ef...

graton•15h ago
Same. I've gotten over 30 I think.
_Chief•15h ago
Received 15+ in 10mins on a public email (dropbox, soundcloud, gitlab, tidelift etc). Then just started hitting handles on the domain ( diddy@, epstein@ ). Just placing an aggressive block for "Activate account" and "zendesk" in content for now
semiquaver•13h ago
Zendesk’s mailserver reputation has got to be extremely poor by now. I think they will have trouble with deliverability after this is over. Got about 50 of these today and nearly all of them were categorized as spam before they made it to the inbox despite being nominally “legit”
direwolf20•13h ago
Unfortunately mail server reputation's based on how rich and important you are and not how much spam you send
rationalist•10h ago
Considering I get spam from large U.S. companies because they believed someone else when they used my email to sign up for something, I am inclined to agree with you. No matter how many times I click "mark as spam" in Gmail, it always gets delivered to my inbox.

Credit Karma is the biggest offender off the top of my head. For a company in the consumer datamining business, they sure aren't doing a good job.

driverdan•9h ago
Two of the biggest spammers in the world are Salesforce and Hubspot. They should both be blacklisted yet most of their email goes into the inbox.
skgsergio•2h ago
Well, I got most of the Zendesk inbox-bombing emails into SPAM in Gmail.

All support[at]<company>.zendesk.com were flagged, none of them reached the Inbox.

Most of whatever[at]company.tld were flagged also. I think only Headspace and another that I don't remember got to my inbox. There were some automatic SPAM flags using custom domains that are more or less known: Tinder, Squarespace, TED, ...

So I guess currently their reputation is messed up.

dang•13h ago
I got about 50 of these this morning and thought it was a disgruntled HN user.
dewey•13h ago
Glad I'm not the only one. It seems to use {popular website without tld}@example.com as a pattern, so I'm getting a lot via my catch all address even if I haven't used the specific inbox yet.
matteason•2h ago
I'm seeing the same pattern, with the addition of diddy@ and epstein@, curiuosly
danpalmer•13h ago
For a company utterly dependent on email, Zendesk came across to me as very naive about email sending.

I did a Zendesk integration shortly after working on a general overhaul of our email at a previous company. The overhaul involved separating out our different types (transactional, marketing, support, etc), and then implementing best practices on deliverability for each of them. Not your day-one email setup, but we were still a small company.

The comparison to Zendesk's approach was astounding. Assuming you don't want to use a Zendesk address (we didn't, customers thought it was dodgy), the email setup they let you do was bad, and their support folks had no idea about any of the details. DKIM, SPF, etc, was all alien to them. Ironically they had pretty bad support in general.

rpcope1•13h ago
> DKIM, SPF, etc, was all alien to them. Ironically they had pretty bad support in general.

So basically good old fashioned "quality" enterprise shitware.

danpalmer•13h ago
Not necessarily, our support team kinda loved it. I used the interfaces and it was pretty good software in many ways. They just didn't seem to be very capable when it came to medium complexity email setups. Many of their setup guides literally tell you to log into support address Gmail and set up a forwarding rule to send everything to Zendesk.

I suspect the issue is that we weren't paying enough. We had maybe 10 seats. I bet if you're buying 1000 seats a bunch of Zendesk engineers turn up and configure everything for you, but with the robust email setup needing that engineering time on their side to configure... so I guess in that way it may be Enterprise shitware.

treis•12h ago
I worked at Zendesk on the email team. I think that's just support being support. The core engineers knew what they were doing.
danpalmer•12h ago
That's good to know you knew what you were doing! However the product also didn't appear to expose any of the control we needed to have a good email setup. Maybe this is because we weren't paying enough (mentioned in another reply), but we were also never directed to pay more despite asking for this sort of control.
treis•12m ago
That is true. There's a lot of magic that goes into parsing the emails. But end user configuration of the infrastructure of sending didn't really exist when I was there
otterley•11h ago
I transitioned Zendesk from their original Exim-based ingress/egress SMTP services to Postfix and set up all the DKIM and SPF stuff long before there was ever a mail team. I worked regularly with large email providers to ensure our egress CIDR blocks were clean.

I like to think I knew what I was doing. :-)

adityashankar•13h ago
I just got 50 emails lol, this really sucks, phew glad i am not alone
Gualdrapo•13h ago
Thank you for letting us know, got a bunch of those in the last two hours, like one each five minutes, but it seems they've stopped (at least for now).
timvisee•13h ago
I've also received about 40 messages, on mail adresses I've never used before.
LoganDark•13h ago
Huh. I thought this was targeted to me in particular, because it started coming up with new aliases at my Firefox Relay subdomain, and then only once I started blocking them it started using plus-addressing on my gmail. Annoying.
akpa1•12h ago
I've been getting some of these these to my wildcard domain - I've had sign-up messages sent to diddy@<domain> and epstein@<domain>, which is... odd. And no, I can't say I've ever used those addresses.
Wingy•11h ago
I had several sent to these local parts as well.
Wingy•11h ago
I got 201 activation emails in 98 minutes.
rootxy•10h ago
Same here, I removed my email address from Github and all other public pages
dandigangi•10h ago
They've been getting hammered by bad actors. Work in the email industry and its been bad for them. Hopefully they figure it out. Yesterday I got two phishing scams that were from a BS gmail saying they were in hiring at Unilever and Nestle.
bravetraveler•10h ago
They're being used to hit addresses of mine exposed to Discord and GitHub. Catch-all had the names of two people in the news, oddly, as well. Hint: 1,000 bottle delivery to an island.
lynndotpy•9h ago
Those names are diddy and epstein, for those wondering.
ddtaylor•9h ago
Why do we have to tease out the names of convicted criminals?
lynndotpy•9h ago
I am not sure what you mean. But I did receive many `epstein@` and `diddy@` catch-alls. As I type, they're starting up again.
bravetraveler•4h ago
More 'entertainment' than 'have to', parent named them correctly. Keeping the memes alive, not acting like they're Beetlejuice.

Why did my teaser provoke your comment? Rhetorical, by the way.

edoceo•9h ago
I get similar ones from Zoom and other collaboration providers. Like folk make a meeting in Zoom and then can invite any email they know. Is that just me? Eventbrite, Meetup and Luma do similar.
Arcayr•8h ago
i received _a lot_ of these as well (~200 now). i'm noticing while all are from the zendesk platform using it as a relay similar to the previous waves, many of them are specifically customers of synack, as the emails are coming "via" the responsibledisclosure.com platform. not sure if there's any correlation there—i don't think they've been compromised, but they may be being used as a trampoline.

similar to others i had it hitting emails that "don't exist" (wildcard catchall), including the less tasteful ones mentioned here.

spike_protein•7h ago
Zendesk has issued an official announcement about this.

https://support.zendesk.com/hc/en-us/articles/8257723564186-...

I'm not satisfied with it, tbh.

captn3m0•3h ago
> Thank you for your attention to this important matter.

You gotta be kidding me.

noname120•2h ago
This announcement from December is completely unrelated.
catgirlinspace•5h ago
weirdly i have 10+ wild card domains and some very public emails (websites with nothing to prevent bots) yet i’ve not gotten even one?