frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Another round of Zendesk email spam

65•Philpax•4h ago
Looks like there's another round of Zendesk email spam happening. I've gotten hundreds over the last half-hour.

Comments

noname120•4h ago
Yeah same here, specifically on my (public) GitHub email address
petetnt•3h ago
Started getting these too just now
spike_protein•3h ago
I've got four emails, and I've no idea what’s going on. (I have a public email address on GitHub)
bentley•3h ago
It seems to have started two weeks ago. A spammer realized that one can find a Zendesk‐based help forum, open a new ticket without an account, fill the ticket with spam URLs, and put an email address scraped from GitHub commit logs in the author email field. Zendesk would “helpfully” send the “author” the contents of the ticket, becoming in effect an open relay for spam emails. Two weeks ago is when the spammer started the attack in earnest: I received hundreds of these spam emails, typically one or two per Zendesk‐hosted help forum, sent to email addresses that I’ve only ever used on GitHub. It was discussed a bit on HN: https://news.ycombinator.com/item?id=46685768

Since then, Zendesk seems to have strengthened their system so that opening a ticket requires account activation first. Leading to today, when I’ve received thousands of signup attempt emails (again, typically one or two per Zendesk‐hosted forum). This is way more emails than I got last time. I hypothesize that the spammer is doing a “last gasp” attack: now that Zendesk has burned the exploit by no longer including the ticket text in the emails, the spammer is trying every Zendesk site it knows in hopes that some of them are slow to update and still forward the ticket text to the victim.

axka•3h ago
I'm getting emails titled "Activate account for ...", and addressed to random names of web services at my domain (e.g. reddit@example.org). Also Twitch-related names like pog, kekw and xqc.

Also super annoying are crypto scams sent from an Italian ISP's (tiscali.it, shame on you) email service, even though I tried to contact the ISP, but that's unrelated to this.

trevyn•3h ago
Yep, same here, with those exact prefixes...
bitwize125•3h ago
sounds like a sign up bomb for github addresses, these are typically used to hide new login notifications by threat actors
hampus•3h ago
If your email service supports Sieve scripts (for example, Fastmail or Proton Mail), you can use this filter [1] that I made. It's very aggressive and will block all emails that originate from Zendesk, so you'll need to disable it whenever you're actually expecting mail from Zendesk.

[1]: https://gist.github.com/hampuskraft/780c8fbcc4042689153533ef...

graton•3h ago
Same. I've gotten over 30 I think.
_Chief•2h ago
Received 15+ in 10mins on a public email (dropbox, soundcloud, gitlab, tidelift etc). Then just started hitting handles on the domain ( diddy@, epstein@ ). Just placing an aggressive block for "Activate account" and "zendesk" in content for now
semiquaver•1h ago
Zendesk’s mailserver reputation has got to be extremely poor by now. I think they will have trouble with deliverability after this is over. Got about 50 of these today and nearly all of them were categorized as spam before they made it to the inbox despite being nominally “legit”
direwolf20•1h ago
Unfortunately mail server reputation's based on how rich and important you are and not how much spam you send
dang•1h ago
I got about 50 of these this morning and thought it was a disgruntled HN user.
dewey•1h ago
Glad I'm not the only one. It seems to use {popular website without tld}@example.com as a pattern, so I'm getting a lot via my catch all address even if I haven't used the specific inbox yet.
danpalmer•1h ago
For a company utterly dependent on email, Zendesk came across to me as very naive about email sending.

I did a Zendesk integration shortly after working on a general overhaul of our email at a previous company. The overhaul involved separating out our different types (transactional, marketing, support, etc), and then implementing best practices on deliverability for each of them. Not your day-one email setup, but we were still a small company.

The comparison to Zendesk's approach was astounding. Assuming you don't want to use a Zendesk address (we didn't, customers thought it was dodgy), the email setup they let you do was bad, and their support folks had no idea about any of the details. DKIM, SPF, etc, was all alien to them. Ironically they had pretty bad support in general.

rpcope1•1h ago
> DKIM, SPF, etc, was all alien to them. Ironically they had pretty bad support in general.

So basically good old fashioned "quality" enterprise shitware.

danpalmer•1h ago
Not necessarily, our support team kinda loved it. I used the interfaces and it was pretty good software in many ways. They just didn't seem to be very capable when it came to medium complexity email setups. Many of their setup guides literally tell you to log into support address Gmail and set up a forwarding rule to send everything to Zendesk.

I suspect the issue is that we weren't paying enough. We had maybe 10 seats. I bet if you're buying 1000 seats a bunch of Zendesk engineers turn up and configure everything for you, but with the robust email setup needing that engineering time on their side to configure... so I guess in that way it may be Enterprise shitware.

treis•5m ago
I worked at Zendesk on the email team. I think that's just support being support. The core engineers knew what they were doing.
danpalmer•1m ago
That's good to know you knew what you were doing! However the product also didn't appear to expose any of the control we needed to have a good email setup. Maybe this is because we weren't paying enough (mentioned in another reply), but we were also never directed to pay more despite asking for this sort of control.
adityashankar•1h ago
I just got 50 emails lol, this really sucks, phew glad i am not alone
Gualdrapo•1h ago
Thank you for letting us know, got a bunch of those in the last two hours, like one each five minutes, but it seems they've stopped (at least for now).
timvisee•1h ago
I've also received about 40 messages, on mail adresses I've never used before.
LoganDark•58m ago
Huh. I thought this was targeted to me in particular, because it started coming up with new aliases at my Firefox Relay subdomain, and then only once I started blocking them it started using plus-addressing on my gmail. Annoying.
akpa1•50m ago
I've been getting some of these these to my wildcard domain - I've had sign-up messages sent to diddy@<domain> and epstein@<domain>, which is... odd. And no, I can't say I've ever used those addresses.

Voxtral Transcribe 2

https://mistral.ai/news/voxtral-transcribe-2
676•meetpateltech•9h ago•167 comments

As Rocks May Think

https://evjang.com/2026/02/04/rocks.html
25•modeless•1h ago•5 comments

Claude Code: connect to a local model when your quota runs out

https://boxc.net/blog/2026/claude-code-connecting-to-local-models-when-your-quota-runs-out/
160•fugu2•3d ago•67 comments

Claude Code for Infrastructure

https://www.fluid.sh/
120•aspectrr•5h ago•101 comments

Remarkable Pro Colors

https://www.thregr.org/wavexx/rnd/20260201-remarkable_pro_colors/
43•ffaser5gxlsll•3d ago•17 comments

Building a 24-bit arcade CRT display adapter from scratch

https://www.scd31.com/posts/building-an-arcade-display-adapter
107•evakhoury•6h ago•29 comments

AI is killing B2B SaaS

https://nmn.gl/blog/ai-killing-b2b-saas
190•namanyayg•7h ago•316 comments

Sqldef: Idempotent schema management tool for MySQL, PostgreSQL, SQLite

https://sqldef.github.io/
19•Palmik•3d ago•4 comments

Tractor

https://incoherency.co.uk/blog/stories/tractor.html
137•surprisetalk•1d ago•45 comments

A real-world benchmark for AI code review

https://www.qodo.ai/blog/how-we-built-a-real-world-benchmark-for-ai-code-review/
31•benocodes•3h ago•13 comments

Microsoft's Copilot chatbot is running into problems

https://www.wsj.com/tech/ai/microsofts-pivotal-ai-product-is-running-into-big-problems-ce235b28
84•fortran77•8h ago•115 comments

Attention at Constant Cost per Token via Symmetry-Aware Taylor Approximation

https://arxiv.org/abs/2602.00294
144•fheinsen•9h ago•79 comments

A sane but bull case on Clawdbot / OpenClaw

https://brandon.wang/2026/clawdbot
234•brdd•1d ago•374 comments

RS-SDK: Drive RuneScape with Claude Code

https://github.com/MaxBittker/rs-sdk
91•evakhoury•7h ago•34 comments

Data Poems

https://dr.eamer.dev/datavis/poems/
17•putzdown•3d ago•3 comments

Arcan-A12: Weaving a Different Web

https://www.divergent-desktop.org/blog/2026/01/26/a12web/
44•ingenieroariel•8h ago•14 comments

Coding Agent VMs on NixOS with Microvm.nix

https://michael.stapelberg.ch/posts/2026-02-01-coding-agent-microvm-nix/
76•secure•3d ago•37 comments

The Codex app illustrates the shift left of IDEs and coding GUIs

https://www.benshoemaker.us/writing/codex-app-launch/
52•straydusk•3h ago•112 comments

Converge (YC S23) Is Hiring Product Engineers (NYC, In-Person)

https://www.runconverge.com/careers/product-engineer
1•thomashlvt•7h ago

Tell HN: Another round of Zendesk email spam

65•Philpax•4h ago•24 comments

Litestream Writable VFS

https://fly.io/blog/litestream-writable-vfs/
14•emschwartz•1h ago•13 comments

Claude is a space to think

https://www.anthropic.com/news/claude-is-a-space-to-think
335•meetpateltech•12h ago•179 comments

Spotlighting the World Factbook as We Bid a Fond Farewell

https://www.cia.gov/stories/story/spotlighting-the-world-factbook-as-we-bid-a-fond-farewell/
65•mxfh•3h ago•56 comments

No More Hidden Changes: How MySQL 9.6 Transforms Foreign Key Management

https://blogs.oracle.com/mysql/no-more-hidden-changes-how-mysql-9-6-transforms-foreign-key-manage...
25•ksec•4d ago•13 comments

The Great Unwind

https://occupywallst.com/yen
222•jart•6h ago•167 comments

Guinea worm on track to be 2nd eradicated human disease; only 10 cases in 2025

https://arstechnica.com/health/2026/02/guinea-worm-on-track-to-be-2nd-eradicated-human-disease-on...
245•bookofjoe•9h ago•96 comments

Technocracy 2.0

https://brooklynrail.org/2026/02/field-notes/technocracy-2-0/
74•antonomon•4h ago•39 comments

Show HN: Interactive California Budget (By Claude Code)

https://california-budget.com
27•sberens•3h ago•11 comments

Turn any website into a live, structured data feed

https://www.meter.sh/
25•chadwebscraper•5h ago•17 comments

A case study in PDF forensics: The Epstein PDFs

https://pdfa.org/a-case-study-in-pdf-forensics-the-epstein-pdfs/
240•DuffJohnson•9h ago•135 comments