{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-zendesk-breach-followed-successful-sms-phishing-of-employees"},"incident":{"title":"Zendesk breach followed successful SMS phishing of employees","date":"2022-10","date_precision":"month","victim_org":"Zendesk","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":null,"summary":"Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.","how_it_worked":"Employees received text messages that led to a page impersonating Zendesk's single sign-on portal. Several staff entered their credentials, which the attacker used to authenticate to internal systems. Because Zendesk operates a support ticketing platform for other businesses, mailboxes and ticket stores can contain customer correspondence, attachments and account details belonging to Zendesk's own clients, which is what created the downstream exposure. Zendesk described the incident as a sophisticated SMS phishing campaign, disabled the affected accounts and notified customers whose service data may have been reached.","lessons":"SaaS providers holding tenant data should mandate phishing-resistant MFA for all staff and alert on employee logins from unfamiliar devices to tenant-facing consoles.","confidence":"Reported","sources":[{"title":"Zendesk Hacked After Employees Fall for Phishing Attack","url":"https://www.securityweek.com/zendesk-hacked-after-employees-fall-for-phishing-attack/","publisher":"SecurityWeek"},{"title":"Compromised Zendesk Employee Credentials Lead to Breach","url":"https://www.darkreading.com/application-security/compromised-zendesk-employee-credentials-breach","publisher":"Dark Reading"},{"title":"Zendesk hit by phishing-related data breach","url":"https://www.scworld.com/brief/zendesk-hit-by-phishing-related-data-breach","publisher":"SC Media"}],"entry_type":"incident","slug":"2022-zendesk-breach-followed-successful-sms-phishing-of-employees","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-zendesk-breach-followed-successful-sms-phishing-of-employees"}}