Skip to content
NetarxImpact Database
Smishing (SMS)No AI reportedReported

Zendesk breach followed successful SMS phishing of employees

Zendesk · Technology · United States · October 2022

What happened

Customer service software vendor Zendesk notified customers in early 2023 that several employees had fallen for an SMS phishing campaign in October 2022, allowing an attacker to access service data. The disclosure came to light after a cryptocurrency company that used Zendesk published the notification letter. Zendesk said it rotated credentials, engaged outside forensics and found no evidence of wider compromise.

How the deception worked

Employees received text messages that led to a page impersonating Zendesk's single sign-on portal. Several staff entered their credentials, which the attacker used to authenticate to internal systems. Because Zendesk operates a support ticketing platform for other businesses, mailboxes and ticket stores can contain customer correspondence, attachments and account details belonging to Zendesk's own clients, which is what created the downstream exposure. Zendesk described the incident as a sophisticated SMS phishing campaign, disabled the affected accounts and notified customers whose service data may have been reached.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

SaaS providers holding tenant data should mandate phishing-resistant MFA for all staff and alert on employee logins from unfamiliar devices to tenant-facing consoles.

Sources (3)

  1. Zendesk Hacked After Employees Fall for Phishing Attack
    SecurityWeek·securityweek.comOpen ↗
  2. Compromised Zendesk Employee Credentials Lead to Breach
    Dark Reading·darkreading.comOpen ↗
  3. Zendesk hit by phishing-related data breach
    SC Media·scworld.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.