• News/
  • https://www.theregister.com/2025/11/27/scattered_lapsus_hunters_zendesk/

Zendesk users targeted as Scattered Lapsus$ Hunters spin up fake support sites

The Register
·
Carly Page
·
Published Nov 27, 2025
·
Updated

Scattered Lapsus$ Hunters may be circling Zendesk users for its latest extortion campaign, with new phishing domains and weaponized helpdesk tickets uncovered by ReliaQuest. Researchers say they found more than 40 typosquatted and impersonation domains – names like "znedesk.com" or "vpn-zendesk.com" – designed to mirror Zendesk's portals over the past six months. Some host fake single sign-on (SSO) pages aimed at harvesting credentials, while others are used to submit fraudulent tickets to helpdesk staff. All share common registration hallmarks – the same registrar (NiceNic), US or UK contact details, and Cloudflare-masked nameservers – a profile almost identical to that of a previous impersonation campaign targeting Salesforce. That similarity leads security watchers to suspect the same criminal crew is behind both schemes: the "retired" Scattered Lapsus$ Hunters crew. "These elements are reminiscent of the recent Scattered Lapsus$ Hunters campaign that targeted customer relationship management platform Salesforce in August 2025," ReliaQuest's threat researchers said in a blog post this week. This is more than phishing noise. According to ReliaQuest, the attackers appear to be chaining support interface impersonation with targeted intrusions, submitting malicious tickets to legitimate Zendesk portals operated by real organizations, potentially dropping remote-access trojans (RATs) directly onto agents' machines. Once inside, they could pivot across corporate networks, quietl...

Read full article

Affected Software

1 affected component
Zendesk Zendesk
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security threat targeting Zendesk users through phishing tactics by Scattered Lapsus$ Hunters.

2

What security implications are discussed?

The article highlights the risks of extortion campaigns utilizing fake support sites and weaponized helpdesk tickets.

3

What products or software are affected?

Zendesk is specifically mentioned as the affected product in this phishing campaign.

4

What tactics are being used by Scattered Lapsus$ Hunters?

Scattered Lapsus$ Hunters are using typosquatting domains and fraudulent helpdesk interactions to lure victims.

5

Who discovered the ongoing threats against Zendesk users?

The security firm ReliaQuest uncovered the phishing domains and associated threats against Zendesk users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203