Scattered Lapsus$ Hunters may be circling Zendesk users for its latest extortion campaign, with new phishing domains and weaponized helpdesk tickets uncovered by ReliaQuest. Researchers say they found more than 40 typosquatted and impersonation domains – names like "znedesk.com" or "vpn-zendesk.com" – designed to mirror Zendesk's portals over the past six months. Some host fake single sign-on (SSO) pages aimed at harvesting credentials, while others are used to submit fraudulent tickets to helpdesk staff. All share common registration hallmarks – the same registrar (NiceNic), US or UK contact details, and Cloudflare-masked nameservers – a profile almost identical to that of a previous impersonation campaign targeting Salesforce. That similarity leads security watchers to suspect the same criminal crew is behind both schemes: the "retired" Scattered Lapsus$ Hunters crew. "These elements are reminiscent of the recent Scattered Lapsus$ Hunters campaign that targeted customer relationship management platform Salesforce in August 2025," ReliaQuest's threat researchers said in a blog post this week. This is more than phishing noise. According to ReliaQuest, the attackers appear to be chaining support interface impersonation with targeted intrusions, submitting malicious tickets to legitimate Zendesk portals operated by real organizations, potentially dropping remote-access trojans (RATs) directly onto agents' machines. Once inside, they could pivot across corporate networks, quietl...
Zendesk users targeted as Scattered Lapsus$ Hunters spin up fake support sites
The Register
·Carly Page
·Published Nov 27, 2025
·Updated
Affected Software
1 affected component
Zendesk Zendesk
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security threat targeting Zendesk users through phishing tactics by Scattered Lapsus$ Hunters.
2
What security implications are discussed?
The article highlights the risks of extortion campaigns utilizing fake support sites and weaponized helpdesk tickets.
3
What products or software are affected?
Zendesk is specifically mentioned as the affected product in this phishing campaign.
4
What tactics are being used by Scattered Lapsus$ Hunters?
Scattered Lapsus$ Hunters are using typosquatting domains and fraudulent helpdesk interactions to lure victims.
5
Who discovered the ongoing threats against Zendesk users?
The security firm ReliaQuest uncovered the phishing domains and associated threats against Zendesk users.