Friction

Pain point · Permissions & security · Blocks work

Unauthenticated tickets enabled spam email abuse

1 source thread · first seen 2026-02

Summary

A spammer exploited Zendesk-hosted help forums to submit tickets that triggered emails to addresses scraped from GitHub. After Zendesk changed ticket activation behavior, the user received thousands of signup-attempt emails instead.

Affects
People whose email addresses were scraped from GitHub commit logs

Evidence

Excerpts are copied word for word from the source; follow the link to read it in full.

“Zendesk would “helpfully” send the “author” the contents of the ticket, becoming in effect an open relay for spam emails”

Report this item