Pain point · Permissions & security · Blocks work
Unauthenticated tickets enabled spam email abuse
1 source thread · first seen 2026-02
Summary
A spammer exploited Zendesk-hosted help forums to submit tickets that triggered emails to addresses scraped from GitHub. After Zendesk changed ticket activation behavior, the user received thousands of signup-attempt emails instead.
- Affects
- People whose email addresses were scraped from GitHub commit logs
Evidence
Excerpts are copied word for word from the source; follow the link to read it in full.
“Zendesk would “helpfully” send the “author” the contents of the ticket, becoming in effect an open relay for spam emails”