Cybercriminals have exploited insufficient authentication controls in widely used web-based platforms to launch large-scale spam and email bombing attacks. In one case, attackers abused the customer service platform Zendesk, which allows some customer accounts to accept support requests from anonymous users without prior verification. This configuration enabled malicious actors to generate thousands of ticket creation notifications, which were then sent from the domains of legitimate Zendesk customers such as CapCom, CompTIA, Discord, GMAC, NordVPN, The Washington Post, and Tinder. The emails, which could contain any subject line chosen by the attacker, included threatening messages and personal insults, and appeared to originate from the customer’s own domain, increasing their credibility and impact. The reply-to addresses in these emails were set to the legitimate support addresses of the affected organizations, further complicating mitigation efforts. Zendesk acknowledged the abuse and stated that while they recommend customers restrict ticket creation to verified users, some organizations opt for anonymous submissions for business reasons, inadvertently exposing themselves to this type of attack. Separately, a massive spam campaign was uncovered on a client’s website due to the misuse of a contact form feature that allowed users to send a copy of their message to themselves. This seemingly innocuous feature was leveraged by attackers to generate 149,700 spam emails, overwhelming the server’s resources and causing significant performance degradation. The investigation revealed that the emails were being generated locally on the server using PHP scripts, with all messages appearing to come from the legitimate website domain. The server’s email queue became saturated, and the high volume of outbound spam led to complaints from recipients and potential blacklisting of the domain. Both incidents highlight the risks associated with allowing unauthenticated or loosely authenticated email submissions in web applications and customer service platforms. Attackers can exploit these features to conduct denial-of-service attacks on inboxes, damage reputations, and disrupt business operations. The technical analysis in both cases pointed to the need for stricter authentication and verification mechanisms for user-submitted forms and support tickets. Organizations are advised to review their platform configurations, disable anonymous submissions where possible, and implement rate limiting and CAPTCHA protections to mitigate abuse. The incidents underscore the importance of balancing user convenience with security controls to prevent exploitation by malicious actors. Failure to secure these features can result in significant operational impact, reputational harm, and increased risk of further compromise. Both cases serve as a warning to organizations using third-party platforms or custom web forms to regularly audit their authentication and submission policies. Proactive monitoring and rapid response to unusual email activity are critical to minimizing the damage from such attacks. The widespread nature of these abuses suggests that many organizations may be unknowingly vulnerable to similar exploitation. Security teams should prioritize the review of all externally facing forms and ticketing systems to ensure robust protections are in place.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
As an immediate response, administrators stopped email service, suspended the affected user, cleared the mail queue, and disabled the contact form. Recommended follow-up mitigations included removing copy-to-sender features, adding CAPTCHA and rate limits, tightening validation, and improving mail monitoring and controls.
Analysis determined attackers abused a 'Send a copy to yourself' checkbox that let them specify arbitrary external recipients, causing each submission to generate an extra outbound email. The root issue was functional abuse combined with weak or ineffective CAPTCHA, validation, and rate limiting rather than malware or a PHPMailer backdoor.
An incident investigation found a server under extreme CPU load with 149,700 emails queued after attackers abused a website contact form. Mail logs showed the messages were generated locally through PHP/PHPMailer, not through an external SMTP account compromise.
Zendesk said some customers intentionally allow anonymous submissions for business reasons but confirmed this can be abused. The company said it was investigating additional preventive measures and advised customers to require authentication for ticket creation.
Cybercriminals exploited Zendesk customer support instances that allowed anonymous ticket creation to trigger large volumes of notification emails from legitimate customer domains. The abuse sent thousands of harassing or malicious emails to targeted inboxes and exposed weaknesses in Zendesk rate limiting and email validation practices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.