Discussion about this post

User's avatar
The AI Architect's avatar

This is such a clever exploitation of legitimate systems! What really stands out is how the attackers weaponized trust—using authenticated domains means these emails sail right pasttraditional filters. I dunno if Zendesk's retroactive fixes will be enough since the damage relies on companies maintaning open support policies for genuine users. We saw somethig similiar with SendGrid abuse a few years back.

No posts

Ready for more?