Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Data Breach

Scattered Lapsus$ Hunters Tied to Targeting of Zendesk Users

Cyberinchief by Cyberinchief
November 29, 2025
Reading Time: 3 mins read
0
Scattered Lapsus$ Hunters Tied to Targeting of Zendesk Users


Uncovered: Typosquatted Domains Linked to Suspected Ransomware Group Campaign

Akshaya Asokan (asokan_akshaya) •
November 28, 2025    

Scattered Lapsus$ Hunters Tied to Targeting of Zendesk Users
Image: Shutterstock

A Western cybercrime collective largely comprised of teenagers, tied to disruptions of major firms, appears to be gearing up for a fresh round of large-scale attacks.

See Also: Traditional M365 Data Protection No Longer Enough

More than 40 “typosquatted and impersonating domains” have been discovered, designed to mimic legitimate Zendesk URLs, and which apparently trace to the hacking collective lately calling itself Scattered Lapsus$ Hunters, says a report from cybersecurity firm ReliaQuest.

The typosquatted domains have debuted over the last six months and lead to phishing pages that feature bogus single sign-on portals for Zendesk, designed to steal legitimate authentication credentials for accessing the customer service and sales platform. “These domains, such as znedesk.com or vpn-zendesk.com, are clearly designed to mimic legitimate Zendesk environments,” it said.

Based on the tactics being used as well as focus, the researchers attribute the Zendesk user-targeting campaign to Scattered Lapsus$ Hunters.

“The elements are reminiscent of the recent Scattered Lapsus$ Hunters campaign that targeted customer relationship management platform Salesforce in August. The domains we uncovered while investigating the August campaign shared similarities with the Zendesk domains,” ReliaQuest said (see: Ransomware Group Debuts Salesforce Customer Data Leak Site).

Buy JNews
ADVERTISEMENT

The loosely knit cybercrime group is a spinoff of the collective known as “The Community” or “The Com,” and largely consists of adolescent hackers based in the West, experts say. Many of the group’s members – largely comprised of native English language speakers – have proven themselves to be adept at social engineering, including tricking help desk staff, allowing them to reset passwords, bypass multi-factor authentication checks and gain access to a victim’s environment.

Customer data stores remain another one of the group’s repeat targets. In the August campaign, the attackers stole OAuth tokens from Salesloft, used to integrate its Drift Email AI chatbot software with Salesforce. The criminals employed the stolen tokens to steal data from 760 different organizations that integrated their Salesloft software with their Salesforce instances.

More recently, the Scattered Lapsus$ Hunters subgroup Shiny Hunters claimed credit for stealing data from Salesforce instances, in an attack that traced to the targeting of data management tool Gainsight, again using stolen access tokens. In that campaign, 300 organizations appear to have fallen victim (see: Salesforce Details Supply Chain Attack Targeting Gainsight).

On Nov. 5, an apparent member of the cybercrime group claimed in a post to social platform X that the it had at least three or four other major campaigns underway.

These aren’t the first attacks targeting Zendesk customers to recently come to light. On Nov. 1, Arda Büyükkaya, a cyber threat intelligence analyst at EclecticIQ, detailed how 600 different domain names registered with the .dev top-level domain managed by Google Registry were “using typosquatting to impersonate customer support portals for well-known brands,” including Cloudflare and Zendesk.

“Their primary intent is to obtain remote access to steal sensitive data and account credentials, ultimately enabling financially motivated account takeover and fraud,” he said.

The typosquatted sites’ contents appeared to have been AI-generated, and included “an embedded live chat interface, staffed by a human operator who asks victims’ phone number and email address under the pretext of providing technical assistance,” after which the attacker attempts to trick the victim into installing legitimate remote monitoring software, which grants the attacker “full remote access to the device,” Büyükkaya said.

His discovery followed Discord in September saying hackers targeted its Zendesk-based support system. The hackers claimed to have stolen sensitive user data, including names, email addresses, billing information, IP addresses, and government-issued IDs, reported Bleeping Computer.

ReliaQuest said it’s likely that “the Zendesk-related infrastructure we’ve uncovered is part of one of these campaigns,” and advised organizations to beware further attacks by Scattered Lapsus$ Hunters that target CRM and customer support systems in the coming months.

RELATED POSTS

UK Hospital Asks Court to Stymie Ransomware Data Leak

These five countries recorded the most third-party data breaches last year

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net





Source link

Tags: HuntersLAPSUSScatteredTargetingTiedUsersZendesk
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

UK Hospital Asks Court to Stymie Ransomware Data Leak
Data Breach

UK Hospital Asks Court to Stymie Ransomware Data Leak

December 8, 2025
These five countries recorded the most third-party data breaches last year
Data Breach

These five countries recorded the most third-party data breaches last year

December 8, 2025
LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net
Data Breach

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

December 7, 2025
Rethinking the CIO-CISO Dynamic in the Age of AI
Data Breach

Rethinking the CIO-CISO Dynamic in the Age of AI

December 6, 2025
NHS supplier hit with £3m fine for security failings that led to attack
Data Breach

NHS supplier hit with £3m fine for security failings that led to attack

December 6, 2025
HHS Outlines AI Road Map Amid Major Department Overhaul
Data Breach

HHS Outlines AI Road Map Amid Major Department Overhaul

December 5, 2025
Next Post
Cyber Security Experts React To The WORST TikTok Cyber Security Advice

Cyber Security Experts React To The WORST TikTok Cyber Security Advice

LIVE: Metropolitan Police Head of Economic and Cybercrime Command delivers a statement

LIVE: Metropolitan Police Head of Economic and Cybercrime Command delivers a statement

Recommended Stories

UWEcyber students and CyberWomen@UWE support Cynam EmPowerCyber to inspire 1000 year 8 schoolgirls

UWEcyber students and CyberWomen@UWE support Cynam EmPowerCyber to inspire 1000 year 8 schoolgirls

October 20, 2025
Cyber Crime aur Online Fraud se Kaise Bache ? | Digital Arrest Scam Explained | Legal Remedies 2025

Cyber Crime aur Online Fraud se Kaise Bache ? | Digital Arrest Scam Explained | Legal Remedies 2025

November 2, 2025
The Group Who Hacked The NSA: The Shadow Brokers

The Group Who Hacked The NSA: The Shadow Brokers

October 17, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested