I’ve seen a few hundred of these emails in the past couple days coming in from multiple different companies.
I’m looking for more info.
at least one said it was zendesk, most did not say any software.
the tickets are being sent with CC addresses that contain large email lists. often others on the CC who don’t know what’s happening will reply “stop emailing me”.
so far I’ve seen this coming in to multiple addresses and none of the sending companies are familiar either.
sounds familiar to anyone? any info on this? it’s there a name i can lookup to find more info? i want to know what services this effects so i can properly protect my stuff and my work stuff.
This is someone abusing ticketing systems that send autoresponses. Nothing has been hacked, the best thing for you to do is make a mailbox filter rule that trashes those and move on.
I’ve done that, but it’s spreading.
The people operating the ticketing systems that are being abused will need to individually take action to deal with those incoming false support requests. They’re already aware of it, you don’t need to try and tell anyone.
Another thing to be aware of - sometimes malicious actors will do this in order to overwhelm your mailbox because they’re doing a identity theft or account takeover thing against you, so watch out for emails that say some password of yours was changed, or a purchase was made or something. This might not apply to you, you mentioned other recipients. But it’s still good to know.
You’d be surprised how many of those emails I am still somehow getting… Not at all surprised.
Where seeing it as well. I’m unsure what the scam is. The ticket systems we saw don’t have any obvious connection to our industry. It is a lot of noise, but it wasn’t like a coverup spam, because it hit multiple users in the org at once. Really a strange thing.
i assume something just got popular with script kiddies, but i want to know what it is and what systems it effects so i can know if I’m protected or not.
gonna keep looking at least as long as i keep seeing this happening
Do yours have an onmicrosoft.com account CC’d? Both cases we have seen have had a different onmicrosoft.com account CC’d.
not sure if all of them did, but some did for sure. off looking address too
Thanks, that helps. I shared this with the mspgeek.org community to see if anyone else is seeing it.