
Customer service solutions provider Zendesk, which provides software-as-a-service products related to customer support, sales, and other customer communications, has suffered a data breach after hackers targeted its employees with an SMS phishing campaign.
The news came out when cryptocurrency trading and portfolio management company Coinigy revealed that Zendesk had informed it about a cybersecurity incident in an email, stating that Zendesk learned on October 25 that a sophisticated SMS phishing campaign targeted several employees.
The email continued that some employees fell for the trap and provided the attackers with their account credentials, enabling them to access unstructured data between September 25 and October 26, 2022.
Zendesk informed Coinigy that while account-specific service data might have been present in the logging platform data, there was no evidence that Coinigy’s Zendesk instance had been accessed. However, a probe is still underway.
On its website, Zendesk doesn’t appear to have posted any statement or notice regarding this incident. According to the currently available information, the attack on Zendesk may be connected to the 0ktapus campaign, in which a threat actor with apparent financial motivations targeted more than 130 organizations between March and August 2022, including well-known firms like Twilio and Cloudflare.
Cryptocurrency companies were among the victims of the 0ktapus attackers, who used SMS-based phishing messages to obtain employee credentials. It’s possible that the same hackers who attacked Twilio and Cloudflare in August also attacked Zendesk since there was no sign that the campaign was not still active. While Coinigy appears to have learned about the data breach from Zendesk only in January 2023, other victims seem to have learned about it much earlier.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543