I’ve seen a few hundred of these emails in the past couple days coming in from multiple different companies.

I’m looking for more info.

at least one said it was zendesk, most did not say any software.

the tickets are being sent with CC addresses that contain large email lists. often others on the CC who don’t know what’s happening will reply “stop emailing me”.

so far I’ve seen this coming in to multiple addresses and none of the sending companies are familiar either.

sounds familiar to anyone? any info on this? it’s there a name i can lookup to find more info? i want to know what services this effects so i can properly protect my stuff and my work stuff.

-26 points
*

Reply-all with “unsubscribe”

Edit: Jesus, y’all are dense.

permalink
report
reply
3 points

that’s not going to stop the hacked system from spamming myself and every other customer they have. I would highly doubt if they even take the time to look at any replies let alone actually read them and unsubscribe anyone who asked for it… after the entire hack was over because I called one company and they were already aware of the hack and were trying to stop it.

permalink
report
parent
reply
-9 points

It baffles me how many people thought I was actually serious.

permalink
report
parent
reply
2 points

first day on the internet?

permalink
report
parent
reply
1 point

I’m getting big “haha i was just pretending” vibes from that guy who wrote you a paragraph lol

permalink
report
parent
reply
0 points

Ah, reply STOP

permalink
report
parent
reply
42 points

Don’t confirm your email, it only increases its value to the black hats.

permalink
report
parent
reply
-7 points

Oh shucks my super serious suggestion wasn’t the best idea?

permalink
report
parent
reply
4 points
*

My comment was to others who didn’t see that you used that sarcastic font when you hit post.

I didn’t downvote. 🤷

permalink
report
parent
reply
8 points

I’ve only seen four or five. What do you use to filter your emails?

permalink
report
reply
3 points

other than specific filters and generic spam filter I have the “if content contains ‘unsubscribe’ then mark as read and never mark important”

permalink
report
parent
reply
1 point

Whose your email provider? Or do you self-host? If you have a provider you can report the spam to them so they can update their systems.

permalink
report
parent
reply
2 points

I’m using Google. I’ve done that too. protecting inboxes is step one for sure, but i also want to know the extent of this. it’s not enough for me to just block the emails and leave it at that.

if it keeps coming and i fail to block them all i want to have some info on the intent of this so I can properly educate others i work with to defend ourselves

permalink
report
parent
reply
5 points

Watch out for email footers like “This is important account information. You cannot unsubscribe from these emails.”.

permalink
report
parent
reply
2 points

oh, yeah. it’s not perfect but it sure does remove so much crap i don’t intend to read.

i recently missed an event invite because of it… luckily i was just a late responder and have not actually missed the event itself

i definitely have to “browse” the unimportant emails regularly

permalink
report
parent
reply
39 points
*

Why do you think anything is hacked? It’s trivially easy to send an email pretending to be someone else. There’s no validation.

Do they contain valid data or something?

permalink
report
reply
-13 points

this isn’t that

permalink
report
parent
reply
9 points

Could you elaborate on why you think that?

permalink
report
parent
reply
0 points

I’ve seen hundreds of those and they’re mostly phishing attempts. this new one doesn’t look anything like that.

this one has multiple addresses in the CC field, at least one of which is always a predefined list on the senders side. and it’s otherwise a legit looking support ticket response.

but i want to know what’s the origin, what’s the vectors, and what’s the target.

permalink
report
parent
reply
2 points

There’s no validation.

SPF.

permalink
report
parent
reply
5 points

Optional, but recommended. But doesn’t guarantee anything unless both sides respect it. Also, IP spoofing is a thing.

Email is a broken protocol. There’s a great copy pasta about why it can’t or won’t be fixed, which I unfortunately can’t find. But it boils down to the fact that you can’t get everyone to agree on, or implement, the fixes necessary to prevent spam.

permalink
report
parent
reply
1 point

Use a host that requires it. Done?

permalink
report
parent
reply
20 points

This is someone abusing ticketing systems that send autoresponses. Nothing has been hacked, the best thing for you to do is make a mailbox filter rule that trashes those and move on.

permalink
report
reply
2 points

I’ve done that, but it’s spreading.

permalink
report
parent
reply
14 points

The people operating the ticketing systems that are being abused will need to individually take action to deal with those incoming false support requests. They’re already aware of it, you don’t need to try and tell anyone.

Another thing to be aware of - sometimes malicious actors will do this in order to overwhelm your mailbox because they’re doing a identity theft or account takeover thing against you, so watch out for emails that say some password of yours was changed, or a purchase was made or something. This might not apply to you, you mentioned other recipients. But it’s still good to know.

permalink
report
parent
reply
2 points

Where seeing it as well. I’m unsure what the scam is. The ticket systems we saw don’t have any obvious connection to our industry. It is a lot of noise, but it wasn’t like a coverup spam, because it hit multiple users in the org at once. Really a strange thing.

permalink
report
reply
2 points

i assume something just got popular with script kiddies, but i want to know what it is and what systems it effects so i can know if I’m protected or not.

gonna keep looking at least as long as i keep seeing this happening

permalink
report
parent
reply
1 point

Do yours have an onmicrosoft.com account CC’d? Both cases we have seen have had a different onmicrosoft.com account CC’d.

permalink
report
parent
reply
1 point

not sure if all of them did, but some did for sure. off looking address too

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 12K

    Posts

  • 544K

    Comments