Top
Best
New

Posted by Philpax 2 days ago

Tell HN: Another round of Zendesk email spam

Looks like there's another round of Zendesk email spam happening. I've gotten hundreds over the last half-hour.
104 points | 54 commentspage 2
bitwize125 2 days ago|
sounds like a sign up bomb for github addresses, these are typically used to hide new login notifications by threat actors
LoganDark 2 days ago||
Huh. I thought this was targeted to me in particular, because it started coming up with new aliases at my Firefox Relay subdomain, and then only once I started blocking them it started using plus-addressing on my gmail. Annoying.
bravetraveler 2 days ago||
They're being used to hit addresses of mine exposed to Discord and GitHub. Catch-all had the names of two people in the news, oddly, as well. Hint: 1,000 bottle delivery to an island.
lynndotpy 2 days ago|
Those names are diddy and epstein, for those wondering.
ddtaylor 2 days ago||
Why do we have to tease out the names of convicted criminals?
bravetraveler 1 day ago|||
More 'entertainment' than 'have to', parent named them correctly. Keeping the memes alive, not acting like they're Beetlejuice.

Why did my teaser provoke your comment? Rhetorical, by the way.

ddtaylor 1 day ago||
What I am wondering here is are we doing this stuff now on HN where we don't say the scary words like how YouTube content blacks out words on screen because they don't want to spook the algorithm
bravetraveler 1 day ago||
Self-censoring? No. In more words: not in my case, at least. Thinking way too hard about it, there's surely a better use of your time
lynndotpy 2 days ago|||
I am not sure what you mean. But I did receive many `epstein@` and `diddy@` catch-alls. As I type, they're starting up again.
noname120 2 days ago||
Yeah same here, specifically on my (public) GitHub email address
axka 2 days ago||
I'm getting emails titled "Activate account for ...", and addressed to random names of web services at my domain (e.g. reddit@example.org). Also Twitch-related names like pog, kekw and xqc.

Also super annoying are crypto scams sent from an Italian ISP's (tiscali.it, shame on you) email service, even though I tried to contact the ISP, but that's unrelated to this.

trevyn 2 days ago|
Yep, same here, with those exact prefixes...
timvisee 2 days ago||
I've also received about 40 messages, on mail adresses I've never used before.
rootxy 2 days ago||
Same here, I removed my email address from Github and all other public pages
dang 2 days ago||
I got about 50 of these this morning and thought it was a disgruntled HN user.
catgirlinspace 1 day ago||
weirdly i have 10+ wild card domains and some very public emails (websites with nothing to prevent bots) yet i’ve not gotten even one?
_Chief 2 days ago|
Received 15+ in 10mins on a public email (dropbox, soundcloud, gitlab, tidelift etc). Then just started hitting handles on the domain ( diddy@, epstein@ ). Just placing an aggressive block for "Activate account" and "zendesk" in content for now
More comments...