Tumblr, Pinterest, Twitter hipsters exposed in Zendesk data raid

Hacker slurps email info from helpdesk biz


Customer service provider Zendesk has been hacked - potentially blowing the lid on the anonymity of some users of Twitter, Pinterest and Tumblr.

Zendesk, which handles helpdesk emails for the aforementioned trendy blog trio, copped to the breach of its network in a blog post last night. It admitted its system was illegally accessed this week and a hacker got into support information for those three clients.

The intruder downloaded email addresses for users who'd got in touch with Tumblr, Twitter and Pinterest via Zendesk for support, as well as the message subject lines. Although no sensitive information beyond this was swiped, the hacker can at least associate the email addresses with their owners' profiles and potentially unmask any anonymous tweeters, pinsters or tumblers behind them.

"We’re incredibly disappointed that this happened and are committed to doing everything we can to make certain it never happens again," the firm said. "We’ve already taken steps to improve our procedures and will continue to build even more robust security systems.

"We are also completely committed to working with authorities to bring anyone involved to justice and make certain we fully understand what happened. As this process unfolds, we aim to update our customers in as transparent and timely a manner as possible about new developments."

Twitter's support had this to say about the breach:

Meanwhile Tumblr emailed all of its affected users reminding them not to give out their password by email and warning them to watch out for unexpected emails.

"We're working with law enforcement and Zendesk to better understand this attack," the blogging site said. "Please monitor for email and Tumblr accounts for suspicious behaviour and notify us immediately if you have any concerns."

Zendesk is a customer service that sorts out support emails and queries from clients' users. Tumblr said it had been using the service for the last two and a half years. ®

Similar topics


Other stories you might like

  • Verizon: Ransomware sees biggest jump in five years
    We're only here for DBIRs

    The cybersecurity landscape continues to expand and evolve rapidly, fueled in large part by the cat-and-mouse game between miscreants trying to get into corporate IT environments and those hired by enterprises and security vendors to keep them out.

    Despite all that, Verizon's annual security breach report is again showing that there are constants in the field, including that ransomware continues to be a fast-growing threat and that the "human element" still plays a central role in most security breaches, whether it's through social engineering, bad decisions, or similar.

    According to the US carrier's 2022 Data Breach Investigations Report (DBIR) released this week [PDF], ransomware accounted for 25 percent of the observed security incidents that occurred between November 1, 2020, and October 31, 2021, and was present in 70 percent of all malware infections. Ransomware outbreaks increased 13 percent year-over-year, a larger increase than the previous five years combined.

    Continue reading
  • Slack-for-engineers Mattermost on open source and data sovereignty
    Control and access are becoming a hot button for orgs

    Interview "It's our data, it's our intellectual property. Being able to migrate it out those systems is near impossible... It was a real frustration for us."

    These were the words of communication and collaboration platform Mattermost's founder and CTO, Corey Hulen, speaking to The Register about open source, sovereignty and audio bridges.

    "Some of the history of Mattermost is exactly that problem," says Hulen of the issue of closed source software. "We were using proprietary tools – we were not a collaboration platform before, we were a games company before – [and] we were extremely frustrated because we couldn't get our intellectual property out of those systems..."

    Continue reading
  • UK government having hard time complying with its own IR35 tax rules
    This shouldn't come as much of a surprise if you've been reading the headlines at all

    Government departments are guilty of high levels of non-compliance with the UK's off-payroll tax regime, according to a report by MPs.

    Difficulties meeting the IR35 rules, which apply to many IT contractors, in central government reflect poor implementation by Her Majesty's Revenue & Customs (HMRC) and other government bodies, the Public Accounts Committee (PAC) said.

    "Central government is spending hundreds of millions of pounds to cover tax owed for individuals wrongly assessed as self-employed. Government departments and agencies owed, or expected to owe, HMRC £263 million in 2020–21 due to incorrect administration of the rules," the report said.

    Continue reading

Biting the hand that feeds IT © 1998–2022