In a recent security notice, the firm disclosed the incident that remained undetected for around three years. The firm noticed this breach after a security alert from a third-party that affected Zendesk. Nonetheless, it allegedly hit only a small subset of users.
As stated by the firm,
On September 24, we identified approximately 10,000 Zendesk Support and Chat accounts, including expired trial accounts and accounts that are no longer active, whose account information was accessed without authorization prior to November of 2016.This breach specifically affected Zendesk Support and Chat products. The breached information could include some PII data of some users. Precisely, it included names, email addresses, contact numbers of agents and end-users, and hashed & salted passwords of both the agents as well as the end-users.
Whereas, for some 700 accounts, the information also included TLS encryption keys and app configuration settings.
Moreover, they have also informed the affected customers regarding the breach. They are also implementing password rotations requiring users to set new passwords who have not done so since November 1, 2016.
While Zendesk continues the investigation, for more details, users can visit their dedicated FAQ page.
Let us know your thoughts in the comments.