Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Spammers are using Jira to send phishing sites.

TT
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 16, 2023

Hello,

For the third time this month I received an email from Jira stating that I was invited to project and then immediately spammed with a phishing site. I fixed this by creating an account, deleting the issue, and disabling all notifications. 

However, they are using different variations of my email: 
first.last@gmail.com

firstlas.t@gmail.com

fi.rstlast@gmail.com

and so on...

I can't seem to find a proper place to report this. More importantly, I can't believe people can exploit a stable product like Jira so easily. Why would you send me issue notifications before I even create an account? 

Edit: I already reported this to abuse address. Nothing has been done to resolve this issue so I'm assuming Atlassian simply doesn't care.

Untitled.png

1 answer

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
October 16, 2023

Hi,

The site that sent this message has already been suspended today.  It appears that this site was suspended right around the time you posted here to community.  I believe that if you reported this by forwarding it to abuse@atlassian.com then that report is what helped our team to identify this site as violating our terms of service.  Our abuse team is unable to reply to any messages sent to that address though.

Sorry that someone has send you spam with our services.  We are working to takedown such sites faster, and prevent users from abusing messaging features of our products. 

In the future if you receive spam from an Atlassian Cloud site, I would ask that you please forward that message to that email address abuse@atlassian.com

Alternatively, you can report it to us here in Community, or you could reach out to our support contact page https://support.atlassian.com/contact

TT
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 17, 2023

Yes, I saw that it was suspended. The first one one wasn't suspended for a full week, which is frustrating. It would be nice if Jira filtered out emails with a period or with a +, this would make abuse much harder. 

Or, requiring email verification before sending anymore emails would be a much better solution. 

Either way, thank you for the fix. 

Suggest an answer

Log in or Sign up to answer