Collaboration tool phishing forces identity security rethink

Enterprise chat messages surrounding a highlighted digital identity badge under security scrutiny.

Trusted workplace chats become an identity attack surface​

Unit 42 says attackers are increasingly abusing enterprise collaboration platforms for identity phishing, impersonation, credential theft and malware delivery. In research published Aug. 20, 2026, the firm reported that endpoint alerts tied to malicious activity associated with collaboration tools more than quadrupled over the previous 12 months. The finding shifts Slack, Microsoft Teams and similar SaaS communication tools from productivity software into a monitored part of the identity perimeter.

Collaboration platforms move inside the security boundary​

Enterprise identity has become a primary security boundary because employees use the same identities to reach cloud services, business applications, collaboration channels and sensitive data. Unit 42 argues that this makes collaboration platforms part of the enterprise attack surface, not just a place where employees exchange messages and files.

The risk is rooted in trust. Collaboration tools support real-time chats, external federation, guest access, shared workspaces and third-party integrations. Those features are useful for business, but they can also let an attacker communicate through a compromised account, a trusted outside organization or an authorized guest relationship. A request that might look suspicious in email can appear ordinary when it arrives inside an authenticated workplace chat.


Phishing shifts from inboxes to trusted chats​

Unit 42 said 99% of the alerts it analyzed in this area were related to chat phishing operations. The firm described these attacks as attempts to exploit the trust users place in enterprise communication platforms after authentication has already occurred.

The report points to Microsoft Teams and Slack as examples of channels abused in recent campaigns. Unit 42 previously reported that APT29 used compromised Teams accounts to send links to credential-harvesting pages and used external federation to initiate conversations while impersonating IT support or other trusted personnel. The source also cited Okta Threat Intelligence reporting on attacker-controlled Slack workspaces that used direct messages, channel mentions and legitimate notifications to send phishing links.

The practical implication for defenders is that the first suspicious signal may not be the chat message itself. Security teams may instead see the downstream action: a file transfer, a browser session, an endpoint alert, an unfamiliar external tenant interaction or a new sign-in pattern tied to a valid enterprise identity.


Impersonation campaigns target familiar workflows​

The strongest examples in the report show attackers wrapping identity abuse in familiar business processes. Unit 42 cited a January 2026 Fireblocks disclosure about a recruitment-themed social engineering campaign in which attackers impersonated Fireblocks executives, recruiters and hiring managers, contacted technology workers and used Google Meet interviews to make the impersonation more convincing.

The report also cited a March 2026 campaign against the lead maintainer of the Axios npm package. In that case, a threat actor allegedly created a staged Slack workspace with company branding, channels, users and message history, then moved the interaction to a staged Teams meeting. Unit 42 said the maintainer was convinced to install software that delivered a remote access Trojan, after which the actor gained access to the npm account and published two poisoned Axios versions.

A third example came from an April 2026 OpenSSF report involving members of the Linux Foundation TODO Group Slack workspace and related communities. Unit 42 said the actor impersonated a known community leader through Slack direct messages and used a fraudulent Google Workspace authentication flow to collect information and deliver malware. The common pattern is not a single platform vulnerability. It is the use of recognized identities, real services and familiar workflows to lower suspicion.


Post-compromise abuse reaches SaaS integrations​

Unit 42 also highlighted abuse after an identity or system has already been compromised. The report cited a December 2025 intrusion investigated by CERT Polska in which a threat actor modified compromised firewall-VPN appliances at a manufacturing company in Poland and used built-in scripting and Slack notification capabilities to send results to a Slack channel controlled by the actor.

That case matters because it shows trusted collaboration services being used as part of persistence and credential exfiltration, not only initial phishing. Unit 42 noted that webhook traffic to collaboration services can be legitimate, but unexpected Slack webhook activity, uncommon user agents or webhook traffic from systems without an approved integration should be reviewed. The same logic applies to Microsoft Teams, which supports similar incoming webhook workflows.


Defensive priorities for identity teams​

Unit 42 recommends treating collaboration platforms with scrutiny comparable to email and identity infrastructure. The first step is reducing unnecessary exposure by reviewing external federation, guest access and third-party integrations, then limiting external communication to trusted organizations where possible.

Authentication controls remain necessary but incomplete. Multifactor authentication, conditional access and session risk evaluation can reduce compromise risk, but they do not prevent an attacker from misusing a valid session. The report calls for monitoring unusual messaging activity, unexpected file sharing, unfamiliar external tenant communications, administrative changes, outbound webhook usage and unusual connections from infrastructure such as firewalls, VPN appliances, load balancers and managed switches.

User verification procedures are also central. Unit 42 says users should not approve MFA prompts, install remote access tools, share credentials, transfer files or change access based only on a collaboration message. High-risk requests should be verified through an approved secondary channel such as a known phone number, ticketing system or documented internal process. For security teams, the useful goal is correlation: combine identity telemetry, sign-in activity, endpoint alerts, file-sharing events and external tenant data so authenticated activity can still be challenged when it behaves abnormally.


Conclusion​

The Unit 42 report does not suggest that collaboration platforms are inherently unsafe. It shows that attackers are adapting to the places where employees now trust messages, files, meetings and notifications.

For enterprises, the lesson is that authentication is no longer enough to establish trust. Collaboration activity must be visible, logged, triaged and connected to identity and endpoint monitoring. If a compromised identity can speak from inside a trusted channel, defenders need controls that recognize misuse after the login succeeds.


Sources​


Editorial Team - CoinBotLab
  • Reading time 5 min read
  • Views6
  • Reading time 5 min read
  • Views29
  • Reading time 4 min read
  • Views19
  • Reading time 5 min read
  • Views28
  • Reading time 7 min read
  • Views35
  • Reading time 5 min read
  • Views33

Comments

There are no comments to display

Information

Author
CoinBotLab AI Editor
Published
Reading time
5 min read
Views
1

More by CoinBotLab AI Editor

Top