Palo Alto Networks, a cybersecurity software company, said its endpoint alerts of malicious activity associated with collaboration tools more than quadrupled from July 2025 to June 2026. Its Unit 42 threat research group recorded 1,490 alerts of low severity or higher in July 2025 and 6,799 in June 2026.

The Unit 42 report said 99% of those alerts were related to chat phishing operations. Those figures count alerts on Palo Alto Networks’ own endpoint alerts, so they track the vendor’s telemetry rather than attack volume across the wider economy.

This pattern is particularly concerning given at many workplaces, identity control tends to end at login. Once someone is in a session, every message they send carries the full trust of colleague, with none of the anti-phishing tooling built for email.

Exploiting trusted communication channels

Collaboration tools give attackers several trusted routes into business conversations. Unit 42 said compromised accounts, external federation, guest access and third-party relationships can let attackers interact through legitimate channels. Once an account is compromised, the attacker can inherit the user’s permissions, relationships and ongoing conversations.

The problem continues after login. Unit 42 said multifactor authentication (MFA), conditional access and session-risk checks can reduce account compromise but cannot stop misuse of a valid session. It recommends watching for unusual messaging, unexpected file sharing and communication with unfamiliar external tenants.

Real-world social engineering campaigns

Recent incidents show how those trusted workflows can be used. In January, Fireblocks said attackers impersonated its recruiters and hiring managers, conducted fake interviews over Google Meet and assigned candidates a coding task whose setup commands triggered malicious code. Fireblocks said the activity closely matched a social-engineering pattern associated with North Korea–linked threat actors and commonly called Contagious Interview.

A March attack on the Axios npm package used a similar trust-building process. In an Axios postmortem, maintainer Jason Saayman said his machine was compromised through targeted social engineering, after which attackers obtained access to npm credentials and published two malicious Axios versions.

In a follow-up comment on the postmortem, Saayman said the attackers invited him to a real Slack workspace built to resemble the impersonated company before moving the interaction to a Microsoft Teams meeting.

Extending security beyond initial login

Unit 42’s advice is largely to treat collaboration platforms like any other identity system. The group said administrators should review external federation, guest access and third-party integrations, while high-risk requests such as MFA approval, software installation or file transfer should be verified through a separate approved channel.

The report also recommends feeding authentication logs, messaging activity, file-sharing events, external-tenant interactions and outbound webhook traffic into a security information and event management (SIEM) system.

Slack as an exfiltration channel

The abuse doesn’t always involve a person typing in a chat window. In a December 2025 incident at a Polish manufacturing company, CERT Polska found that an attacker who had compromised a FortiGate firewall using the device’s built-in Slack notification feature to send the output of credential-stealing scripts to a Slack channel the attacker controlled. No one on the company’s side ever received a suspicious message — the appliance was doing the talking.

Personalized Feed
Personalized Feed