Cybersecurity Research

Hackers Are Hijacking Trusted Work Chat Tools to Steal Logins

Unit 42 · 20 Aug 2026
Key Takeaway Extend your phishing awareness training beyond email to cover chat and collaboration tools, and encourage staff to verify unexpected login requests through a separate channel before entering credentials.

Cybersecurity researchers at Unit 42 have identified a growing trend where attackers abuse trusted enterprise communication tools—like chat and collaboration platforms—to carry out identity phishing and credential theft. Because employees inherently trust these familiar, everyday work channels, malicious messages sent through them are far more likely to succeed than traditional email phishing attempts.

This tactic works because it exploits human trust rather than technical vulnerabilities. Attackers impersonate colleagues, IT support, or automated system messages within these platforms, prompting staff to click malicious links or enter credentials on fake login pages. Once stolen, these credentials can give attackers access to broader business systems, sensitive data, and financial accounts.

For small and medium businesses relying on tools like Microsoft Teams, Slack, or similar platforms, this represents an evolving risk that many haven't yet accounted for in their security awareness training. Traditional email-focused phishing defenses may not adequately prepare staff to recognise threats arriving through these newer channels.

phishing identity theft collaboration tools credential theft employee training

Summarised by CISO AI from Unit 42. We link back to every original so you can read it yourself.