Hackers Are Hijacking Trusted Work Chat Tools to Steal Logins
Cybersecurity researchers at Unit 42 have identified a growing trend where attackers abuse trusted enterprise communication tools—like chat and collaboration platforms—to carry out identity phishing and credential theft. Because employees inherently trust these familiar, everyday work channels, malicious messages sent through them are far more likely to succeed than traditional email phishing attempts.
This tactic works because it exploits human trust rather than technical vulnerabilities. Attackers impersonate colleagues, IT support, or automated system messages within these platforms, prompting staff to click malicious links or enter credentials on fake login pages. Once stolen, these credentials can give attackers access to broader business systems, sensitive data, and financial accounts.
For small and medium businesses relying on tools like Microsoft Teams, Slack, or similar platforms, this represents an evolving risk that many haven't yet accounted for in their security awareness training. Traditional email-focused phishing defenses may not adequately prepare staff to recognise threats arriving through these newer channels.