Slack and Teams: The New Launchpad for Phishing
Palo Alto Networks Unit 42 released research last month that should have every CISO rethinking their threat model.
Phishing attempts on Slack and Teams quadrupled in a single year. From under 1,500 alerts monthly to nearly 6,800. And 99% started as simple, text-based messages.
Here's what should terrify you: Most organizations aren't catching these attacks because we spent 20 years training everyone to be paranoid about email and completely naive about Slack.
Your email security is irrelevant to this threat. Your awareness training teaches people to distrust links in messages. Your SIEM logs every external login attempt.
None of it matters. Because the attack isn't happening in email anymore.
The Attack That's Already Running

It's Friday afternoon.
An employee gets a Teams message from what looks like their IT provider. The sender name is right. The workspace feels internal. The message reads: "We've detected an account issue. Can you approve an MFA prompt to verify your identity?"
The employee knows MFA is important. Security matters. They click.
A conversation unfolds over a few minutes. Back and forth. Building credibility. By the time the employee realizes something's wrong, their account is compromised.
This isn't theoretical. APT29 (Midnight Blizzard) and UNC6692 are running this campaign right now. They stand up Microsoft 365 tenants deliberately named to look like IT support. They use typosquatted domains. They send messages that look internal.
It works. And your email gateway sees none of it.
But Here's What Most CISOs Miss

While security teams focus on Teams phishing, a completely different attack unfolds simultaneously on Slack.
An employee receives: "Can you take a look at Q2 numbers? Need your feedback."
Attached: a Google Slides file.
The sender looks familiar. The request is reasonable. Google is trusted. Sharing documents is normal. The employee clicks.
A permission dialog appears asking for access to their Google account. It's the standard OAuth flow. Perfectly legitimate. They grant it.
Now the attacker has access to:
- Google Drive (every file, all data)
- Gmail (entire inbox, all contacts, every message)
- Google Calendar (meeting schedules, sensitive discussions, who meets with whom)
- Every app connected via that Google account (Slack, Teams, Zoom, everything)
Your email gateway doesn't see this. Your network monitoring doesn't see this. Your DLP solution doesn't flag it. Because the attack isn't in email. It's in a trusted collaboration tool asking for perfectly reasonable permissions.
Why This Works So Reliably
When someone asks you to review a Google Slides file in a Slack message from what looks like a colleague, there are layers of assumed trust:
- The platform is internal ✓
- The person looks familiar ✓
- The request is reasonable ✓
- Google is trusted ✓
- Sharing documents is normal ✓
All of them true. All of them together create a perfect storm for account compromise. The attacker doesn't need to be sophisticated. They just need to understand that you've built trust into every layer of the interaction except one: actual visibility into what's connected to your identity.
The Data CISOs Keep Missing
Scale:
- Palo Alto Networks tracked the scale:
- Phishing alerts on Slack and Teams: Increased 4.5x in one year
- Average monthly alerts (now): 6,800+
- Percentage starting as chat-based phishing: 99%
The threat actors are organized:
- APT29 (Midnight Blizzard): Resourced state-sponsored group running sustained campaigns
- UNC6692: Active threat group targeting Teams with credential phishing
- Cloaked Ursa: Coordinated attacks on collaboration platforms
The method is consistent:
- Impersonating IT providers
- Standing up fake Microsoft 365 tenants
- Asking for reasonable access to Google Docs
- Building credibility through multi-message conversations
- Getting in.
And it's working.
The Real Problem: You Can't See What's Connected
When someone compromises an account through Teams phishing, they don't just have Teams access. They have everything connected to that identity.
When someone grants OAuth access to a Google Slides file, they're granting access to their entire Google ecosystem. Calendar. Drive. Gmail. Every contact. Every meeting. Every file.
Think about your organization right now:
- Google Drives connected to Slack
- Slack connected to your email
- Calendars synced across platforms
- Third-party apps with OAuth permissions you've never audited
- Service accounts with elevated access across multiple systems
An attacker compromises one identity and suddenly they have a tunnel into your entire SaaS stack.
What A Real Breach Looks Like Now
Friday 2:38 PM:
Fake Teams message from "Microsoft_Security_Team." Employee sees external tenant warning. Dismisses it as a false positive.
Friday 2:40 PM:
"Security alert: Please approve the MFA prompt below."
Friday 2:41 PM:
Employee clicks. Enters credentials on a fake login page.
Friday 2:42 PM:
Attacker has valid credentials. Access to email, Teams, calendar, file storage, everything connected to that identity.
Simultaneously:
A different employee gets: "Can you review Q2 numbers?" with a Google Slides file from "James Hill."
Friday 1:50 PM:
They click. Grant access to their Google account.
Friday 1:55 PM:
Attacker has access to Google Drive, Gmail, contacts, calendar.
Friday 2:30 PM:
Both attackers exploring. Who has sensitive data? Which integrations are running? Which service accounts have elevated privileges? What does the data architecture look like?
Monday 2:00 AM:
Wire transfer request sent with valid credentials. Authenticates properly. Approval workflows think it's legitimate. By morning, money is gone.
Your email security saw none of this.
Because none of it happened in email.
What You're Actually Blind To
Your current security model assumes:
- Email is the primary threat ✅ (Was true. Not anymore.)
- Collaboration platforms are internal ✅ (They are, but they're also identity vectors.)
- Users know not to click links ✅ (Only in email. Not in chat from colleagues.)
- You monitor who logs into your systems ❌ (Probably not on Slack and Teams.)
- You know what's connected to your identity ❌ (Most organizations don't. Most CISOs can't even list it.)
The gap isn't in your security infrastructure. The gap is in visibility.
You can't protect what you can't see.
What Actually Needs to Happen
First: Stop Assuming Internal Tools Are Safe
Slack, Teams, Google Workspace, they're SaaS applications. They're identity vectors. They're attack surfaces. They can be compromised just as easily as email. And when they are, the blast radius is worse because they're connected to everything.
Second: Map Your Entire SaaS Ecosystem
What's connected to Teams? What OAuth permissions exist? What integrations are running? What apps have access to which data?
Most CISOs can't answer these questions without a SaaS exposure report. And that's the problem.
An attacker who gains control of one compromised identity can traverse your entire SaaS ecosystem in hours. They can read Gmail, access Google Drive, see calendars, authenticate to Slack, pull files from Box, access customer data from Salesforce. They can do it all without triggering your email security or your network monitoring.
Third: Monitor Identity Behavior On Every Platform
See who's logging in to Slack and Teams. When. From where. What are they accessing? What's normal for that identity? What's anomalous?
An impossible login on Slack matters as much as one in email. But most organizations don't monitor it.
The Real Seperation Point
Here's what separates organizations that catch these attacks from those that get breached:
The ones that catch them ask: "Do we have visibility into our entire SaaS attack surface?"
Not: "Are our platforms secure by default?"
Not: "Do our users know not to click links?"
But: "Do we actually see what's happening on every platform where identity lives? Do we know what's connected? Do we monitor for anomalies?"
Because that's where the breach is happening now.
Your Next Move
You have visibility into employee logins in your on-prem systems. You know who's accessing your email. You monitor your firewall.
But you probably don't know:
- How many apps have OAuth access to your Google Workspace
- Which integrations are connected to Slack
- Whether a Teams login from a new geography is normal or an attack
- What data is accessible through a compromised SaaS identity
Close that gap. Before the attack that's already running becomes the breach you're explaining to your board.