CYBER DELTA FORCESearch

Identity Abuse Through Trusted Communication Channels

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft.

CDF News DeskPalo Alto Unit 4220 Aug 2026, 3:30 pm
Image courtesy of Palo Alto Unit 42. Original report
CDF REPORT

Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Identity has become a primary security boundary for most organizations, reducing the ability to solely trust other boundaries once associated with corporate networks. With the adoption of software-as-a-service (SaaS) on the rise, people are shifting to platforms for communication and collaboration. In addition to typical email-based phishing, attackers increasingly misuse trusted collaboration platforms to conduct identity phishing, impersonation, credential theft, malware delivery and social engineering.

Unit 42 researchers found that 99% of the alerts generated related to chat or voice phishing operations, indicating that attackers often gain access to these environments through targeted phishing operations. We also provide practical recommendations for detecting and defending against identity-focused attacks targeting enterprise collaboration platforms. This reduces a target’s suspicion and increases the effectiveness of identity phishing, impersonation, credential theft and social engineering. The threat actor behind this activity impersonated administrators and employees from targeted organizations and sent phishing links through direct messages, channel mentions and legitimate notifications.

Protecting them requires both strong authentication, and visibility into how trusted identities and communication channels are used after authentication. In our Insights article, "When 'Hi, This Is IT' Comes Through Microsoft Teams" , we discussed how APT29 used compromised Teams accounts to send links to credential-harvesting pages . In this case, the threat actor sent a RAR file via a link to a victim in a Teams chat. The attackers relied on recognized identities, legitimate services and familiar business processes to obtain credentials or persuade victims to take actions that enabled identity compromise.

This changes the role that collaboration platforms play within enterprise security. We examine how threat actors leverage trusted communication channels and review identity abuse techniques. Requests that might appear suspicious in an email can appear routine when delivered through an authenticated collaboration platform. As organizations adopt more SaaS collaboration platforms, they should treat these environments as part of the identity attack surface.

Security teams should review unexpected Slack webhook traffic, uncommon user agents and webhook activity from systems without an approved Slack integration. Where possible, limit external communications to trusted organizations, and implement a process to review guest accounts regularly and remove unnecessary access. Security teams should monitor for behavior that could indicate identity compromise, including unusual messaging activity, unexpected file sharing or communications with unfamiliar external tenants.

What changed

Recent campaigns demonstrate that attackers use collaboration platforms in multiple stages of identity-focused attacks, from initial access to post-compromise operations.

We reported that attackers misuse external federation in Teams to initiate conversations with victims while impersonating IT support or other trusted personnel.

Unlike commonly-seen email phishing, some collaboration platforms support interactive communication.

Attackers use impersonation to exploit trust in collaboration platforms and gain access to enterprise identities, posing as known individuals, trusted organizations or support personnel.

Each of these campaigns used impersonation through trusted collaboration workflows.

Instruct people to verify high-risk requests through an approved secondary channel, such as a known phone number, ticketing system or documented internal process.

Who is affected

After a successful compromise, attackers can then communicate using the identity and privileges of the compromised user.

Palo Alto Networks customers are better protected from the threats discussed above through the following products and services: If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team .

Employees use these platforms to exchange messages, share files, coordinate projects and communicate with colleagues, customers and business partners.

Organizations typically connect collaboration platform access to their identity provider, and people rely on these platforms for trusted, authenticated communication.

Attackers can exploit compromised accounts, trusted business relationships or authorized external access to interact with victims through legitimate communication channels.

When a collaboration account is compromised, attackers inherit the identity context of that user, including their permissions, relationships and ongoing conversations.

Why this matters

Unit 42 researchers found that 99% of the alerts generated related to chat or voice phishing operations, indicating that attackers often gain access to these environments through targeted phishing operations.

We also provide practical recommendations for detecting and defending against identity-focused attacks targeting enterprise collaboration platforms.

This reduces a target’s suspicion and increases the effectiveness of identity phishing, impersonation, credential theft and social engineering.

The threat actor behind this activity impersonated administrators and employees from targeted organizations and sent phishing links through direct messages, channel mentions and legitimate notifications.

Note that attackers may avoid sending files through Teams because doing so creates an additional detection point through Safe Links/Safe Attachments, instead directing victims to websites or scripts during calls.

The attacker can then access enterprise and cloud services with the privileges and identity context of the compromised user.

The technical picture

Protecting them requires both strong authentication, and visibility into how trusted identities and communication channels are used after authentication.

In our Insights article, "When 'Hi, This Is IT' Comes Through Microsoft Teams" , we discussed how APT29 used compromised Teams accounts to send links to credential-harvesting pages .

In this case, the threat actor sent a RAR file via a link to a victim in a Teams chat.

The attackers relied on recognized identities, legitimate services and familiar business processes to obtain credentials or persuade victims to take actions that enabled identity compromise.

One script retrieved the password of a privileged identity, and another script modified security settings and disabled two-factor authentication for a privileged account.

This activity combined identity persistence and credential exfiltration with a legitimate SaaS integration.

Because these platforms are integrated with enterprise identities, security controls should focus on both preventing identity compromise and detecting misuse after authentication.

Identity protections should also extend beyond authentication.

How organizations are responding

This changes the role that collaboration platforms play within enterprise security.

We examine how threat actors leverage trusted communication channels and review identity abuse techniques.

Requests that might appear suspicious in an email can appear routine when delivered through an authenticated collaboration platform.

As organizations adopt more SaaS collaboration platforms, they should treat these environments as part of the identity attack surface.

One of the most common techniques is identity phishing through enterprise collaboration platforms.

Okta Threat Intelligence has also documented the technique of identity phishing through attacker-controlled Slack workspaces .

What defenders should do now

Security teams should review unexpected Slack webhook traffic, uncommon user agents and webhook activity from systems without an approved Slack integration.

Where possible, limit external communications to trusted organizations, and implement a process to review guest accounts regularly and remove unnecessary access.

Security teams should monitor for behavior that could indicate identity compromise, including unusual messaging activity, unexpected file sharing or communications with unfamiliar external tenants.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

MORE IN CLOUD & IDENTITY

More cybersecurity reporting

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev ServersThe Hacker News · 15 Sept 2026, 4:42 pmChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEThe Hacker News · 15 Sept 2026, 11:01 amTwitch extension with 30K installs exposes users’ OAuth tokensBleepingComputer · 15 Sept 2026, 12:33 amUnmasking Cloud Identities: From Behavioral Clustering to Automated DetectionPalo Alto Unit 42 · 14 Sept 2026, 3:30 pm