Trusted work chat is becoming a path to account takeover
THE BRIEF
The technique matters because a message inside a company workspace can appear safer than an external email. Attackers may compromise a real account, invite a victim into an external tenant or impersonate support staff and colleagues. Once they establish a conversation, they can direct the user to a fake sign-in page, request approval for an application or persuade them to share information. A successful account takeover can expose chat history, files and business applications connected to the same identity. Unit 42’s research contains observed case material and defensive telemetry. It describes a pattern rather than one single breach, and the prevalence of each technique will vary by organization and platform. The defensive change is to treat collaboration messages as untrusted requests when they involve credentials, payments, access changes or software. Employees need an independent route to verify unusual instructions. Security teams should monitor external tenants, risky application consent, new device registrations and abnormal use of trusted accounts.
WHY IT MATTERS
Work chat removes many warning signs people associate with phishing: the interface is familiar, the sender may display a colleague’s name and the conversation can unfold gradually. That increases the chance that an employee approves access or acts on a payment request before checking another channel. For managers, collaboration platforms are now part of the identity perimeter. Their guest settings, application permissions, retention and incident logs deserve the same governance as email and remote access. The result can be lost money, account disruption and long recovery work for affected people.
WHO SHOULD CARE
Employees, finance teams, help desks, collaboration-platform administrators and small businesses using cloud workspaces should care because a message from a familiar-looking account can lead to credential theft, fraudulent payments or broader account takeover. They need clear steps because delays can increase financial, privacy or operational harm.
WHAT TO DO NOW
- Verify payment, credential and access-change requests through a separate known channel.
- Restrict external messaging and guest access to documented business needs.
- Review and limit user consent for third-party applications.
- Require phishing-resistant multi-factor authentication for sensitive accounts where possible.
- Alert on new device registration, unusual tenant invitations and abnormal sign-in locations.
- Give employees a simple way to report suspicious chat messages without forwarding dangerous links.
VERIFICATION NOTE
Verified as primary threat research from Unit 42, based on observed campaigns and security telemetry. The report supports the described techniques and defensive controls but is not a population-wide measurement of all collaboration-platform abuse. No single victim count is asserted, and the brief avoids treating every external or unexpected work-chat message as malicious.