Attackers Abuse Enterprise Collaboration Tools to Avoid Detection

KnowBe4 Team | Aug 31, 2026

Threat actors’ abuse of enterprise collaboration tools increased fourfold over the past twelve months, according to researchers at Palo Alto Networks’ Unit 42.

“In addition to typical email-based phishing, attackers increasingly misuse trusted collaboration platforms to conduct identity phishing, impersonation, credential theft, malware delivery, and social engineering,” the researchers write. “Over the last 12 months, our endpoint alerts of malicious activity associated with collaboration tools have more than quadrupled. This activity could involve compromised accounts, external federated organizations, guest accounts, or trusted third-party relationships. In each case, the attackers seek to exploit the trust that people place in enterprise communication platforms.”

Nearly all of this malicious activity begins with a traditional phishing attack. Once the attackers have access to an internal collaboration tool, they’re much less likely to be detected by security tools.

“This changes the role that collaboration platforms play within enterprise security,” the researchers write. “They are not just productivity applications, they have become part of the enterprise attack surface. Unit 42 researchers found that 99% of the alerts generated related to chat phishing operations, indicating that attackers often gain access to these environments through targeted phishing operations. After a successful compromise, attackers can then communicate using the identity and privileges of the compromised user. This allows malicious activity to appear as normal collaboration activity.”

Security awareness training provides an essential layer of defense against these attacks, since the threat actors primarily rely on social engineering.

“User awareness remains an important part of effective verification procedures,” Unit 42 says. “People should treat collaboration messages, platform notifications and links to hosted content with the same caution as email. This is especially important when a request involves credentials, MFA approval, software installation, remote access tools or sensitive data. Security training should make clear that content associated with an enterprise collaboration platform is not automatically trustworthy. An attacker can send a direct message, trigger a legitimate platform notification, or use content hosted on an approved service to direct victims to a phishing site. Security awareness teams should include these scenarios in phishing simulations and security awareness exercises. Many people recognize email phishing indicators but might not apply the same scrutiny to collaboration platforms and related notification workflows.”

Unit 42 has the story: https://unit42.paloaltonetworks.com/communication-channel-identity-risks/

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.