Tools like Microsoft Teams, Slack, Trello, and Asana have become essential to the modern-day workforce. Since the world shifted to remote work in 2020, our usage of these platforms has skyrocketed — they simplify communication, support seamless file sharing, and let remote workers connect easily. For many professionals, logging into a chat platform is like opening the door to their digital office.
But as we’ve come to rely on these apps, they’ve also become a favored target for cybercriminals.
Why Attackers Prefer Chat Over Email Now
Years of security awareness training have made employees reasonably suspicious of email, checking sender addresses, hovering over links, questioning unexpected attachments. Chat platforms haven’t received the same level of scrutiny or training investment, even though they’re now just as central to daily work. A message in Teams or Slack carries an implicit trust that email has largely lost, since it feels like it’s coming from inside the building, from a coworker, on a platform your company chose and controls. Attackers have noticed this gap and are shifting effort accordingly, which is exactly why collaboration-tool phishing has grown even as email-based awareness has improved.
Friendly Chats, Serious Risks
A report by Veritas found that 71% of remote workers have shared sensitive company information through collaboration tools — usually while just trying to be helpful. If a coworker asks for a file, you send it. But your “coworker” could actually be a cybercriminal who’s taken over their account.
Hackers love this kind of social engineering because it exploits trusted faces. Before responding to a request, ask yourself:
- Do I actually know who’s sending this message?
- Is this the right place to share this information?
- Does this feel like a phishing attempt?
- Am I following my company’s security policies?
- Is there a safer way to respond?
If you have any doubts, don’t respond immediately — a quick phone call or a separate text to verify the request can save you from falling for a scam.
A Real Example of How Convincing These Attacks Get
Consider a message that looks like it’s from your IT department, sent through your actual collaboration platform, referencing a real internal project by name, asking you to approve a routine-looking access request. Nothing about it looks obviously wrong: the platform is legitimate, the tone matches how IT usually communicates, and the project reference proves the sender did their homework. That’s the level of sophistication modern collaboration-tool phishing has reached, and it’s exactly why “does this look suspicious” is no longer a reliable filter on its own. The only reliable check left is verifying through a second channel entirely, a phone call or a walk down the hall, before acting on anything involving access, credentials, or money. It takes thirty extra seconds and costs nothing at all compared to what a successful compromise would actually cost the business, in money, time, client trust, and the weeks it can take to fully recover from a serious account compromise.
More Features Mean More Entry Points
Modern collaboration tools connect your files, calendar, and other apps all in one place — and each connection creates a new entry point for a hacker. The tool TeamsPhisher was built specifically to send phishing messages through Microsoft Teams, and the group Midnight Blizzard tricked employees into approving MFA requests by posing as IT staff.
Check Before You Click
20% of employees admit they don’t check whether a message is real before clicking a link in a team chat. Imagine a message from “Microsoft Identity Protection (External)” asking to chat — that “External” tag is a massive red flag. Your actual IT department wouldn’t reach you from outside your company.
If you respond, you may get a link to “verify your identity” that leads to a fake login page designed to steal your credentials. Instead:
- Verify offline. If a request seems odd, call your IT team or use your official ticketing system.
- No passwords in chat. Never send login info or private data over chat — use a secure, encrypted method instead.
- Watch your hardware. A personal laptop that isn’t managed by your company adds extra risk. Stick to company devices and keep software updated.
Hardening Your Collaboration Platform Itself
Employee awareness matters, but it shouldn’t be the only defense. Most platforms, including Microsoft Teams, let administrators restrict external messaging entirely or require explicit approval before an outside domain can contact your team, closing off the exact channel tools like TeamsPhisher rely on. Conditional access policies can also block sign-ins from unmanaged devices or unexpected locations before an attacker ever gets the chance to send a convincing message in the first place. These platform-level controls catch what a distracted employee might not, and they don’t rely on anyone remembering a training session under pressure.
What IT Should Be Reviewing Regularly
Beyond one-time configuration, collaboration platform security needs periodic review, not a set-and-forget setup. Worth checking on a recurring basis: which external domains are currently allowed to message your team, whether any guest accounts from old projects still have lingering access, and whether conditional access policies still match how and where your team actually works today versus when they were first configured. A policy that made sense when everyone worked from one office often stops matching reality once remote work, contractors, or new offices enter the picture, and nobody notices until it’s tested by an actual attack.
Think Before You Share
Memes, emojis, and quick updates are fine for team chat — passwords and private data aren’t. As we rely more on these tools going forward, staying alert, questioning “urgent” requests, and verifying before clicking keeps the convenience without the exposure.
If you have questions or want expert help, reach out to CelereTech. We help small and mid-sized businesses stay secure while still enjoying the tools that make modern work possible.



