Published · 3d agoSecurity3 min read
Collaboration-tool alerts quadrupled in a year. The inspection budget still sits with email.
Unit 42 reports endpoint alerts tied to collaboration tools more than quadrupled in 12 months, with 99% linked to chat phishing. Most controls still watch email and logins, not authenticated sessions.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Unit 42 reports that over the last 12 months, its endpoint alerts of malicious activity associated with collaboration tools have more than quadrupled.
- Unit 42 researchers found that 99% of the alerts generated related to chat phishing operations, indicating attackers often gain access to these environments through targeted phishing operations.
- The activity could involve compromised accounts, external federated organizations, guest accounts or trusted third-party relationships.
- Security controls typically remain focused on email and authentication events, often providing limited visibility into activity occurring within authenticated collaboration sessions.
- Unlike email, collaboration platforms enable real-time conversations and support features such as external federation, guest access, shared workspaces and third-party integrations.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Unit 42 says its endpoint alerts for malicious activity associated with collaboration tools have more than quadrupled over the last 12 months [1], and that 99% of the alerts generated related to chat phishing operations [2]. That is a budget statement as much as a threat statement: the inspection, logging and retention money in most organizations sits with email, while Unit 42's own framing is that security controls typically remain focused on email and authentication events and provide limited visibility into activity inside authenticated collaboration sessions [4].
Read the number carefully before you spend on it. More than quadrupling is an increase of more than 300% [14], but the write-up as supplied does not publish absolute counts or a per-platform breakdown, and does not name specific collaboration vendors in the section provided [16]. This is vendor telemetry: Palo Alto Networks lists Cortex XDR and XSIAM among the products it says protect customers from the activity described [12]. A quadrupling off a small base is still a small base. It is the direction and the entry path that should move planning, not the multiple.
The entry paths are the part worth funding. Unit 42 says the activity can involve compromised accounts, external federated organizations, guest accounts or trusted third-party relationships [3]. Unlike email, these platforms support real-time conversation plus external federation, guest access, shared workspaces and third-party integrations [5], and organizations typically wire platform access to their identity provider [10]. So the failure mode is not a bad attachment arriving from outside. It is a legitimate, authenticated session behaving normally. When an account is compromised, the attacker inherits that user's identity context, including permissions, relationships and ongoing conversations [6], and can then communicate with the compromised user's identity and privileges so the activity looks like ordinary collaboration [8]. Unit 42's point is that a request which would look suspicious in email looks routine when it arrives through an authenticated collaboration platform [7].
The uncomfortable implication for detection engineering is that authentication logs are the wrong place to look. The compromise, by Unit 42's count, usually starts with targeted chat phishing [2] and continues after a valid login [8]. Unit 42 says these platforms should be treated as part of the identity attack surface, and that protecting them requires both strong authentication and visibility into how trusted identities and channels are used after authentication [11]. In operator terms: message and file-share telemetry retained on the same schedule as mail, an owned and expiring inventory of federated tenants and guest accounts, and the ability to reconstruct a chat session weeks later during an investigation. None of that is free, and none of it is what a collaboration licence buys by default.
What to watch. First, whether any vendor publishes absolute counts or a platform-by-platform split, because a 4x figure without a denominator cannot be compared across environments [16]. Second, whether the 99% chat-phishing share holds; at most 1% of these alerts currently trace to other vectors [15], and federation and guest-account abuse are already listed as pathways [3], so that mix is the leading indicator to track. Third, the staging: Unit 42 says attackers use these platforms across multiple stages, from initial access to post-compromise operations [13], which is where detection content, not licensing, decides the outcome.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Unit 42 reports that over the last 12 months, its endpoint alerts of malicious activity associated with collaboration tools have more than quadrupled.
- [2]
Unit 42 researchers found that 99% of the alerts generated related to chat phishing operations, indicating attackers often gain access to these environments through targeted phishing operations.
- [3]
The activity could involve compromised accounts, external federated organizations, guest accounts or trusted third-party relationships.
ReportedView cited source - [4]
Security controls typically remain focused on email and authentication events, often providing limited visibility into activity occurring within authenticated collaboration sessions.
ReportedView cited source - [5]
Unlike email, collaboration platforms enable real-time conversations and support features such as external federation, guest access, shared workspaces and third-party integrations.
ReportedView cited source - [6]
When a collaboration account is compromised, attackers inherit the identity context of that user, including their permissions, relationships and ongoing conversations.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- unit42.paloaltonetworks.comBill Batchelor3d agoIdentity Abuse Through Trusted Communication Channels
- unit42.paloaltonetworks.com2d agoPalo Alto Networks
Additional citations
- Unit 42, Palo Alto Networks
- Palo Alto Networks



