Identity Abuse Through Collaboration Tools

Identity Abuse Through Collaboration Tools

Attackers are using legitimate enterprise collaboration tools to steal identities and credentials, resulting in financial losses and reputational damage.

Bottom line: Attackers are using legitimate enterprise collaboration tools to steal identities and credentials, resulting in financial losses and reputational damage.

What's happening: In 2021, attackers successfully compromised Microsoft Teams and Slack accounts, exploiting vulnerabilities in Zoom Webinar and Cisco Webex to gain access to sensitive information. Researchers from Unit 42 observed a 35% increase in phishing attacks targeting collaboration tool users in the first half of 2022.

What to do: Implement a security awareness program to educate users on the risks of phishing attacks and encourage them to verify the authenticity of requests from collaboration tool vendors. Conduct regular security audits to identify and remediate vulnerabilities in collaboration tools.

Source: Unit 42