The CyberCall Podcast

Collaboration Platforms are the New Phishing Frontier

Andrew Morgan

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 1:02:59

For years, security awareness training has focused almost entirely on email phishing: spot the bad link, question the urgent request, verify the sender. But Unit 42 just published research showing attackers have found a different door, and most teams aren't watching it. Collaboration platforms like Slack and Teams have become part of the identity attack surface. Unit 42 tracked a fourfold increase in malicious activity tied to these platforms over the past year, and 99% of it started as chat-based phishing.

Here's what makes this especially relevant for MSPs: most organizations use Teams to collaborate with outside companies, including their IT provider. Attackers know that. They pose as the MSP itself, or as IT support, because that relationship already carries a zone of trust. When "your IT provider" messages you on Teams asking you to approve an MFA prompt, most people don't question it, they just comply.

That's why we wanted Wil Klusovsky on the show. Wil's known for translating technical risk into something executives can actually understand and act on, and this topic needs exactly that.

Palo Alto's Unit42 Research:

https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ 

https://unit42.paloaltonetworks.com/microsoft-teams-phishing/