Identity Abuse Through Trusted Communication Channels
Palo Alto Networks, Thursday, August 20th, 2026
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft.
Palo Alto Networks Unit 42 details how attackers abuse enterprise collaboration tools to conduct identity phishing and steal credentials. Because these channels are trusted internally, messages sent through them bypass the scepticism users apply to external email.
The research covers the techniques involved, including social engineering, misuse of remote access software and attacks against multi-factor authentication. Author Bill Batchelor sets out defense strategies for each.
The piece is aimed at teams whose email controls are mature but whose collaboration platforms are not.