
Slack user credentials have been found on hacking forums and the dark web , but an analysis shows that hacking groups have little interest in the platform.
That's the conclusion of cybersecurity firm KELA, which scoured underground markets for Slack credentials after the Twitter hack last week.
KELA began searching for Slack credentials on hacking forums and marketplaces because of a New York Times report detailing the Twitter hack .
The report said that the massive Twitter breach was carried out by a teenager who tricked a Twitter employee, through social engineering, and gained access to the company's Slack channel.
Journalists claim that the attacker found a username and password for an internal Twitter admin tool that was present in one of the Slack channel chat rooms. The hacker used this tool to wreak havoc by compromising a large number of high-profile accounts to carry out a cryptocurrency scam.
Twitter never confirmed the NYT report, but the article highlighted the importance and widespread use of Slack as a corporate tool, primarily for internal communications between employees.
Around 17,000 credentials are being sold online
KELA searched for exposed Slack credentials on dark web marketplaces and found more than 17,000 that had recently been put up for sale online, on hacking forums, and on marketplaces such as Genesis.
However, KELA said that despite the large number of credentials, hackers are not showing much interest.
“While at least 4,300 organizations have their Slack credentials available for sale, demand is low,” said Raveed Laeb, product manager at KELA.
Laeb said hackers rarely seek to gain access to the platform.

"Nearly a year after it was published, the ad [pictured above] still has no answers," Laeb said.
Slack usually doesn't provide important data
Laeb cited several reasons why cybercriminals don't pay attention to Slack even though it is a "gateway to corporate platforms and internal data.".
The main reason is that Slack rarely contains useful information. Even if hackers gain access to an account, the platform mainly contains conversations between colleagues, with little information and opportunities for further access to a company's internal network. It is a web-based tool and does not directly connect to Domain Admins, firewalls, or other company equipment.
Sure, attackers can trick a company's employees into going to phishing pages or installing malware on systems , but Laeb says that process is time-consuming and results are not guaranteed.
Additionally, the platform allows companies to choose custom workspace URLs , making it impossible to see which organization the credentials for sale belong to

Slack is more secure than Hangouts or Microsoft Teams
For now, Slack channels, despite being associated with corporate environments, are probably more secure than solutions like Google Hangouts or Microsoft Teams.
account compromise Google or Microsoft gives attackers access to an entire suite of corporate applications, including all of their information. On the other hand, Slack credentials typically provide access to a few sensitive files (shared in conversations) and a lot of memes and GIFs.
However, according to KELA, things are definitely going to change. The Twitter hack has brought more attention to Slack.
