Skip to main content

Slack gets hacked, turns on two-factor authentication

slack search artificial intelligence typing
Image used with permission by copyright holder
Slack, the popular communication tool aimed at businesses and teams, has reported that it was hacked for four days last month. The unauthorized access exposed user account information and passwords, though the company doesn’t believe these passwords were decrypted by the hackers, and no financial payment information was accessed.

“Since the compromised system was first discovered, we have been working 24 hours a day to methodically examine, rebuild and test each component of our system to ensure it is safe,” writes Slack’s Anne Toth on the company blog. “We are collaborating with outside experts to cross-check assumptions and ensure that we are meticulous in our approach. In addition we have notified law enforcement of this illegal intrusion.”

In response to the incident, Slack is rolling out two-factor authentication. As with other services that use the procedure, such as Gmail, Facebook, and Dropbox, users will now have to verify their identities with a mobile code as well as a password. Slack is also adding the ability for organizations to reset the passwords for their entire team at once.

If your company uses Slack, you may well have seen a password reset email appear in your inbox, but if not it’s still a good idea to change your password anyway. Chat logs weren’t accessed during the hack, so your previous communications with your colleagues should be safe. In addition, Slack is directly contacting a small number of users where “suspicious activity” was detected on their accounts.

The fledgling startup currently boasts 500,000 active users and 60,000 clients, including Apple, Google, and Amazon. The most recent round of funding saw the company valued at $1.2 billion, though there are reports that this valuation will rise during the next funding cycle.

Editors' Recommendations

David Nield
Dave is a freelance journalist from Manchester in the north-west of England. He's been writing about technology since the…
Elon Musk’s Starlink satellites hacked by $25 homemade device
A Starlink dish next to an RV.

A $25 hacking tool that can seemingly breach Starlink’s internet terminals has been revealed by a security researcher.

As reported by Wired and Gizmodo, Lennert Wouters, who works at Belgian university KU Leuven, showcased how to infiltrate the satellite dishes at the Black Hat Security Conference.

Read more
Hacking-as-a-service lets hackers steal your data for just $10
A depiction of a hacker breaking into a system via the use of code.

A new (and cheap) service that offers hackers a straightforward method to set up a base where they manage and perform their cyber crimes has been discovered -- and it’s gaining traction.

As reported by Bleeping Computer, security researchers unearthed a program called Dark Utilities, effectively providing a command and control (C2) center.

Read more
Destructive hacking group REvil could be back from the dead
Person typing on a computer keyboard.

There was a period in 2021 when the computing world was gripped by fear of a dizzyingly effective hacking group fittingly named REvil -- until its website was seized by the FBI and its members arrested by Russia’s security services, that is. Yet like a malevolent curse that just can’t be dispelled, it now seems the group’s websites are back online. Has the group returned to spread discord and wreak havoc once again?

In case you missed them the first time around, REvil came to global attention by hacking into various high-profile targets, pilfering secret documents, then threatening their release unless a ransom was paid. In a notable case, the group stole and published files from Apple supplier Quanta Computer, including some that spilled the beans on unreleased product designs.

Read more