In the Intelligence Community a secure chat room carries the same classification as the reporting discussed inside it. Access follows need-to-know rather than the org chart, and the circuits themselves are accredited and owned by the mission they serve. I spent nearly two decades in that world, and the working assumption was that if a conversation matters, someone hostile wants to hear it.
Many enterprises never adopted that assumption. Their collaboration platforms were chosen for speed and openness, provisioned like any other software subscription, and judged by adoption rates. That was a reasonable business decision made without anyone running the counterintelligence math, and adversaries have noticed.
The Adversary Is Reading the Response Channel
The clearest statement of the problem comes from government agencies rather than vendors. In an August 2025 joint advisory on the Chinese state-sponsored activity commonly referred to as Salt Typhoon, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and partner agencies from a dozen other nations warned that the actors frequently compromise mail servers and administrator accounts to watch for signs that their intrusion has been discovered. The agencies urged organizations to shield their threat hunting and incident response activity from that monitoring.
That guidance deserves more attention than it may have received. It means that the incident response bridge, the war room channel opened at two in the morning, and the thread where the security team debates containment timing are all collection targets. An organization that coordinates its response inside the same tenant the adversary already controls is briefing the opposing force on its own plan.
Metadata Is Intelligence
The same advisory explains why that data stolen from telecommunications providers and travel-sector networks can give Chinese intelligence services the ability to identify and track their targets’ communications and movements around the world. In February 2026, a senior FBI cyber official speaking at CyberTalks described Salt Typhoon’s operations as still ongoing across more than 80 countries, pairing broad access with indiscriminate collection.
Enterprise collaboration platforms generate that category of data continuously. Channel membership reveals deal teams and project structures while message timing reveals when a crisis begins and status icons reveal who is online. Microsoft’s threat intelligence team has documented open-source tools that enumerate teams, channel members, tenant settings, and user presence, which is the raw material for mapping an organization before a single phishing lure is sent. In classified environments, that pattern-of-life data was protected as carefully as the content itself, but many commercial deployments treat it as telemetry.
A Collection Target and an Access Path
Microsoft describes its collaboration platform, Microsoft Teams, as a high-value target for both criminal and state-sponsored actors. Evidence in support of that assessment includes reporting on the Russia-affiliated actor Microsoft tracks as Void Blizzard having accessed Microsoft Teams conversations through the web client, though only in a small number of compromises. Post-compromise tooling can search every chat and channel a stolen account can reach and export the results.
While the state-actor cases are real they are not the bulk of the activity, since much of the volume comes from criminal operators. In a campaign Microsoft documented in October 2025, attackers operating from outside tenants impersonated internal help desk staff, talked employees into granting remote sessions, and then pushed laterally toward domain controllers and certificate authorities. The operators sometimes shifted instructions to voice calls so that malicious commands never entered the chat record. Those actors clearly understand that chat is evidence.
State services are walking the same path. Rapid7 assessed with moderate confidence that an early 2026 intrusion branded as a Chaos ransomware attack was the work of MuddyWater, a group affiliated with Iran’s Ministry of Intelligence and Security. The operators gained entry through external Microsoft Teams chats and screen-sharing sessions, harvesting credentials and manipulating multifactor authentication along the way. In Rapid7’s assessment, the extortion theater likely served to pull defenders toward immediate impact while the persistence mechanisms went unnoticed. The adversary used the collaboration platform to get in and then shaped the incident response to stay in. Other researchers who have analyzed similar Teams-based “Chaos” activity have not tied it to MuddyWater, so this attribution should be read as an assessment rather than a settled finding.
Blast radius is the other half of the problem. In November 2025, Nikkei disclosed that malware on a single employee’s personal computer leaked Slack credentials that may have exposed names, email addresses, and chat histories for 17,368 people. The root cause was compromised credentials, not a flaw in the platform. One infected machine put a large body of institutional conversation at risk, which is a compartmentation failure that could enable follow-on attacks.
The Intelligence Community is Not Immune
Holding up classified environments as a model requires honesty about where they fail. In August 2026, a former Defense Intelligence Agency (DIA) information technology specialist who worked in the agency’s Insider Threat Division pleaded guilty to passing classified information to someone he believed represented a foreign government. Over several weeks in 2025, he repeatedly transcribed classified material at his workstation and carried it out of the facility, at one point hidden in his clothing. According to the Justice Department, the case began when the FBI learned of his offer, and the recipient turned out to be an FBI agent. Sentencing is pending. In my view, the need-to-know principle governed that environment largely on paper. The breadth of material one insider could reach, and the ease of walking it out, are architectural questions that policy alone did not answer.
That case carries a direct lesson for commercial security leaders: Policies that rely on individual discipline will eventually meet an individual who lacks it, whether through grievance or through a convincing voice on an unexpected call. The controls must live in the system.
Protecting the Conversation
Applying Intelligence Community discipline to enterprise collaboration does not require classification markings or cleared personnel. It just requires treating the collaboration layer as mission infrastructure with channels functioning as compartments.
Membership in sensitive channels needs a named owner and a periodic review, with default visibility set to closed. External federation deserves the same scrutiny, and Microsoft’s own guidance recommends limiting external chat to explicitly allowed domains. Retention and search deserve a hard look as well, because years of searchable history turn one stolen credential into a strategic loss.
The joint advisory’s warning about adversaries monitoring defenders should drive a standing out-of-band channel for incident response that shares neither identity nor infrastructure with the production environment. Security teams should rehearse moving to that channel long before they need it so when things are happening for real they naturally make that shift without undue contemplation or effort.
Control of the infrastructure belongs in the same conversation as every other security decision. Organizations that host their collaboration platform inside their own boundary decide where the logs reside and which outside parties can ever reach the data. Mattermost supports that model through self-hosted deployments in private cloud, air-gapped, and sovereign environments. Self-hosting is one control among several, and it does not by itself stop credential theft, social engineering, or insider misuse. The principle holds regardless of platform, since whoever owns the infrastructure ultimately owns the conversation.
The people who protect secrets have always treated communication as an operational asset and assumed adversaries were collecting against it. Enterprises now hold conversations worth collecting, so their defenses should be built on the same assumption.