Slack security crack: Its AI feature can breach your private conversations, according to report

You may not have even known Slack has AI features, but it does, and it might be a problem.
 By 
Alex Perry
 on 
Slack logo against purple background
Slack's built-in AI features could be a security risk. Credit: JOSH EDELSON/AFP via Getty Images

AI is encroaching into every app, and in some cases that could be a problem.

Take Slack, for example. The workplace instant messenger app has an optional suite of AI features you can pay extra for, but according to the security firm PromptArmor, it's full of potential holes. The feature exists to help create quick summaries of conversations, but per PromptArmor, it does so with access to private DMs, and can be tricked into phishing other users.

The technical nitty-gritty details are all in the PromptArmor blog post, but the problem here is essentially twofold. For starters, Slack recently updated its AI system to be able to scrape data from private user DMs and file uploads on purpose. Beyond that, using a technique called "prompt injection," PromptArmor proved you can use Slack AI to create malicious links that could potentially phish members of said Slack channel.


You May Also Like

Mashable has reached out to Slack for comment on this. Per PromptArmor's blog, the issue was raised to Slack ahead of the publication of its blog post. A spokesperson for Slack's parent company SalesForce told The Register that the problem has been addressed, but did not go into specifics.

"When we became aware of the report, we launched an investigation into the described scenario where, under very limited and specific circumstances, a malicious actor with an existing account in the same Slack workspace could phish users for sensitive data," the SalesForce spokesperson said. "We've deployed a patch to address the issue and have no evidence at this time of unauthorized access to customer data."

If nothing else, it's probably worth looking up the stated AI policies for every app that you use regularly.

journalist alex perry looking at a smartphone
Alex Perry
Tech Reporter

Alex Perry is a tech reporter at Mashable who primarily covers video games and consumer tech. Alex has spent most of the last decade reviewing games, smartphones, headphones, and laptops, and he doesn’t plan on stopping anytime soon. He is also a Pisces, a cat lover, and a Kansas City sports fan. Alex can be found on Bluesky at yelix.bsky.social.

Mashable Potato

Recommended For You
Claude apps: How Anthropic will integrate Slack, Canva, and more
Claude using Asana to manage tasks

Updating your security mindset: Keep your data private and your devices secure
By PCMag
Cyber Security


Panera Bread breach: ShinyHunters claims hack of 14 million customers' data
Panera Bread logo on storefront


Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.


NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!