Skip to content
KnowledgeCity

By KnowledgeCity

Phishing Tests for Crews Who Live in Slack and Teams, Not the Inbox

7 min read

Construction crew checking messages on a phone at a site office

Key Takeaways

  • Crews run coordination, drawings and subcontractor traffic through chat, so an inbox-only test measures a channel many of them open once a day
  • Microsoft has documented phishing delivered over Teams by the Storm-0324 group
  • Verizon's 2026 report puts click rates 40% higher on mobile, which is where your crews read chat
  • Proofpoint measured an average resilience factor of 2.0 in 2023, up from 1.7
  • Run the same campaign in email, Slack and Teams, then compare the click rate in each

Your crews do not run the workday from an inbox. Those crews assign tasks in Teams, share drawings in Slack, and answer RFIs in a project channel long before anyone opens email. For those crews the inbox handles formal correspondence and very little else.

That thin slice of correspondence is where your phishing simulation software probably runs. A crew member who would click a link in a Teams message from an apparent supervisor never shows up in that software's results. The number you report to your board therefore describes 1 channel out of the 3 your crews use.

Why Crews Are Not Inbox-First Workers

Chat replaced email on site for a practical reason. Field crews are rarely at a desk, and a supervisor who needs an ironworker on the fourth floor gets an answer from a Teams message far sooner than from an email. Mobile apps finished the job, and Slack and Teams now carry the working day's real traffic.

Verizon's 2026 Data Breach Investigations Report gives that shift a number. Click rates run 40% higher on mobile devices, which the report calls the new favorite target, as attackers move toward mobile phishing. Your own crews read chat on a phone all day, which places them inside that 40%.

An inbox-only simulation therefore understates that mobile exposure by design. It captures 1 slice of the attack surface and reports the slice as the whole. The other 2 channels go untested, so that slice never reaches a number anybody reviews.

WHERE YOUR CREWS READ ALL DAY 40% HIGHER mobile click rates, Verizon 2026 DBIR 2.0 resilience factor in 2023, up from 1.7 SINCE 2023 Teams phishing documented by Microsoft 1 OF 3 channels an inbox-only test covers

Where the Attacks Land

Attackers followed that traffic into chat some years ago, and the record of it is public. Microsoft's threat intelligence has documented phishing campaigns delivered through Teams since 2023, with the Storm-0324 group sending external contact requests that carry malicious SharePoint-hosted files. Microsoft's own wording is that the group most likely relies on a public tool called TeamsPhisher.

Slack gives an attacker the same opening as Teams, with none of the SharePoint machinery. Such an opening usually appears as a message from a general contractor or a subcontractor contact, asking for a login to a document-sharing platform and letting the channel do the persuading. Crews click shared links in Slack all day, and that habit is the one email training spent years unpicking.

Years of unpicking that habit in the inbox does not transfer to chat at all. Email clients show sender addresses and routing detail, and chat shows a familiar display name in a fast-moving thread where a quick reply is the norm. A message attributed to a known integration therefore reads as credible in that thread, in a way the same message never would in Outlook.

What a Test Has to Cover

A simulation that matches your attack surface runs in all 3 channels at once and scores each one separately. The 3 campaigns below take a morning to set up and can reuse the pretexts you already have:

  • Run the email campaign you already run, and keep its schedule unchanged
  • Add a Slack campaign built as an external contractor sharing a document link
  • Add a Teams campaign built as an IT contact asking for account verification
  • Record the click rate and the report rate per channel, never blended
  • Compare the channels before you decide where the next training spend goes

That last line is the one that changes decisions you make. If your Slack click rate runs above your email click rate, the data says so before an attacker finds the same gap. Learning about that gap from a test costs you a campaign, and learning it from an incident costs a great deal more.

Report rates deserve the same per-channel treatment as click rates, for the same reason. Proofpoint measured an average resilience factor of 2.0 across organizations in 2023, up from 1.7 the year before, meaning users reported simulated messages at twice the rate they fell for them. A 2.0 measured in the inbox alone says nothing about the 2 channels it never covered.

Test the Channel Your Crews Live In

Run simulations across email, Slack and Teams, and see the click and report rate for each channel by team, department and role.

Explore KC Phishing

Reading the Numbers

Those per-channel rates tell you something a single blended figure cannot:

What the data shows

What it means for your next campaign

Slack click rate above email

Years of inbox training never reached the channel that carries the work

Teams report rate below email

Crews do not know the report button exists where they read most of their messages

Both chat rates near email

Your training transferred, so spend the next budget on depth

Field crews worse than office staff

The gap is device and context, not attitude

The fourth row is the one most often misread. The field crew in that row reads a message on a phone between tasks, under conditions a desk worker never meets, and those conditions are what the 40% mobile figure describes. The fix there is delivery and timing, and a sterner reminder changes nothing about either.

How KnowledgeCity Covers Every Channel

One record across all 3 channels is what makes that comparison possible at all. KC Phishing keeps that record, scheduling simulations across Outlook, Gmail, Slack and Teams from 1 campaign interface. That interface reports click and report rates by team, department and role, so all 3 channels appear in 1 dashboard.

The report button follows your crews into chat as well, which matters more than it sounds. It appears in all 4 platforms and routes to the same security queue, so a supervisor who meets a suspicious message in Teams uses the habit already built in email. Micro-training then fires straight after a click, in the channel where that click happened, while the crew member still remembers it.

Organizations running the test well connect it to what happens afterwards. Our work on phishing simulations and payment approvals covers the finance path a stolen credential opens next. Our piece on shared logins and attribution covers what happens when several people use 1 account, and whoever runs construction and engineering training usually owns both.

Take your last campaign and check which of those channels it ran in. If the answer is email alone, your click rate describes a channel your crews open once a day. Adding 1 Slack campaign to the next run costs an afternoon, and it tells you whether that click rate was ever true.

Frequently Asked Questions

1. Why is an email-only phishing test a problem for construction crews?

Crews run coordination, drawings and subcontractor traffic through Slack and Teams, and many open email once a day. A test that runs only in the inbox measures the channel they use least. The click rate it produces describes the inbox alone.

2. Do phishing attacks really arrive through Slack and Teams?

Microsoft's threat intelligence has documented phishing campaigns delivered through Teams by the Storm-0324 group, using external contact requests that carry malicious SharePoint-hosted files. Microsoft states the group most likely relies on a public tool called TeamsPhisher. Slack presents the same opening through messages attributed to contractors or integrations.

3. Are mobile users more exposed?

Verizon's 2026 Data Breach Investigations Report puts click rates 40% higher on mobile devices and describes them as the new favorite target, with attackers shifting toward mobile phishing. Field crews read chat on a phone, which places them in that population.

4. What is a resilience factor?

It compares how often people report a simulated message against how often they fall for it. Proofpoint measured an average of 2.0 across organizations in 2023, up from 1.7 the year before. A ratio measured only in the inbox says nothing about the channels your crews use most.

5. Where should we start?

Run your existing email campaign unchanged, add a Slack campaign and a Teams campaign built on realistic pretexts, and score each channel separately. Compare the 3 rates before you decide where training goes next. The comparison is the point, not the individual number.

References

  1. Microsoft Security Blog. Malware distributor Storm-0324 facilitates ransomware access.
  2. Verizon. 2026 Data Breach Investigations Report.
  3. Proofpoint. 2024 State of the Phish.
  4. Federal Bureau of Investigation, Internet Crime Complaint Center. 2025 Internet Crime Report.
  5. Cybersecurity and Infrastructure Security Agency, NSA, FBI and MS-ISAC. Phishing Guidance: Stopping the Attack Cycle at Phase One.

Everything your workforce needs, on one platform.

A quick walkthrough tailored to your team — learning, compliance, skills, and performance in one place.