Desk live·
ForensicPost
Breaches/Verification/File 22-0804

Slack Sent Hashed Passwords to Workspace Members for Five Years

Creating or revoking a Slack invite link transmitted the acting user’s hashed password to other members of the workspace. It did that from April 2017 until July 2022, when an outside researcher noticed and Slack fixed it the same day.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetSlack
ActorUnattributed
D. Kennedy10 min readConfidence: high3 sources reviewed

On 4 August 2022 Slack notified approximately 0.5% of its users that it had reset their passwords. A bug meant that when a user created or revoked a Shared Invite Link for their workspace, a hashed version of that user’s password was transmitted to other workspace members.

The behaviour is reported to have existed from 17 April 2017 to 17 July 2022. The hash was salted and was not visible in any Slack client — retrieving it required actively monitoring encrypted network traffic from Slack’s servers. An independent researcher disclosed it on 17 July 2022 and Slack released a fix the same day. The company said it had no reason to believe plaintext passwords were obtained.

The Same-Day Fix Is The Good Part

Disclosed and fixed on 17 July, users notified on 4 August. Against the intervals this corpus routinely records — 289 days at 26-0721b, six and a half months at 22-0617 — that is exemplary and the desk says so plainly.

We noted at 22-0721 that a fast fix does not recall what already left. Here it very nearly does, because the exposure was continuous rather than a one-off dump: closing it stopped the behaviour for everyone from that day, and the population who could have collected anything was limited to people already inside a workspace with a packet capture running.

Five Years And Three Months

The duration is the finding, not the severity. The desk grades this SEV 2 — salted hashes, no plaintext, an awkward observation position and no evidence of exploitation.

It ran for five years and three months inside a product used by a very large number of organisations, and it was found by somebody outside the company. We filed the same shape at 23-0512, where a misconfiguration was open for nine and a half years and an internal audit found it, and at 22-0630. Duration and severity are independent axes, and only one of them gets published as a headline.

What A Salted Hash Is Worth

Slack was right to note the salting, and the desk carries that. Salting defeats precomputed tables; it does not defeat a determined attempt against a single, valuable, known target.

We have recorded the same distinction at 22-1222, where an exfiltrated vault remained attackable indefinitely against whatever compute an attacker cared to spend. A hash that has left the building is a cost problem for the attacker, not a barrier, and the relevant question is always whose password it is.

How we reported this

Compiled from Slack’s own notice and contemporaneous reporting, listed below. The researcher is not named here. No count of affected users in absolute terms was published and none is asserted. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Notice about Slack password resetsSlack
  2. Slack resets passwords after exposing hashes in invitation linksBleepingComputer
  3. Slack resets passwords en masse after invite link vulnerabilityCybersecurity Dive
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary