On 4 August 2022 Slack notified approximately 0.5% of its users that it had reset their passwords. A bug meant that when a user created or revoked a Shared Invite Link for their workspace, a hashed version of that user’s password was transmitted to other workspace members.
The behaviour is reported to have existed from 17 April 2017 to 17 July 2022. The hash was salted and was not visible in any Slack client — retrieving it required actively monitoring encrypted network traffic from Slack’s servers. An independent researcher disclosed it on 17 July 2022 and Slack released a fix the same day. The company said it had no reason to believe plaintext passwords were obtained.
The Same-Day Fix Is The Good Part
Disclosed and fixed on 17 July, users notified on 4 August. Against the intervals this corpus routinely records — 289 days at 26-0721b, six and a half months at 22-0617 — that is exemplary and the desk says so plainly.
We noted at 22-0721 that a fast fix does not recall what already left. Here it very nearly does, because the exposure was continuous rather than a one-off dump: closing it stopped the behaviour for everyone from that day, and the population who could have collected anything was limited to people already inside a workspace with a packet capture running.
Five Years And Three Months
The duration is the finding, not the severity. The desk grades this SEV 2 — salted hashes, no plaintext, an awkward observation position and no evidence of exploitation.
It ran for five years and three months inside a product used by a very large number of organisations, and it was found by somebody outside the company. We filed the same shape at 23-0512, where a misconfiguration was open for nine and a half years and an internal audit found it, and at 22-0630. Duration and severity are independent axes, and only one of them gets published as a headline.
What A Salted Hash Is Worth
Slack was right to note the salting, and the desk carries that. Salting defeats precomputed tables; it does not defeat a determined attempt against a single, valuable, known target.
We have recorded the same distinction at 22-1222, where an exfiltrated vault remained attackable indefinitely against whatever compute an attacker cared to spend. A hash that has left the building is a cost problem for the attacker, not a barrier, and the relevant question is always whose password it is.
Compiled from Slack’s own notice and contemporaneous reporting, listed below. The researcher is not named here. No count of affected users in absolute terms was published and none is asserted. Graded high. Corrections: corrections@forensicpost.com.