Skip to main content

Private Slack channel changed to public

ID:slack_private_channel_made_public
Data type:Slack
Severity:
Informational
MITRE ATT&CK:TA0005:T1562.001

Description

AlphaSOC detected that a private Slack channel was changed to public. This modification affects file visibility and access controls within the organization. Converting private channels to public exposes previously restricted conversations and files to all workspace members.

Impact

The privacy change exposes sensitive information, internal communications, and shared files to unauthorized users. Files shared in the converted channel remain public even if the channel returns to private status. This exposure creates risks of data exfiltration, intellectual property disclosure, and potential regulatory compliance violations.

Severity

SeverityCondition
Informational
Private Slack channel changed to public

Investigation and Remediation

Identify the user who changed the channel privacy settings through Slack audit logs. Review the channel content and shared files to assess exposure of sensitive information. Document all exposed data and affected users for incident reporting. If the change was unauthorized, return the channel to private status immediately. Revoke any file sharing links that may have been exposed. Conduct a review of Slack administrative permissions to prevent unauthorized changes.