Comment-based phishing uses collaboration comments and notification emails as the delivery path for malicious links. Instead of placing a URL directly in the email body, attackers embed it in a document comment or preview so the message inherits trust from the platform and can evade simpler email inspection rules.
What comment-based phishing is really exploiting
Comment-based phishing is less about the message body and more about trust transfer. The attacker leverages a collaboration platform’s own comment, preview, or notification workflow so the link looks like it came from a legitimate workspace rather than a plainly suspicious email.
That matters because many users and controls treat internal comments, document alerts, and shared-file notifications as lower risk than unsolicited external mail. The tactic succeeds when the platform context makes the malicious link feel routine, familiar, and time-sensitive.
It also creates ambiguity for defenders, since the visible email may contain little or no malicious content while the real payload sits inside the linked object or comment thread. Similar credential and token abuse patterns appear in CoPhish OAuth Token Theft via Copilot Studio, where the platform’s trust envelope becomes part of the delivery path.
How the delivery path changes detection
Traditional email filters and user-awareness checks often focus on the message body, sender domain, and obvious URL patterns. Comment-based phishing shifts the suspicious element into a place that may be scanned less deeply, such as a document annotation, shared preview, or collaboration notification.
This means the observable risk is not just a bad link, but a trusted platform forwarding an untrusted destination. Defenders need to consider whether the link inherits trust from the collaboration system, whether previews obscure the final destination, and whether the notification channel itself is being abused as a delivery mechanism.
Where the attack path involves identity-bearing artefacts such as login prompts or stolen session material, the same pattern can spill into account compromise and downstream access abuse. That is one reason phishing-centric credential theft cases like Poland Military Breach remain useful reference points for understanding how social engineering becomes operational compromise.
Why it matters for trust, access, and user behaviour
Comment-based phishing is effective because it exploits ordinary collaboration habits, not just technical flaws. Users are conditioned to click comments to resolve tasks, review files, approve edits, or respond quickly to internal requests, which makes the delivery path feel legitimate even when the destination is hostile.
The security implication is that trust has shifted from sender reputation to platform provenance. A secure email gateway alone will not fully solve the problem if the platform can generate trusted-looking notifications that point to attacker-controlled content or to a compromised collaborator account.
Cases where social engineering yields API keys, tokens, or customer data show the same downstream pattern of trust abuse, including MailChimp Breach, which illustrates how a seemingly ordinary interaction path can expose broader organisational assets.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS 9 — Email and Web Browser Protections | Covers web-link abuse delivered through notification and comment workflows. |
| CIS 14 — Security Awareness and Skills Training | Comment-based phishing relies on user trust in platform notifications and shared content. | |
| Recommendation — Filter and restrict risky collaboration links before users can reach malicious destinations. Train users to verify collaboration links inside the originating workspace before clicking. | ||
| NIST CSF 2.0 | PR.AT — Awareness and Training | Supports user recognition of trusted-channel phishing and social engineering. |
| PR.DS — Data Security | Protects sensitive data when phishing through comments leads to credential or content exposure. | |
| Recommendation — Teach users how collaboration comments can be weaponized to deliver phishing links. Limit sensitive data exposure in shared documents and notification surfaces. | ||
| MITRE ATT&CK | T1566 — Phishing | Comment-based phishing is a phishing delivery variant using trusted collaboration context. |
| Recommendation — Map observed comment-delivery abuse to T1566 and hunt for related social-engineering activity. | ||
Practitioner guidance
Why practitioners should care: Comment-based phishing is a delivery technique that sits between email security, collaboration security, and user trust, so ownership often gets missed if each team assumes another layer will catch it. Treat comment and notification channels as part of the phishing attack surface, not as benign internal plumbing.
What to watch for: Unexpected comments that create urgency, notification emails that link to shared documents or previews, and comment threads that lead users away from the expected workspace are all high-signal patterns. The key question is whether the platform context is being used to suppress suspicion.
Practitioner takeaway: Defences work best when they inspect the full collaboration path, not just the email envelope, because the attacker is exploiting trust in the platform as much as the link itself.
Risk and Threat Considerations
Comment-based phishing raises material exposure because it can bypass simplistic email controls and abuse a trusted collaboration channel to deliver malicious links. The result is a higher chance of credential theft, malware delivery, or session hijack when users trust the platform context more than the destination.
Failure mechanism: The attacker places the payload inside a comment, preview, or notification flow that users and tools treat as low risk, then relies on inherited trust to drive clicks before the destination is evaluated.
Impact: The likely outcome is account compromise, unauthorized access, or a broader phishing cascade through shared workspaces and notification channels, especially where one compromised collaboration account can reach many recipients.