Security is always a matter of cost vs. benefit, i.e. you need to weigh the cost of the risk (likelihood * impact) with the benefit of the action.
For example, I have shared credentials on Slack before, but that's because said credentials were for a non-critical system, and if hackers somehow a) hacked Slack and b) identified the information I shared and used it, the only thing they would get their hands on would be a curated collection of cat pictures with funny captions (and I don't re-use passwords).
Therefore, blanket rules like "don't share credentials on Slack" tend to miss the point. Obviously, don't share your bank account info on there. But you can totally talk about otherwise sensitive stuff if the risk profile is sufficiently negligible.