zoom phone

Video Conferencing Software Zoom Faces Scrutiny Over Hacks, Abusive Behavior During Meetings

The spread of “Zoombombing,” or hijacking a meeting room with abusive images or speech, has grown in scope as more Americans turn to teleconferencing for classroom instruction and workplace meetings.

As more Americans use video conferencing software to connect with coworkers, friends and family during the COVID-19 pandemic, one of the most popular platforms, Zoom, has faced several complaints from customers who have had their conferences “hijacked” by hackers.

The practice, also referred to as “Zoombombing,” has happened with several virtual classrooms and workplace meetings that did not have password protections for the meeting room and had their meeting room links available online.

The FBI’s Boston office issued a warning this week about the potential for hijacking after receiving several reports of “conferences being disrupted by pornographic and/or hate images and threatening language.”

One school in Massachusetts reported an incident where an unidentified individual dialed into the classroom, yelled a profanity and shared the teacher’s home address in the middle of the meeting. Another teacher reported that an unidentified individual appeared in their Zoom meeting room with visible swastika tattoos.

“As individuals continue the transition to online lessons and meetings, the FBI recommends exercising due diligence and caution in your cybersecurity effort,” the warning reads.

In a press statement, Zoom has said that it takes the security of its software seriously and that employees are “deeply upset” to hear about these types of attacks.

“For those hosting large, public group meetings, we strongly encourage hosts to review their settings and confirm that only the host can share their screen,” the company, which has faced criticism for cybersecurity issues in the past, said. “For those hosting private meetings, password protections are on by default and we recommend that users keep those protections on to prevent uninvited users from joining.”

The questions around Zoom’s cybersecurity practices and use of personal data have been escalated by Sen. Richard Blumenthal (D-Conn.). The senator sent a letter to Zoom CEO Eric Yuan on Tuesday to seek information on Zoom’s protections against security threats and “abuse” of its services.

“The millions of Americans now unexpectedly attending school, celebrating birthdays, seeking medical help, and sharing evening drinks with friends over Zoom during the Coronavirus pandemic should not have to add privacy and cybersecurity fears to their ever-growing list of worries,” Blumenthal wrote.

New York Attorney General Letitia James sent a similar letter this week. Blumenthal has requested answers to his questions, which include inquiries about Zoom’s collection of personal data, use of “end-to-end encryption,” and policies against abusive behavior, by April 14.

In the meantime, users can report incidents of Zoombombing to the company so staff can take “appropriate action,” the company said. Victims of teleconference hijacking or any cyber crime can report it to the FBI’s Internet Crime Complaint Center. The FBI offered other tips on preventing Zoombombing, including not sharing links to meeting rooms on unrestricted social media posts where trolls and hackers can find them.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Gaining a Competitive Edge

    Ask most companies about their future technology plans and the answers will most likely include AI. Then ask how they plan to deploy it, and that is where the responses may start to vary. Every company has unique surveillance requirements that are based on market focus, scale, scope, risk tolerance, geographic area and, of course, budget. Those factors all play a role in deciding how to configure a surveillance system, and how to effectively implement technologies like AI. Read Now

  • 6 Ways Security Awareness Training Empowers Human Risk Management

    Organizations are realizing that their greatest vulnerability often comes from within – their own people. Human error remains a significant factor in cybersecurity breaches, making it imperative for organizations to address human risk effectively. As a result, security awareness training (SAT) has emerged as a cornerstone in this endeavor because it offers a multifaceted approach to managing human risk. Read Now

  • The Stage is Set

    The security industry spans the entire globe, with manufacturers, developers and suppliers on every continent (well, almost—sorry, Antarctica). That means when regulations pop up in one area, they often have a ripple effect that impacts the entire supply chain. Recent data privacy regulations like GDPR in Europe and CPRA in California made waves when they first went into effect, forcing businesses to change the way they approach data collection and storage to continue operating in those markets. Even highly specific regulations like the U.S.’s National Defense Authorization Act (NDAA) can have international reverberations – and this growing volume of legislation has continued to affect global supply chains in a variety of different ways. Read Now

  • Access Control Technology

    As we move swiftly toward the end of 2024, the security industry is looking at the trends in play, what might be on the horizon, and how they will impact business opportunities and projections. Read Now

Featured Cybersecurity

Webinars

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3