As Zoomconfronts numerous security issues amid a spike in use of the service during the coronavirus pandemic,Jin Seo yet another problem for the video conferencing platform has entered the stage, thanks to the dark web.
Cybersecurity firm Sixgill recently discovered a collection of 352 Zoom accounts that had been compromised. The accounts were shared by a user on a popular dark web forum; information included each account’s connected email address, password, meeting ID, host key, and host name.
The stolen credentials were even labeled by type of Zoom account, meaning some of the stolen information included users paying for a higher-tier service plan.
“In comments on this post, several actors thanked him for the post, and one revealed intentions to troll the meetings,” said Dov Lerner, security research lead at Sixgill, in a statement provided to Mashable.
But online trolling isn't the only thing people could do with the information shared from these Zoom accounts.
“The accounts could certainly be used to troll the owner of the account or those who are joining the owner's calls, but these credentials could also be used for corporate or personal eavesdropping, identity theft, and other nefarious actions,” Lerner explained. “There's a number of ways a malicious actor could use these stolen accounts.”
This is especially concerning when looking at who the accounts belong to. According to Sixgill, while its researchers found that most of the 352 accounts were personal, some belonged to educational institutions and small businesses. One of the accounts was that of a major U.S. healthcare provider.
So, what is the "dark web" where these accounts were posted? In the simplest terms, the dark web encompasses websites, forums, and other online destinations that require a special web browser called Tor to access. You cannot visit these sites by just typing a URL into Google Chrome or Firefox. They aren’t visible to search engines — the dark isn’t discoverable when searching for them on Google.
The collection was found by Sixgill on April 1, as criticism was being leveled at Zoom for its securityand privacy practices. While the video teleconferencing company has blown up in popularity during the coronavirus pandemic, the newfound success has also brought to light issues with the service.
Security experts have noted how the service can be used by employers to effectively spyon their employees at home. The application was discovered to be unnecessarily providing user datato Facebook, as well as mining LinkedIn to unmaskanonymous users without their knowledge. A bug was uncoveredthat allowed hackers to steal your Windows passwords through Zoom.
Security issues became so prevalent that a new colloquialism, “Zoom-bombing,” was coined to specifically define the act of finding a meeting ID and crashing a Zoom teleconference. The accounts discovered by Sixgill included meeting IDs, which means all those users could be targeted by this act specifically.
Things became so bad that last week, Zoom’s CEO Eric Yuan apologized for the issues and announcedthe company was going to focus on fixing its security and privacy bugs over the next 90 days.
One thing Zoom should work on in these coming months: figuring out how a malicious actor got their hands on account credentials belonging to 352 of its users.
Topics Cybersecurity Privacy COVID-19
Apple vs. Qualcomm: Everything you need to knowRemember when Trump hated Obama? Here's a refresherCreating Captain Marvel in 'Avengers: Endgame' was a group effortNot my president: Powerful images show anti3 ways to combat climate change according to young activistsSamsung Galaxy Fold handsPeople are burning their sneakers over New Balance's perceived Donald Trump endorsementFacebook social network services all go down in a worldwide outageThis moving fan story about George R.R. Martin will make you tear upThe Mountain from 'Game of Thrones' posts extremely hype'Game of Thrones' Season 8 answers the question of Ed Sheeran's fatePaul McCartney gives us all the ultimate #MannequinChallengeSam Tarly was the MVP of 'Game of Thrones' Season 8 premiereSummer movie preview 2019: 6 comedies worth checking outPowerful Mannequin Challenge video highlights the Black Lives Matter movementPaul McCartney gives us all the ultimate #MannequinChallengeThe top Twitter jokes of 'Game of Thrones' Season 8 premierePeople of America aren't buying that Obama and Trump meeting'Game of Thrones' season 8 must deliver an Arya vs. Cersei showdownPeople are burning their sneakers over New Balance's perceived Donald Trump endorsement Women deserve more credit. For proof, just look at #ThanksForTyping. 3 podcasts that will help millennials take over the world Sean Spicer: Trump empowers women. World: You live under a rock, bro? Jennifer Lawrence, Russian spy who uses sex as a weapon? Just try to resist 'Red Sparrow' You're screwed if you want to repair the new iPad North Carolina votes to replace one anti An exhaustive breakdown of how the new 'It' trailer compares to the original Netflix teases a weird live show and even if it's a prank, it still looks insanely watchable These glowing images of the Southern Lights are too beautiful for words 'Street Fighter V' community is on a mission to prove just how much Akuma sucks Boss teacher pranks his fourth Teen babysitter transforms a normal night in into a mermaid party extravaganza Trump's tweet about women just made the internet's head explode Trans people celebrate visibility and identity in poignant new video Most of Square's small business loans are going to women Why this penis is on a subway seat, making people uncomfortable Samsung totally knew it put the S8’s fingerprint sensor in a terrible spot Lyft made Mono, a working wearable, to hail rides for April Fools' Day Nothing to see here, just an alligator in a furniture store The original 'Frozen' ending was terrible
2.0642s , 10133.171875 kb
Copyright © 2025 Powered by 【Jin Seo】,Exquisite Information Network