Zoombombing: Harmless or dangerous?

Last updated:
21.04.2021
Due to the COVID-19 pandemic, the video conferencing tool Zoom gained more than 150 million new users almost overnight. Internet trolls looking to exploit the situation were quick to act, leading to the rise of what is known as "Zoombombing."
Zoombombing: Harmless or dangerous?
Key Takeaways
  • Zoombombing disrupts meetings when unauthorized individuals gain access via guessed or publicly shared meeting IDs.
  • Zoombombing content ranges from harmless pranks to criminal acts, such as the display of racist or pornographic material.
  • Zoom has implemented security measures such as waiting rooms, password protection, and restricted screen sharing.
  • Conference rooms can be locked to prevent uninvited guests from joining; hosts have full control.
  • Zoom recommends using random meeting IDs and the webinar feature for large, public meetings.

According to Zoom, about 10 million people used their video conferencing tool every day in December 2019. By March 2020, that number had climbed to an incredible 200 million meeting participants per day. Furthermore, approximately 90,000 schools across 20 countries reportedly turned to Zoom for online classes. This surge in popularity not only brought several data privacy gaps to light, but is also largely responsible for the phenomenon known as Zoombombing. Zoombombing describes any incident where internet trolls join ongoing Zoom meetings to disrupt them, either by guessing Zoom meeting IDs or by following links that were intentionally or accidentally made public. Many of these incidents went beyond harmless pranks, with intruders posting racist or pornographic content, for example.

What exactly happened during these Zoombombing attacks?

Since it was possible until early April to guess a Zoom meeting ID simply by trying out sequences of numbers and join without any further access control, it was easy for outsiders to disrupt meetings. Once the phenomenon of Zoombombing became known, it took on a life of its own, as students began posting links to their virtual classrooms in the hope of disrupting lessons. But as is common on the internet, the methods used to disrupt meetings became increasingly extreme and, in some cases, even criminal.

The BBC reported, for example, on a case where members of a Jewish congregation in the UK were subjected to antisemitic abuse and images of Hitler were shared. In another incident, a troll confronted participants of a public Zoom call with disturbing pornographic scenes, as noted by the news portal TechCrunch in an article. Such attacks also occurred in Germany. According to Spiegel , some Zoombombers even played recordings of child sexual abuse. As a result, police are now investigating at least 16 cases, and in the USA, the FBI has also stepped in for particularly serious cases. Zoom states that it is working closely with law enforcement agencies.

What measures has Zoom taken against Zoombombing?

Zoom has since not only taken precautions to increase the security of its virtual conference rooms but has also strongly condemned the incidents related to Zoombombing. Furthermore, the company announced that a detailed report on data protection and data security would be released in the near future.

The company has implemented the following measures to combat Zoombombing:

  • Waiting rooms have been set up as an anteroom for conference rooms. Depending on the settings, this means that either all participants must first be admitted by the host, or only those not signed in with a corresponding ID must be approved before they can enter the meeting.
  • Zoom conferences can no longer be joined using just the link. Meeting rooms have also been secured with a password .
  • The default settings have been configured so that only the moderator can share content , unless they enable this option for other participants.
  • Conference rooms can now be locked, preventing any new participants from joining.
  • The moderator can disable video and audio for all participants at any time. switch off or interrupt.
  • Zoom recommends generating a random meeting ID for every conference instead of using a personal meeting ID that is reused repeatedly, in order to prevent the spread of conference links.
  • For hosts of large, public conferences, Zoom recommends using the webinar feature of the software. In webinars, the organizers of a Zoom call predetermine who is an attendee and who is a panelist or speaker. Only panelists can share content; other attendees can only watch.
  • On its website, Zoom posted a guide on how to remove participants from a meeting.
  • Zoom also asks all users to report the accounts behind Zoombombing attacks. Sign up.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in