Hundreds of thousands of Zoom accounts are being sold or given away for free on the dark web and hacker forums, according to a new report by BleepingComputer.
Zoom has surged in popularity in recent weeks as the number of people working from home has increased, but concerns about the videoconferencing app's security have also made the headlines. However, the availability of Zoom accounts on the dark web does not appear to be a direct consequence of the app's failings.
Rather, the sale of the login details are said to be the result of "credential stuffing attacks," where hackers attempt to log in to Zoom using accounts leaked in older data breaches.
Successful logins are then collated into lists and sold on or offered for free to other hackers, with the intention of using them in zoom-bombing pranks or for malicious reasons.
The accounts are reportedly being shared via text sharing sites as lists of email addresses and password combinations. The accounts can include a victim's email address, password, personal meeting URL, and their HostKey.
Cybersecurity firm Cyble, which was able to purchase 530,000 Zoom credentials for less than a penny each at $0.0020 per account, said the Zoom accounts began appearing in the hacker community at the beginning of April, with hackers offering the accounts to build reputation.
The finding underscores the importance of using unique passwords for each website where an account is registered. Concerned users are encouraged to check if their email address has been leaked in data breaches using the Have I Been Pwned website or Cyble's AmIBreached data breach notification service, and change their Zoom password if used elsewhere.
Top Rated Comments
FaceTime has already become a proprietary eponym in the way that you make a xerox of a document or ask for a Kleenex after you sneeze. FaceTime has become even more popular during this time but people have to seek out alternatives when just one member of the call you want to place is an Android user.
1. Offer an Android FaceTime client without all the bells and whistles. Allow Android users to join in on a call. Limit it to just cameras. No Animoji or any of the fun stuff. It’ll make Android users want to get an iPhone.
2. Allow FaceTime to broadcast online with a link that anybody with the link can join. Allow the leader to control who, if anybody, can speak.
3. Optionally, Apple can also go after the work from home, corporate market by adding desktop sharing and whiteboard features.
Apple is missing a huge opportunity to make FaceTime mainstream.
As long as you haven’t reused it anywhere else, there is little chance that the generated password is leaked. Of course, it wouldn’t hurt to be on the safe side either.
For all it's perceived issues, Zoom has been relatively stable for us and significantly cheaper.
Citations please.
What does more secured mean? Does it mean, if you give your user and password to someone else, there is a webex 2fa?