Your Zoom account might be for sale on the dark web

Zoom
(Image credit: Shutterestock)

Thousands of Zoom accounts are being put up for sale online, new research has revealed.

An investigation by security firm Cyble found that more than 500,000 Zoom accounts are up for sale on the dark web and notorious hacker forums, raising more questions over the safety of the popular video conferencing app 

Cyble found that Zoom accounts are often sold for less than a penny each, with some even given away for free to hackers looking to test out so-called 'Zoombombing' attacks.

Dashlane Password Manager, now with a free VPN
Dashlane Premium

Make careless data decisions history with our dark web monitoring and alerts. Get Dashlane for seamless, private 'interneting' with 2FA (two-factor authentication) by default. Your privacy matters to us‎ so that’s why there's no limit on devices or passwords stored or shared.

Zoom dark web

"It is common for web services that serve consumers to be targeted by this type of activity, which typically involves bad actors testing large numbers of already compromised credentials from other platforms to see if users have reused them elsewhere," a Zoom spokesperson told TechRadar Pro.

"This kind of attack generally does not affect our large enterprise customers that use their own single sign-on systems. We have already hired multiple intelligence firms to find these password dumps and the tools used to create them, as well as a firm that has shut down thousands of websites attempting to trick users into downloading malware or giving up their credentials."

"We continue to investigate, are locking accounts we have found to be compromised, asking users to change their passwords to something more secure, and are looking at implementing additional technology solutions to bolster our efforts.”

Zoom has seen a huge level of scrutiny in recent weeks as its user base has soared due to the rise of working from home during the coronavirus outbreak.

The company has faced severe criticism after reports surfaced of traffic being routed through China. It has also been slammed for a lack of proper security and encryption measures and other privacy-related issues such as hackers being able to eavesdrop into calls, records of meetings available publicly on the internet, and uninvited attendees able to hijack calls.

Zoom announced earlier this week that it has appointed former Facebook security chief Alex Stamos as an adviser as safety and privacy concerns, and has also halted development of software updates to focus solely on safeguarding its service.

Among the other institutions to have blocked the use of Zoom so far are the German Foreign Ministry and the entire Taiwanese government.

  • The best online collaboration tools in 2020

Via Bleeping Computer

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.