How Zoom Bombing Exposed the Fragility of Remote Video Security

6

Karen Wilson’s March lecture was supposed to be a standard remote class. Instead, it became a chaotic intrusion. Ten minutes into her presentation, laughter erupted from the speakers. A voice cut through the audio, asking, “What class is this?”

When she asked who was there, two high school girls admitted they’d accidentally joined. They asked a few questions and left. Then came another intruder. Anonymous. Male. Talking loudly about marijuana.

Wilson didn’t know how to stop it. She was new to Zoom. She thought it was background noise. By the time she realized strangers could “drop into” her meeting, the damage was done. She had been Zoom bombed.

The Mechanics of the Intrusion

Zoom bombing is shorthand for strangers intruding on private meetings. Sometimes they just listen. Sometimes they disrupt with hate speech, threats, or pornography. Wilson got the mild version. Others get worse.

How does it happen? It’s not magic. It’s brute force.

Dan Desko, a cybersecurity expert at Schneider Downs, explains that it’s essentially enumerating URL combinations. To join a Zoom meeting, you use a link like https://zoom.us/j/55555523222. The numbers at the end are the Meeting ID. If a meeting has no password, anyone who guesses the ID gets in.

Desko tested this. In under a minute, he found a legitimate Meeting ID. The meeting wasn’t active then, but the ID existed. The flaw is simple: if you guess the right ID at the right time, you’re in. It’s like wiretapping. You just need luck and a little persistence.

Why Zoom Was Unprepared

Zoom exploded from 10 million daily users in December 2019 to 200 million in March. The company grew too fast. It wasn’t built for this scale.

“Zoom is primarily a corporate collaboration tool,” says David Tuffley, a lecturer at Griffith University. “Unlike social media platforms, it was not a service that had to engineer ways to manage the bad behavior of users – until now.”

The platform assumed users were colleagues. It didn’t assume they were targets. The sudden surge exposed basic security failures. Lack of encryption. Dark web accounts selling access. The FBI issued an advisory on March 30. Google banned Zoom on employee laptops. Some organizations just stopped using it.

The Encryption Gap

Security isn’t just about passwords. It’s about how data moves. Desko points to three pillars: confidentiality, integrity, availability.

Confidentiality failed first. The Citizen Lab at the University of Toronto found that Zoom’s encryption wasn’t as strong as claimed. The technology was crackable. It took months to fix. Even in August 2020, reports of Zoom bombing persisted.

Integrity is harder to pin down. As Zoom expanded, it used servers in China with Chinese employees. That raised eyebrows. Concerns about confidentiality grew louder. The U.S. Senate asked members to avoid Zoom. The Pentagon followed on April 10.

What This Means for Users

You can’t rely on the platform to protect you. You have to configure it.

Meetings without passwords are open invitations. Guessing IDs is easy if the range is small. The solution isn’t complex. It’s discipline.

Use waiting rooms. Require passwords. Disable “Join Before Host.” Check your privacy settings. Zoom gives you these tools. Most people don’t use them.

Why? Because it’s easy to share a link. Because you trust the people on the other end. Because you’re busy.

But trust isn’t security. Luck isn’t a strategy.

The next time you join a meeting, check the URL. Look for the password field. Mute yourself. Assume you’re being watched. It’s not paranoia. It’s basic hygiene.

The internet doesn’t care if you’re a professor. It doesn’t care if you’re a CEO. It only cares if you left the door unlocked.

Zoom hasn’t fixed everything. The servers are still global. The encryption is still evolving. The intruders are still guessing.

You’re still vulnerable. Are you watching?

Securing Your Virtual Space

The landscape has shifted. Zoom no longer leaves its doors wide open by default. Recognizing the chaos of “Zoom bombing,” the platform now enforces stricter protocols right out of the box. Every new meeting requires a password. The waiting room is active by default, acting as a bouncer that screens attendees before they slip into the main event. And if you were relying on the meeting ID displayed in the title bar to share access, that’s gone too. The ID is hidden, making it significantly harder for bad actors to guess or find your link.

Desko sees this as a necessary evolution. Keeping the meeting ID private stops people from linking a specific session to your identity or organization. It’s a defensive layer. He points to Boris Johnson as a cautionary tale. When the former UK Prime Minister tweeted a screenshot containing his meeting ID back in March, he didn’t just share a number; he shared an address. Even if the Bat Cave is secure, revealing the location makes it a target. The password becomes the only real barrier.

For those serious about security, automation isn’t enough. You should change your meeting ID and password for every single call. Zoom allows you to generate a new ID automatically, but you can also set a custom password. The onus is on you to verify these settings.

If you have recurring meetings set up under old defaults, they might still be vulnerable. You have to go back into the settings and update them. It’s a quick fix, but it’s easy to forget.

Beyond passwords, control the room. Restrict screen sharing to the host only. Mute participants, leaving only the speaker unmuted. Once everyone is in, lock the meeting. This prevents break-ins from people who might have stumbled upon an old link. And absolutely do not post public links to your meetings on social media or public forums. An open link is an invitation to the wrong crowd.

The Broader Security Reality

Zoom has taken a massive hit for its security shortcomings during the pandemic. It’s the elephant in the room. But don’t assume other platforms are cleaner. Skype, Webex, Google Hangouts—they all have vulnerabilities. No conferencing tool is immune. The privacy of your online meetings isn’t guaranteed by the software alone; it’s guaranteed by how you configure it. Apply the same rigor you’d use for Zoom to every other virtual space you inhabit.

Zoom Bombing FAQ

Is Zoom bombing a crime?
Yes. In an April 2020 press release, the U.S. District Attorney’s office clarified that perpetrators can face serious charges. These include disrupting a public meeting, computer intrusion, using a computer to commit a crime, hate crimes, fraud, or transmitting threatening communications. The penalties are severe: fines and imprisonment are on the table.

How do you stop Zoom bombing?
The waiting room is your first line of defense. It prevents participants from joining unless the host explicitly admits them. Beyond that, restrict screen sharing to the host. Mute all microphones except for the active speaker. Lock the meeting once all intended attendees have joined. These tools are available directly on the Zoom toolbar.

What is Zoom bombing?
It’s the act of uninvited guests disrupting an online Zoom meeting. Internet trolls join specifically to bombard other attendees with distracting, offensive, or disturbing content. It’s digital vandalism.

How do Zoom bombs work?
Sometimes the intruder just listens in, staying silent and unseen. In other cases, they crash the meeting with explicit or threatening behavior. The method varies, but the intent is disruption.

Is it legal to Zoom bomb a class?
No. The U.S. Department of Justice has explicitly warned that Zoom bombing is illegal. Depending on the behavior of the uninvited guest, they can be charged with state and federal crimes. The act itself is not protected speech; it’s a criminal intrusion.