zoombombing
{{short description|Unwanted intrusion into video conference calls}}
{{Use mdy dates|date=April 2020}}
File:Zoombombing.png portraying a Zoom meeting with an unwanted intrusion]]
Zoombombing or Zoom raiding{{cite news |first1=Taylor |last1=Lorenz |first2=Davey |last2=Alba |author-link2=Davey Alba |title='Zoombombing' Becomes a Dangerous Organized Effort |url=https://www.nytimes.com/2020/04/03/technology/zoom-harassment-abuse-racism-fbi-warning.html |access-date=4 April 2020 |work=The New York Times |date=3 April 2020 |language=en |quote="Zoombombing" or "Zoom raiding" by uninvited participants have become frequent |archive-date=December 7, 2021 |archive-url=https://web.archive.org/web/20211207104943/https://www.nytimes.com/2020/04/03/technology/zoom-harassment-abuse-racism-fbi-warning.html |url-status=live }} is the unwanted, disruptive intrusion, generally by Internet trolls, into a video-conference call. In a typical Zoombombing incident, a teleconferencing session is hijacked by the insertion of material that is lewd, obscene, or offensive in nature, typically resulting in the shutdown of the session or the removal of the troll. The term is especially associated with and is derived from, the name of the Zoom videoconferencing software program; however, it has also been used to refer to the phenomenon on other video conferencing platforms. The term became popularized in 2020 when the COVID-19 pandemic forced many people to stay at home, and videoconferencing came to be used on a large scale by businesses, schools, and social groups.
Zoombombing has caused significant issues in particular for schools, companies, and organizations worldwide. Such incidents have resulted in increased scrutiny on Zoom as well as restrictions on usage of the platform by educational, corporate, and governmental institutions globally. In response, Zoom, citing the sudden influx of new users due to the COVID-19 pandemic, took measures to increase security of its teleconferencing application. Incidents of Zoombombing have prompted law enforcement officers in various countries to investigate such cases and file criminal charges against those responsible.
Etymology
{{Wiktionary|Zoombombing}}
The term Zoombombing is a neologism derived from the teleconferencing application Zoom and influenced by the word photobombing.{{cite journal |last=Al-Salman |first=Saleh |last2=Haider |first2=Ahmad S. |title=COVID-19 trending neologisms and word formation processes in English |journal=Russian Journal of Linguistics |volume=25 |issue=1 |date=2021-12-15 |issn=2686-8024 |doi=10.22363/2687-0088-2021-25-1-24-42 |doi-access=free |pages=24–42}} The term had appeared in mid-March 2020 on technology and news websites.{{cite web |last=Constine |first=Josh |title=Beware of 'ZoomBombing': screensharing filth to video calls |website=TechCrunch |date=2020-03-18 |url=https://techcrunch.com/2020/03/17/zoombombing/ |access-date=2024-11-24}}{{cite web |last=Parsons |first=Jeff |title=What is Zoombombing and how can you stop it? |website=Metro |date=2020-03-24 |url=https://metro.co.uk/2020/03/24/zoombombing-can-stop-12448404/ |access-date=2024-11-24}}{{cite web |last1=Xia |first1=Roxanna |last2=Blume |first2=Howard |last3=Money |first3=Luke |title=USC, school districts getting 'Zoom-bombed' with racist taunts, porn as they transition to online meetings |work=Los Angeles Times |date=2020-03-25 |access-date=2020-04-11 |url=https://www.latimes.com/california/story/2020-03-25/zoombombing-usc-classes-interrupted-racist-remarks |archive-date=March 28, 2020 |archive-url=https://web.archive.org/web/20200328021910/https://www.latimes.com/california/story/2020-03-25/zoombombing-usc-classes-interrupted-racist-remarks |url-status=live }} Zoombombing has also been used in reference to similar incidents on other teleconferencing platforms, such as WebEx or Skype.{{cite web |last=Holmberg |first=Shannon |title=Zoombombing, Location Tracking, and Contact Tracing, Oh My! Data Privacy & Cybersecurity During the COVID-19 Pandemic |website=JD Supra |date=2020-04-20 |url=https://www.jdsupra.com/legalnews/zoombombing-location-tracking-and-13976/ |access-date=2020-05-19 |archive-date=April 30, 2020 |archive-url=https://web.archive.org/web/20200430035916/https://www.jdsupra.com/legalnews/zoombombing-location-tracking-and-13976/ |url-status=live }}
Methods
The increased use of Zoom during the COVID-19 pandemic as an alternative to face-to-face meetings resulted in widespread exposure to hackers and Internet trolls, who exploit and work around the application's security features.{{cite web |last=Marotti |first=Ally |title=Zoom video meetings are being interrupted by hackers spewing hate speech and showing porn. It's called 'Zoombombing.' Here's how to prevent it. |work=Chicago Tribune |date=2020-04-02 |access-date=2020-04-11 |url=https://www.chicagotribune.com/coronavirus/ct-coronavirus-zoombombing-20200401-wf2pvzqhbngitankuokvinvk2m-story.html |archive-date=June 22, 2021 |archive-url=https://web.archive.org/web/20210622042635/https://www.chicagotribune.com/coronavirus/ct-coronavirus-zoombombing-20200401-wf2pvzqhbngitankuokvinvk2m-story.html |url-status=live }} In various forums such as Discord and Reddit, efforts have been coordinated to disrupt Zoom sessions, while certain Twitter accounts advertise meeting IDs and passwords or meeting links (allowing users to instantly join a Zoom meeting instead of entering the credentials required to access a meeting) for sessions that were vulnerable to being joined without authorization.{{Cite web |last=Cimpanu |first=Catalin |date=April 2, 2020 |title=The internet is now rife with places where you can organize Zoom-bombing raids |url=https://www.zdnet.com/article/the-internet-is-now-rife-with-places-where-you-can-organize-zoom-bombing-raids/ |url-status=live |archive-url=https://web.archive.org/web/20200405044803/https://www.zdnet.com/article/the-internet-is-now-rife-with-places-where-you-can-organize-zoom-bombing-raids/ |archive-date=April 5, 2020 |access-date=2020-04-03 |website=ZDNet}} At educational institutions, some students were "actively asking strangers to Zoombomb or 'Zoom raid' their virtual classrooms to spice up their isolated lessons" and facilitating the raids by sharing passwords with the raiders.{{cite news |first=Audrey |last=Conklin |title='Zoombombing' is an inside job? Meeting codes shared on Twitter |url=https://www.foxbusiness.com/technology/zoombombing-codes-raids-twitter |website=Fox Business |access-date=2 April 2020 |date=2 April 2020 |archive-date=November 26, 2020 |archive-url=https://web.archive.org/web/20201126070433/https://www.foxbusiness.com/technology/zoombombing-codes-raids-twitter |url-status=live }} CNET pointed out that simple Google searches for URLs that include "Zoom.us" could bring up conferences that are not password protected, and that links within public pages can allow anyone to join.{{Cite web |url=https://www.cnet.com/how-to/zoombombing-what-it-is-and-how-you-can-prevent-it-in-zoom-video-chat/ |title=Zoombombing: What it is and how you can prevent it in Zoom video chat |last=Hodge |first=Rae |date=April 21, 2020 |website=CNET |url-status=live |archive-url=https://web.archive.org/web/20200421104004/https://www.cnet.com/how-to/4-zoom-security-settings-to-change-now-to-prevent-zoombombing/ |archive-date=April 21, 2020 }} Hackers and trolls also look for easy targets such as unprotected or underprotected "check-in" meetings in which organizations meet with their employers or clients remotely.{{cite web |last=Brazzano |first=Rebecca |title=Zoombombing, Sexting and Revenge Porn, Oh My! |work=Law.com |publisher=ALM |date=2020-06-10 |access-date=2020-06-16 |url=https://www.law.com/newyorklawjournal/2020/06/10/zoombombing-sexting-and-revenge-porn-oh-my/ |archive-date=March 5, 2022 |archive-url=https://web.archive.org/web/20220305000422/https://www.law.com/newyorklawjournal/2020/06/10/zoombombing-sexting-and-revenge-porn-oh-my/ |url-status=live }}
While a Zoom session is in progress, unfamiliar users show up and hijack the session by saying or showing things that are lewd, obscene, or racist in nature.{{cite web |last=Kan |first=Michael |date=April 2, 2020 |title=Were You Zoom-Bombed? Video of It May Now Be on YouTube, TikTok for All to See |url=https://www.pcmag.com/news/were-you-zoom-bombed-video-of-it-may-now-be-on-youtube-tiktok-for-all-to |access-date=15 October 2020 |website=PCMAG |language=en |archive-date=December 11, 2021 |archive-url=https://web.archive.org/web/20211211041212/https://www.pcmag.com/news/were-you-zoom-bombed-video-of-it-may-now-be-on-youtube-tiktok-for-all-to |url-status=live }}{{Cite news |last=Koebler |first=Jason |date=July 1, 2024 |title='Local Residents' Terrorizing City Council Meetings Were Actually Overseas, Feds Allege |url=https://www.404media.co/local-residents-terrorizing-city-council-meetings-were-actually-overseas-feds-allege/ |access-date=July 2, 2024 |work=404 Media}} The compromised Zoom session is then typically shut down by the host.{{cite web |last1=Xia |first1=Roxanna |last2=Blume |first2=Howard |last3=Money |first3=Luke |title=USC, school districts getting 'Zoom-bombed' with racist taunts, porn as they transition to online meetings |work=Los Angeles Times |date=2020-03-25 |access-date=2020-04-11 |url=https://www.latimes.com/california/story/2020-03-25/zoombombing-usc-classes-interrupted-racist-remarks |archive-date=March 28, 2020 |archive-url=https://web.archive.org/web/20200328021910/https://www.latimes.com/california/story/2020-03-25/zoombombing-usc-classes-interrupted-racist-remarks |url-status=live }} Many of those successful in disrupting sessions have posted video footage of those incidents to social media and video sharing platforms such as TikTok and YouTube.
While it is believed Zoombombing attacks are mainly orchestrated by external hackers and trolls, many are also orchestrated internally from within their respective organization or entity.{{cite web |last=Lu |first=Donna |title=Most Zoombombing is not done by external hackers – they're inside jobs |website=New Scientist |date=2020-09-30 |access-date=2020-10-11 |url=https://www.newscientist.com/article/2255550-most-zoombombing-is-not-done-by-external-hackers-theyre-inside-jobs/ |archive-date=October 8, 2020 |archive-url=https://web.archive.org/web/20201008070050/https://www.newscientist.com/article/2255550-most-zoombombing-is-not-done-by-external-hackers-theyre-inside-jobs/ |url-status=live }}{{subscription required}} Some view Zoombombing as a continuation of cyberbullying by teenagers, particularly after schools were shut down due to the pandemic.{{cite web |last=Dalbey |first=Beth |title='Zoom Bombing' Is A Pandemic Thing; It's Also A Bullying Thing |website=Patch |date=2020-09-17 |access-date=2020-10-11 |url=https://patch.com/us/across-america/zoom-bombing-pandemic-thing-it-s-also-bullying-thing |archive-date=October 3, 2020 |archive-url=https://web.archive.org/web/20201003040535/https://patch.com/us/across-america/zoom-bombing-pandemic-thing-it-s-also-bullying-thing |url-status=live }}
Responses
Zoombombings would frequently make the local news for how disruptive they are.
The trolling has caused a number of problems for schools and educators, with unwanted participants posting lewd content to interrupt learning sessions.{{Cite web |url=https://www.insidehighered.com/news/2020/03/26/zoombombers-disrupt-online-classes-racist-pornographic-content |title='Zoombombers' disrupt online classes with racist, pornographic content |last=Redden |first=Elizabeth |date=March 26, 2020 |website=Inside Higher Ed |access-date=2020-05-22 |archive-date=March 29, 2020 |archive-url=https://web.archive.org/web/20200329174620/https://www.insidehighered.com/news/2020/03/26/zoombombers-disrupt-online-classes-racist-pornographic-content |url-status=live }}{{Cite news |last=Anderson |first=Nick |date=2020-03-25 |title='Zoombombing' disrupts online classes at University of Southern California |newspaper=The Washington Post |url=https://www.washingtonpost.com/education/2020/03/25/zoombombing-disrupts-online-classes-university-southern-california/ |url-status=live |url-access=subscription |access-date=2020-05-22 |archive-url=https://web.archive.org/web/20200325190052/https://www.washingtonpost.com/education/2020/03/25/zoombombing-disrupts-online-classes-university-southern-california/ |archive-date=25 March 2020}} Some schools had to suspend using video conferencing altogether.{{Cite web |url=https://techcrunch.com/2020/03/26/norwegian-school-whereby/ |title=School quits video calls after naked man 'guessed' the meeting link |last=Whittaker |first=Zack |date=March 26, 2020 |website=TechCrunch |language=en-US |access-date=2020-03-28 }} The University of Southern California called Zoombombing a type of trolling and apologized for "vile" events that interrupted "lectures and learning."{{cite web |url=https://www.miamiherald.com/news/coronavirus/article241513761.html |title='Zoombombing' is the new way to troll online. Here's how to protect your video chat |last=Wolford |first=Brooke |date=2020-03-25 |website=Miami Herald |access-date=2020-03-30 |archive-date=June 13, 2020 |archive-url=https://web.archive.org/web/20200613080439/https://www.miamiherald.com/news/coronavirus/article241513761.html |url-status=live }} Zoombombing has prompted colleges and universities to publish guides and resources to educate and bring awareness to their students and staff about the phenomenon.{{cite web |last=McKenzie |first=Lindsay |title='Zoombies' Take Over Online Classrooms |publisher=Inside Higher Ed |date=2020-04-03 |access-date=2020-05-02 |url=https://www.insidehighered.com/news/2020/04/03/zoombombing-isn%E2%80%99t-going-away-and-it-could-get-worse |archive-date=May 1, 2020 |archive-url=https://web.archive.org/web/20200501053003/https://www.insidehighered.com/news/2020/04/03/zoombombing-isn%E2%80%99t-going-away-and-it-could-get-worse |url-status=live }} Zoombombing has left online lectures vulnerable to the intrusion of people looking to inflict harm. These crimes have brought attention not only to the lack of security on videoconferencing platforms, but also the lack in the universities. According to an article from The Guardian, the University of Warwick, in the midst of a rape-chat scandal, received criticisms for its weak cybersecurity.{{Cite news |last=Batty |first=David |date=2020-04-22 |title=Harassment fears as students post extreme pornography in online lectures |language=en-GB |work=The Guardian |url=https://www.theguardian.com/education/2020/apr/22/students-zoombomb-online-lectures-with-extreme-pornography |access-date=2020-05-18 |issn=0261-3077 |archive-date=May 22, 2020 |archive-url=https://web.archive.org/web/20200522014208/https://www.theguardian.com/education/2020/apr/22/students-zoombomb-online-lectures-with-extreme-pornography |url-status=live }}
Zoombombing affected twelve-step programs such as Alcoholics Anonymous and Narcotics Anonymous and other substance abuse and addiction recovery programs who were forced to switch to online meetings. Concerns arise from causing undue stress to an already vulnerable population and video recording which can break anonymity.{{Cite web|url=https://nypost.com/2020/04/02/trolls-crash-zoom-aa-meetings-alcohol-is-soooo-good/|title=Trolls crash Zoom Alcoholics Anonymous meetings: 'Alcohol is soooo good'|first=Hannah|last=Sparks|date=April 2, 2020|access-date=December 11, 2020|archive-date=March 7, 2021|archive-url=https://web.archive.org/web/20210307054141/https://nypost.com/2020/04/02/trolls-crash-zoom-aa-meetings-alcohol-is-soooo-good/|url-status=live}}{{Cite web|url=https://www.cnn.com/2020/04/05/us/alcoholics-anonymous-coronavirus-online/index.html|title=Alcoholics Anonymous members find support online during coronavirus pandemic|author=Denise Royal|website=CNN|date=April 5, 2020|access-date=December 11, 2020|archive-date=April 10, 2020|archive-url=https://web.archive.org/web/20200410210135/https://www.cnn.com/2020/04/05/us/alcoholics-anonymous-coronavirus-online/index.html|url-status=live}} Some bombers reference the drug-of-choice for recovery members, such as alcohol, in an attempt to emotionally trigger the participants of the meeting.
The problem reached such prominence that the United States Federal Bureau of Investigation (FBI) warned of video-teleconferencing and online classroom hijacking, which it called "Zoom-bombing."{{cite web |url=https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic |title=FBI Warns of Teleconferencing and Online Classroom Hijacking During COVID-19 Pandemic |last=Setera |first=Kristen |date=30 March 2020 |website=Federal Bureau of Investigation |language=en |url-status=live |archive-url=https://web.archive.org/web/20200416205609/https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic |archive-date=2020-04-16 |access-date=2020-03-31 |quote=people turn to video-teleconferencing (VTC) platforms to stay connected in the wake of the COVID-19 crisis, reports of VTC hijacking (also called "Zoom-bombing") are emerging}}{{Cite web |url=https://www.cnn.com/2020/04/02/us/fbi-warning-zoombombing-trnd/index.html |title=FBI warns video calls are getting hijacked. It's called 'Zoombombing' |first=Dakin |last=Andone |website=CNN |date=2020-04-02 |access-date=2020-05-22 |archive-date=November 19, 2021 |archive-url=https://web.archive.org/web/20211119094728/https://www.cnn.com/2020/04/02/us/fbi-warning-zoombombing-trnd/index.html |url-status=live }} The FBI advised users of teleconferencing software to keep meetings private, require passwords or other forms of access control such as "waiting rooms" to limit access only to specific people, and limiting screen-sharing access to the meeting host only. Given the number of incidents of Zoombombing, New York's attorney general initiated an inquiry into Zoom's data privacy and security policies.{{cite news |last1=Hakim |first1=Danny |last2=Singer |first2=Natasha |date=30 March 2020 |title=New York Attorney General Looks Into Zoom's Privacy Practices |language=en |work=The New York Times |url=https://www.nytimes.com/2020/03/30/technology/new-york-attorney-general-zoom-privacy.html?partner=IFTTT |url-status=live |url-access=limited |access-date=31 March 2020 |archive-url=https://web.archive.org/web/20230113143533/https://www.nytimes.com/2020/03/30/technology/new-york-attorney-general-zoom-privacy.html?partner=IFTTT |archive-date=13 January 2023 |quote=Over the last few weeks, internet trolls have exploited a Zoom screen-sharing feature to hijack meetings and do things like interrupt educational sessions or post white supremacist messages to a webinar on anti-Semitism — a phenomenon called "Zoombombing." [...] "We appreciate the New York attorney general's engagement on these issues}} U.S. Senator Sherrod Brown (D-OH) asked the Federal Trade Commission to investigate into the matter, accusing Zoom of engaging in deceptive practices regarding user privacy and security.{{cite web |last=Bond |first=Shannon |title=Senator Asks FTC To Investigate Zoom's 'Deceptive' Security Claims |work=National Public Radio |date=2020-04-03 |access-date=2020-04-12 |url=https://www.npr.org/2020/04/03/826968159/senator-zoom-deceived-users-over-its-security-claims |archive-date=November 19, 2021 |archive-url=https://web.archive.org/web/20211119094730/https://www.npr.org/2020/04/03/826968159/senator-zoom-deceived-users-over-its-security-claims |url-status=live }}
Amid concerns about Zoombombing, various organizations banned the use of Zoom. In April 2020, Google banned the use of Zoom on its corporate computers, directing employees to instead use its video chat app Google Duo. The use of Zoom was also banned by SpaceX, Smart Communications, NASA, and the Australian Defence Force.{{cite web |last=Vigliarolo |first=Brandon |title=Who has banned Zoom? Google, NASA, and more |website=TechRepublic |date=2020-04-09 |access-date=2020-04-11 |url=https://www.techrepublic.com/article/who-has-banned-zoom-google-nasa-and-more/ |archive-date=April 13, 2020 |archive-url=https://web.archive.org/web/20200413114306/https://www.techrepublic.com/article/who-has-banned-zoom-google-nasa-and-more/ |url-status=live }} The Taiwanese and Canadian governments banned Zoom for all government use.{{cite web |title=Taiwan joins Canada in banning Zoom for government video conferencing |work=Canadian Broadcasting Corporation |date=2020-04-07 |access-date=2020-04-11 |url=https://www.cbc.ca/news/technology/taiwan-zoom-video-conference-1.5524384 |archive-date=April 12, 2020 |archive-url=https://web.archive.org/web/20200412103347/https://www.cbc.ca/news/technology/taiwan-zoom-video-conference-1.5524384 |url-status=live }} The New York City Department of Education prohibited all its teachers from using the platform with students, and the Clark County School District in Nevada disabled access to Zoom to its staff.{{cite news |last=Strauss |first=Valerie |date=2020-04-04 |title=School districts, including New York City's, start banning Zoom because of online security issues |newspaper=The Washington Post |url=https://www.washingtonpost.com/education/2020/04/04/school-districts-including-new-york-citys-start-banning-zoom-because-online-security-issues/ |url-status=live |url-access=subscription |access-date=2020-04-11 |archive-url=https://web.archive.org/web/20200404210026/https://www.washingtonpost.com/education/2020/04/04/school-districts-including-new-york-citys-start-banning-zoom-because-online-security-issues/ |archive-date=4 April 2020}} Singapore's Ministry of Education briefly banned all teachers within the country from using Zoom{{Cite web |last=Elangovan |first=Navene |date=April 10, 2020 |title=MOE suspends use of Zoom for home-based learning after hackers hijack classes |url=https://www.todayonline.com/singapore/moe-suspends-use-zoom-home-based-learning-after-hackers-hijack-classes |access-date=2023-07-11 |website=TODAY |language=en |archive-date=July 11, 2023 |archive-url=https://web.archive.org/web/20230711030152/https://www.todayonline.com/singapore/moe-suspends-use-zoom-home-based-learning-after-hackers-hijack-classes |url-status=live }}{{cite web |last=Farrer |first=Martin |date=2020-04-11 |title=Singapore bans teachers using Zoom after hackers post obscene images on screens |url=https://www.theguardian.com/world/2020/apr/11/singapore-bans-teachers-using-zoom-after-hackers-post-obscene-images-on-screens |access-date=2020-04-11 |work=The Guardian |archive-date=November 20, 2021 |archive-url=https://web.archive.org/web/20211120223956/https://www.theguardian.com/world/2020/apr/11/singapore-bans-teachers-using-zoom-after-hackers-post-obscene-images-on-screens |url-status=live }} before lifting the ban three days later, adding extra security features.{{Cite web|url=https://www.straitstimes.com/singapore/education/schools-to-resume-use-of-zoom-for-home-based-learning-with-additional-safeguards|title=Singapore schools to resume use of Zoom for home-based learning with additional safeguards in place|last=hermesauto|date=2020-04-13|website=The Straits Times|language=en|access-date=2020-04-13|archive-date=April 15, 2020|archive-url=https://web.archive.org/web/20200415005849/http://www.straitstimes.com/singapore/education/schools-to-resume-use-of-zoom-for-home-based-learning-with-additional-safeguards|url-status=live}} Some Zoombombers have shared their side of the story, claiming they aren't trying to cause harm. They claim it is a form of protest in response to the extensive amount of work given from teachers. Not all incidents are malicious, as many have shared some new pop culture, such as memes and TikToks, to bring some relief and fun during the pandemic.
Zoom CEO Eric Yuan made a public apology, saying that the teleconferencing company had not anticipated the sudden influx of new consumer users and stating that "this is a mistake and lesson learned."{{cite web |title=After Zoom calls hacked with racial slurs and pornography, CEO admits "mistake" |work=CBS News |date=2020-04-02 |access-date=2020-04-12 |url=https://www.cbsnews.com/news/zoom-bombing-calls-hacked-racial-slurs-pornography/ |archive-date=September 21, 2021 |archive-url=https://web.archive.org/web/20210921064024/https://www.cbsnews.com/news/zoom-bombing-calls-hacked-racial-slurs-pornography/ |url-status=live }}{{cite web |last=Billings |first=Kevin |title=Zoom Announces New Security Changes In Response To Hacks And 'Zoom-Bombing' Incidents |work=International Business Times |date=2020-04-08 |access-date=2020-04-12 |url=https://www.ibtimes.com/zoom-announces-new-security-changes-response-hacks-zoom-bombing-incidents-2955269 |archive-date=December 14, 2020 |archive-url=https://web.archive.org/web/20201214094523/https://www.ibtimes.com/zoom-announces-new-security-changes-response-hacks-zoom-bombing-incidents-2955269 |url-status=live }} In response to the concerns, Zoom has published a guide on their blog on how to avoid these types of incidents.{{Cite web|url=https://blog.zoom.us/wordpress/2020/03/20/keep-the-party-crashers-from-crashing-your-zoom-event/|title=How to Keep the Party Crashers from Crashing Your Zoom Event|date=2020-03-20|website=Zoom Blog|access-date=2020-03-29|archive-date=April 2, 2020|archive-url=https://web.archive.org/web/20200402110514/https://blog.zoom.us/wordpress/2020/03/20/keep-the-party-crashers-from-crashing-your-zoom-event/|url-status=dead}} On April 7, 2020, Zoom implemented user experience and security updates to the application. Such updates include a more visible "Security" icon for users to see and use, suppression of meeting ID numbers, and a change in the default settings to require passwords and waiting rooms for sessions.{{cite web |last=Peters |first=Jay |title=Zoom adds new security and privacy measures to prevent Zoombombing |work=The Verge |date=2020-04-03 |access-date=2020-04-12 |url=https://www.theverge.com/2020/4/3/21207643/zoom-security-privacy-zoombombing-passwords-waiting-rooms-default |archive-date=November 25, 2021 |archive-url=https://web.archive.org/web/20211125023947/https://www.theverge.com/2020/4/3/21207643/zoom-security-privacy-zoombombing-passwords-waiting-rooms-default |url-status=live }} On April 8, 2020, Zoom announced that it had formed a council of chief information security officers from other companies to share ideas on best practices, and that it had hired Alex Stamos, former chief security officer of Facebook, as an adviser.{{cite news |last1=Singer |first1=Natasha |date=8 April 2020 |title=Zoom Rushes to Improve Privacy for Consumers Flooding Its Service |work=New York Times |url=https://www.nytimes.com/2020/04/08/business/zoom-video-privacy-security-coronavirus.html?action=click&module=RelatedLinks&pgtype=Article |url-status=live |url-access=limited |access-date=22 May 2020 |archive-url=https://web.archive.org/web/20220305105320/https://www.nytimes.com/2020/04/08/business/zoom-video-privacy-security-coronavirus.html?action=click&module=RelatedLinks&pgtype=Article |archive-date=5 March 2022}} Zoom released its 5.0 version in April 2020 with security features that include AES 256-bit GCM encryption, passwords by default, and a feature to report suspicious users to its Trust and Safety Team for possible misuse.{{cite web |title=90-Day Security Plan Progress Report: April 22 |publisher=Zoom Video Communications |date=2020-04-22 |access-date=2020-04-26 |url=https://blog.zoom.us/wordpress/2020/04/22/90-day-security-plan-progress-report-april-22/ |archive-date=June 18, 2020 |archive-url=https://web.archive.org/web/20200618173827/https://blog.zoom.us/wordpress/2020/04/22/90-day-security-plan-progress-report-april-22/ |url-status=live }}{{cite web |title='Zoombombing' targeted with new version of app |publisher=BBC News |date=2020-04-23 |access-date=2020-04-26 |url=https://www.bbc.com/news/business-52392084 |archive-date=December 22, 2021 |archive-url=https://web.archive.org/web/20211222012854/https://www.bbc.com/news/business-52392084 |url-status=live }} In May 2020, Zoom announced it had temporarily disabled its Giphy (frequently used as a tactic in Zoombombing) integration until security concerns could be properly and fully addressed.{{Cite web |title=Zoom has temporarily removed Giphy from its chat feature |url=https://www.theverge.com/2020/5/25/21269506/zoom-disables-giphy-gifs-chat-security-facebook |last=Lyons |first=Kim |date=2020-05-25 |website=The Verge |language=en |access-date=2020-05-26 |archive-date=May 25, 2020 |archive-url=https://web.archive.org/web/20200525194040/https://www.theverge.com/2020/5/25/21269506/zoom-disables-giphy-gifs-chat-security-facebook |url-status=live }} On July 1, 2020, Zoom stated it had released 100 new safety features over the past 90 days, including end-to-end encryption for all users, turning on meeting passwords by default, giving users the ability to choose which data centers calls are routed from, consulting with security experts, forming a CISO council, an improved bug bounty program, and working with third parties to help test security.{{cite news |last1=Peters |first1=Jay |title=Zoom promises its first transparency report later this year |url=https://www.theverge.com/2020/7/1/21310130/zoom-transparency-report-update-ceo-security-program |access-date=30 July 2020 |work=The Verge |date=1 July 2020 |archive-date=November 16, 2020 |archive-url=https://web.archive.org/web/20201116205027/https://www.theverge.com/2020/7/1/21310130/zoom-transparency-report-update-ceo-security-program |url-status=live }}{{cite news |last1=Cruze |first1=Danny |title=Zoom released 100 new security features in 90 days |url=https://www.livemint.com/technology/tech-news/zoom-released-100-new-security-features-in-90-days-11593681306833.html |access-date=30 July 2020 |work=Live Mint |date=2 July 2020 |archive-date=November 16, 2020 |archive-url=https://web.archive.org/web/20201116205037/https://www.livemint.com/technology/tech-news/zoom-released-100-new-security-features-in-90-days-11593681306833.html |url-status=live }}
Criminal use
National authorities worldwide warned of possible charges against people engaging with Zoombombing.{{Cite web |url=https://www.justice.gov/usao-edmi/pr/federal-state-and-local-law-enforcement-warn-against-teleconferencing-hacking-during |title=Federal, State, and Local Law Enforcement Warn Against Teleconferencing Hacking During Coronavirus Pandemic |date=April 3, 2020 |access-date=April 11, 2020 |archive-date=April 16, 2020 |archive-url=https://web.archive.org/web/20200416221709/https://www.justice.gov/usao-edmi/pr/federal-state-and-local-law-enforcement-warn-against-teleconferencing-hacking-during |url-status=bot: unknown }}{{cite press release|title=Federal, State, and Local Law Enforcement Warn Against Teleconferencing Hacking During Coronavirus Pandemic|agency=United States District Court for the Eastern District of Michigan|date=2020-04-03|access-date=2020-04-11|url=https://www.justice.gov/usao-edmi/pr/federal-state-and-local-law-enforcement-warn-against-teleconferencing-hacking-during|archive-date=April 16, 2020|archive-url=https://web.archive.org/web/20200416221709/https://www.justice.gov/usao-edmi/pr/federal-state-and-local-law-enforcement-warn-against-teleconferencing-hacking-during|url-status=live}} On April 8, 2020, a teen in Madison, Connecticut, was arrested for computer crime, conspiracy, and disturbing the peace following a Zoombombing incident involving online classes at Daniel Hand High School; police also identified another teen involved in the incident.{{cite web|title=Connecticut Teen Arrested for Allegedly 'Zoom Bombing' Virtual High School Lessons and Using 'Obscene Language and Gestures'|url=https://www.newsweek.com/connecticut-teenager-arrested-zoom-bombing-high-school-virtual-class-police-1497075|last=Murdock|first=Jason|date=2020-04-09|work=Newsweek|access-date=2020-04-11|archive-date=July 1, 2021|archive-url=https://web.archive.org/web/20210701191330/https://www.newsweek.com/connecticut-teenager-arrested-zoom-bombing-high-school-virtual-class-police-1497075|url-status=live}} In San Francisco, a man was arrested after being traced to pornographic videos that were streamed on Zoom.{{Cite web|title=SF Man Traced From Zoom Streaming Activity Faces Child Porn Charges|url=https://www.nbcbayarea.com/news/local/san-francisco/sf-man-traced-from-zoom-streaming-activity-faces-child-porn-charges/2287372/|website=NBC Bay Area|date=May 9, 2020|language=en-US|access-date=2020-05-18|archive-date=May 18, 2020|archive-url=https://web.archive.org/web/20200518094040/https://www.nbcbayarea.com/news/local/san-francisco/sf-man-traced-from-zoom-streaming-activity-faces-child-porn-charges/2287372/|url-status=live}} As of May 2020, the FBI has received 195 incidents of Zoombombing involving child abuse,{{cite web |title=FBI Issues Warning To Public After Reports Of 'Zoombombing' With Child Abuse Being Displayed During Virtual Meetings |work=WCCO-TV |location=Minneapolis |date=2020-05-20 |access-date=2020-06-16 |url=https://minnesota.cbslocal.com/2020/05/20/fbi-issues-warning-to-public-after-reports-of-zoombombing-with-child-abuse-being-displayed-during-virtual-meetings/ |archive-date=June 16, 2020 |archive-url=https://web.archive.org/web/20200616110642/https://minnesota.cbslocal.com/2020/05/20/fbi-issues-warning-to-public-after-reports-of-zoombombing-with-child-abuse-being-displayed-during-virtual-meetings/ |url-status=live }} while the United Kingdom's National Crime Agency has reported more than 120 such cases.{{cite news |title=More than 120 cases of child abuse Zoombombing in UK being investigated |newspaper=The Irish Times |date=2020-05-18 |access-date=2020-06-16 |url=https://www.irishnews.com/magazine/technology/2020/05/18/news/more-than-120-cases-of-child-abuse-zoombombing-in-uk-being-investigated-1943449/ |archive-date=October 26, 2021 |archive-url=https://web.archive.org/web/20211026172753/https://www.irishnews.com/magazine/technology/2020/05/18/news/more-than-120-cases-of-child-abuse-zoombombing-in-uk-being-investigated-1943449/ |url-status=live }}
Notable incidents
St. Paulus Lutheran Church in San Francisco filed a class-action lawsuit against Zoom after one of its Bible study classes was "Zoombombed" with pornographic videos on May 6, 2020.{{cite web|title=California church files class action lawsuit against Zoom after bible class 'Zoombombing'|url=https://www.usatoday.com/story/tech/2020/05/14/zoom-class-action-lawsuit-zoombomb-pornographic-images/5182609002/|last=Tyko|first=Kelly|date=2020-05-15|publisher=USA Today|access-date=2020-05-17|archive-date=May 18, 2020|archive-url=https://web.archive.org/web/20200518004915/https://www.usatoday.com/story/tech/2020/05/14/zoom-class-action-lawsuit-zoombomb-pornographic-images/5182609002/|url-status=live}} The church alleged that Zoom "did nothing" when it tried to reach out to the company.{{cite web|title=California church sues Zoom over 'Zoombombing' pornography incident|url=https://thehill.com/changing-america/respect/equality/497853-california-church-sues-zoom-over-zoombombing-pornography|last=Kelley|first=Alexandra|date=2020-05-14|work=The Hill|access-date=2020-05-17|archive-date=May 21, 2020|archive-url=https://web.archive.org/web/20200521160317/https://thehill.com/changing-america/respect/equality/497853-california-church-sues-zoom-over-zoombombing-pornography|url-status=live}}
In November 2020, a Dutch journalist for RTL Nieuws managed to gain access to a secret Zoom meeting of European Union defence ministers. The EU's foreign affairs representative Josep Borrell told him that it was criminal offense and he should sign off before the police arrived. The Zoombomb was revealed to have been the result of the Dutch defence minister Ank Bijleveld posting a picture of herself that showed the login and the partial PIN number.{{cite news | url=https://www.bbc.co.uk/news/world-europe-55027641 | title=Dutch journalist gatecrashes EU defence video conference | work=BBC News | date=November 21, 2020 }}
In 2022, an online event hosted by the Italian Senate's Movimento 5 Stelle and broadcast live to Senato della Repubblica was interrupted by roughly a minute of a 3D animated Final Fantasy VII pornographic parody, displaying the character Tifa Lockhart in the middle of sexual intercourse.{{Cite web |date=2022-01-18 |title=Porn video inserted into M5S Senate online event - English |url=https://www.ansa.it/english/news/politics/2022/01/18/porn-video-inserted-into-m5s-senate-online-event_85b49960-edda-404e-a513-7f1394cc8a0a.html |access-date=2022-01-24 |website=ANSA.it |language=en |archive-date=April 7, 2022 |archive-url=https://web.archive.org/web/20220407212725/https://www.ansa.it/english/news/politics/2022/01/18/porn-video-inserted-into-m5s-senate-online-event_85b49960-edda-404e-a513-7f1394cc8a0a.html |url-status=live }}{{Cite web |last=Zaid |first=A'bidah |date=2022-01-20 |title=Tifa Lockhart Final Fantasy Pornography Interrupts Italian Senate Proceedings |url=https://geekculture.co/tifa-lockhart-final-fantasy-pornography-interrupts-italian-senate-proceedings/ |access-date=2022-01-25 |website=Geek Culture |language=en-US |archive-date=February 4, 2022 |archive-url=https://web.archive.org/web/20220204150136/https://geekculture.co/tifa-lockhart-final-fantasy-pornography-interrupts-italian-senate-proceedings/ |url-status=live }} Overlapping the content's original audio was a man speaking English with a thick Italian accent stating, "I used to be a sex offender, but now I am a kindergarten teacher."{{Cite web |last=Kaonga |first=Gerrard |date=2022-01-20 |title=Italian Senate meeting interrupted by lewd "Final Fantasy" video |url=https://www.newsweek.com/italian-senate-meeting-zoom-final-fantasy-porn-maria-laura-mantovani-video-1671170 |access-date=2022-01-24 |website=Newsweek |language=en |archive-date=March 18, 2022 |archive-url=https://web.archive.org/web/20220318073747/https://www.newsweek.com/italian-senate-meeting-zoom-final-fantasy-porn-maria-laura-mantovani-video-1671170 |url-status=live }}
Brian Adams, a man from Paintsville, Kentucky, faced multiple federal charges after he interrupted an elementary school's video conference class during the COVID-19 pandemic with a digital racist threat. He allegedly crashed a class Zoom conference on October 14, 2020, and targeted the Laureate Academy Charter School, whose student population is about 67% Black, because of its racial demographics.{{Cite web |last=Bubnash |first=Kasey |date=2022-07-06 |title=Racist 'Zoombombing' of Harvey fifth-grade class leads to federal indictment |url=https://www.nola.com/news/courts/racist-zoombombing-of-harvey-fifth-grade-class-leads-to-federal-indictment/article_29896f5e-fcc6-11ec-bea0-4f93f1867884.html |access-date=2023-05-27 |website=NOLA.com |language=en |archive-date=May 27, 2023 |archive-url=https://web.archive.org/web/20230527050637/https://www.nola.com/news/courts/racist-zoombombing-of-harvey-fifth-grade-class-leads-to-federal-indictment/article_29896f5e-fcc6-11ec-bea0-4f93f1867884.html |url-status=live }}
In 2020, livestreamer Muudea Sedik, better known as twomad, gained popularity for his Zoom bombings. Sedik would request Zoom meeting links or passwords from his followers on social media, and would broadcast the subsequent invasions live. Sedik's antics made him a popular subject for various internet memes, particularly among Generation Z.{{Cite journal |last=Friedberg |first=Brian |date=2020 |title=SPACE INVADERS: THE NETWORKED TERRAIN OF ZOOM BOMBING |url=https://mediamanipulation.org/sites/default/files/2020-07/TSC002_Zoombombing.pdf |url-status=live |journal=Technology and Social Change |pages=4 |archive-url=https://web.archive.org/web/20240220121016/https://mediamanipulation.org/sites/default/files/2020-07/TSC002_Zoombombing.pdf |archive-date=February 20, 2024 |access-date=February 18, 2024}}