Stolen Zoom Accounts for Sale

On the dark web (the part of the Internet not publicly accessible), offers to sell stolen Zoom accounts are proliferating at an alarming rate. We are talking about hundreds of thousands of profiles, most of them offered for token amounts, which could become a source of trouble for many an organization.

The Scale of the Problem: Hundreds of Thousands of Accounts

The alarming trend was discovered by security researchers at Cyble. While monitoring the dark web, they came across approximately 530,000 stolen accounts for the Zoom video conferencing platform being offered for sale. The offered profiles contained email addresses, passwords, personal meeting room addresses for individual users, and individual host keys.

How Can Stolen Accounts Be Used?

How can criminals use stolen accounts? The simplest use is to employ them for zoom-bombing attacks, which involve joining other people's meetings solely to vandalize them. In recent weeks, such incidents have become a plague for many an organization. Potentially, however, far more dangerous is the takeover by criminals of the corporate Zoom account of one of a company's employees. In this way, they can impersonate that person within the organization and extort confidential information from other employees or the company's contractors by carrying out a phishing attack on them.

- Although the sudden surge in hacker interest in the Zoom platform is alarming, it is not at all surprising. Criminals direct their efforts where they can yield the greatest profit. At a time of rapid growth in Zoom's popularity and its adoption by more and more organizations, often without full knowledge of how to use it safely, it was predictable that criminals would also focus their attention on it – comments Kamil Sadkowski, senior threat analyst at ESET.

Where Does the Stolen Data Come From?

The accounts available for sale were mostly stolen using repeated login credentials obtained as a result of leaks from other services. This means that the blame for such incidents lies with users and their failure to practice proper password hygiene. The same method can, after all, be used to steal accounts in many other services and on websites. However, as Kamil Sadkowski of ESET reassures, such situations can be relatively easily protected against.

- We should never use the same combination of login and password to sign in to different services and platforms. By following this simple rule, we can sleep a little more soundly – even if our data leaks from one service, criminals will not be able to use it to log in to our other accounts – explains Kamil Sadkowski of ESET.

Summary

Cyble researchers discovered approximately 530,000 stolen Zoom accounts on the dark web. Criminals can use them for zoom-bombing attacks or to impersonate company employees in order to extort confidential information. The thefts result mainly from a failure to practice proper password hygiene and from using the same login credentials across different services.

ESET expert Kamil Sadkowski reminds us that the key principle is to use unique passwords for each service. Thanks to this, even a data leak from one service will not allow criminals to take over a user's other accounts.