In the latest privacy headache, thousands of Zoom account details were reportedly found on the dark web.
Account Information Is Selling for Cheap
Per Bleeping Computer, the discovery was made by researchers at Cyble, a third-party cyber-threat platform. Cyble revealed it found up to 530,000 Zoom accounts and their details — including passwords, email addresses, and personal meeting URLs. The researchers tested some of the credentials and found them to be valid.
As the firm explained, the discovery was mostly the result of credential stuffing. In this process, hackers use the same details from previous successful security breaches on new platforms, considering many people have the habit of reusing the same password on multiple services.
While some account credentials are being sold for free, others go for less than a cent each. Researchers also posited that some hackers are doing this for the sake of gaining more popularity on the dark web.
Users Reusing Passwords
Per the report, one of the user’s passwords had not been changed in a long time. This gives cause for speculation that a lot of the credentials could also be old and outdated.
Of course, the fact that hackers still have these details means that they can always try them on new services and use brute force hacking to gain access. For many users, the best way to prevent this likelihood is to use unique passwords on different services.
As for Zoom, the company isn’t entirely at fault on this one. The teleconferencing app can’t do much to restrict users from recycling old passwords that hackers already have access to when signing up. However, the firm could have introduced several security features that restrict unwanted access to users’ accounts. This is where two-factor authentication comes in.
Still, Zoom has endured its fair share of criticism in recent weeks. Reports of hackers gaining access to private chats and “zoombombing” meetings have been prominent in the past month, and the firm has also found itself on the blacklist of several organizations as a result of these privacy concerns.