A First Look at Zoombombing
Chen Ling, Utkucan Balci, Jeremy Blackburn, Gianluca Stringhini
Abstract
Online meeting tools like Zoom and Google Meet have become central to our professional, educational, and personal lives. This has opened up new opportunities for large scale harassment. In particular, a phenomenon known as zoombombing has emerged, in which aggressors join online meetings with the goal of disrupting them and harassing their participants. In this paper, we conduct the first data-driven analysis of calls for zoombombing attacks on social media. We identify ten popular online meeting tools and extract posts containing meeting invitations to these platforms on a mainstream social network, Twitter, and on a fringe community known for organizing coordinated attacks against online users, 4chan. We then perform manual annotation to identify posts that are calling for zoombombing attacks, and apply thematic analysis to develop a codebook to better characterize the discussion surrounding calls for zoombombing. During the first seven months of 2020, we identify over 200 calls for zoombombing between Twitter and 4chan, and analyze these calls both quantitatively and qualitatively. Our findings indicate that the vast majority of calls for zoombombing are not made by attackers stumbling upon meeting invitations or bruteforcing their meeting ID, but rather by insiders who have legitimate access to these meetings, particularly students in high school and college classes. This has important security implications because it makes common protections against zoombombing, e.g., password protection, ineffective. We also find instances of insiders instructing attackers to adopt the names of legitimate participants in the class to avoid detection, making countermeasures like setting up a waiting room and vetting participants less effective. Based on these observations, we argue that the only effective defense against zoombombing is creating unique join links for each participant.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- Hate Raids on Twitch: Echoes of the Past, New Modalities, and Implications for Platform GovernanceCatherine Han, Joseph Seering, Deepak Kumar, Jeffrey T. Hancock et al.CSCW 2023 · 43 citations
- "I'm a Professor, which isn't usually a dangerous job": Internet-facilitated Harassment and Its Impact on ResearchersPeriwinkle Doerfler, Andrea Forte, Emiliano De Cristofaro, Gianluca Stringhini et al.CSCW 2021 · 39 citations
- Getting Meta: A Multimodal Approach for Detecting Unsafe Conversations within Instagram Direct Messages of YouthShiza Ali, Afsaneh Razi, Seunghyun Kim, Ashwaq Alsoubai et al.CSCW 2023 · 32 citations
- Is It Safe to Share Your Files? An Empirical Security Analysis of Google WorkspaceLiuhuo Wan, Kailong Wang, Haoyu Wang, Guangdong BaiWWW 2024 · 6 citations
- Enforcing End-to-end Security for Remote Conference ApplicationsYuelin Liu, Huangxun Chen, Zhice YangS&P 2024 · 5 citations
Builds on3
- Detecting Fake Accounts in Online Social Networks at the Time of RegistrationsDong Yuan, Yuanli Miao, Neil Zhenqiang Gong, Zheng Yang et al.CCS 2019 · 86 citations
- The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity AbuseJanith Weerasinghe, Bailey Flanigan, Aviel J. Stein, Damon McCoy et al.WWW 2020 · 24 citations
- The Tools and Tactics Used in Intimate Partner Surveillance: An Analysis of Online Infidelity ForumsEmily Tseng, Rosanna Bellini, Nora McDonald, Matan Danos et al.USENIX Security 2020
Related papers
- Seeing Through: Analyzing and Attacking Virtual Backgrounds in Video CallsFelix Weissberg, Jan Malte Hilgefort, Steve Grogorick, Daniel Arp et al.USENIX Security 2025
- Multi-Stage Group Key Distribution and PAKEs: Securing Zoom Groups against Malicious Servers without New Security ElementsCas Cremers, Eyal Ronen, Mang ZhaoS&P 2024 · 2 citations
- Investigating Moderation Challenges to Combating Hate and Harassment: The Case of Mod-Admin Power Dynamics and Feature Misuse on RedditMadiha Tabassum, Alana Mackey, Ashley Schuett, Ada LernerUSENIX Security 2024 · 10 citations
- Beyond Mute and Block: Adoption and Effectiveness of Safety Tools in Social VR, from Ubiquitous Harassment to Social SculptingMaheshya Weerasinghe, Shaun Alexander Macdonald, Cristina Fiani, Joseph O'Hagan et al.IEEE VR 2025 · 12 citations
- Investigating the Use and Perception of Blocking Feature in Social Virtual Reality Spaces: A Study on Discussion ForumsQijia Chen, Seyed Mahed Mousavi, Giuseppe Riccardi, Giulio JacucciCSCW 2025 · 9 citations
