
Zoom’s surge in use during the pandemic has been matched by a rise in scams that exploit the platform’s familiar meeting invites.
Impersonation invitations targeting senior staff
Attackers often send a link that looks like a standard Zoom URL, but subtle changes redirect the recipient to a counterfeit login page. When a senior employee enters credentials, the criminals gain access to internal systems and can install malware or exfiltrate data. The same technique can involve a fake meeting screen where the scammer pretends to be a company executive or an external partner, then asks the victim to download a file or share their screen.
These schemes rely on the trust placed in routine calendar invites. Once inside, the intruder can move laterally across the network, looking for valuable information or planting ransomware.
Screen‑sharing and remote‑access traps
A second common scam asks the target to install screen‑sharing or remote‑access software under the pretense of a software update. The user is guided to a realistic‑looking Zoom page and prompted to download an installer that actually contains malicious code. Once installed, the malware can harvest banking details, passwords, and other confidential data, which may later appear for sale on dark‑web forums.
Because Zoom itself never requests control of a participant’s screen, any such prompt should be treated with suspicion. Disabling remote‑access features unless they are essential can reduce exposure.
Related: Businesses Compare Green Energy Suppliers Before Switching
Fake update requests that deliver malware
In the third scenario, scammers masquerade as a legitimate software vendor and send a link that appears to originate from Zoom. The page may display official branding and ask the user to download an “update.” The file, however, is a trojan that can compromise the entire organization’s network.
Users who do not verify the source of an update risk giving attackers a foothold that can be used to target internal accounts, including those with privileged access.
These three patterns share a common thread: they exploit the expectation that meeting invites are safe and that software updates are routine. Organizations need to adopt clear policies and technical controls to break that expectation.
One way to put the risk in perspective is to consider how quickly remote work became the default for many companies. The shift happened in months, but security habits often lag behind. When employees are used to clicking “Join” without a second thought, the smallest deviation in a URL can be enough to hand over credentials. Strengthening verification steps, even for familiar contacts, is a practical response that aligns with broader trends in cyber‑defense.
Practical steps to reduce Zoom‑related threats
Encourage staff to stay vigilant, especially if they handle a high volume of meetings. Enabling multi‑factor authentication (MFA) is a strong first line; the Information Commissioner’s Office may impose penalties for breaches that occur without it.
Related: Top business bank accounts in the UK
Keep anti‑virus solutions up to date across all devices. Hovering over a link to view the full URL can reveal subtle mismatches that betray a phishing attempt. Organizations should also set policies that require verification of urgent or unusual meeting requests through a separate channel, such as a known email address or phone number.
Digital ID can allow participants of a meeting to be identified before the meeting begins; a few providers offer this as an extra paid service.
Employees should remember that Zoom will never ask for screen control; any such request is a red flag. Likewise, software does not update itself mid‑meeting, so an unexpected prompt to install something should be treated as suspicious.
Finally, configuring email clients so they do not automatically add meeting invitations to calendars can prevent malicious entries from slipping in unnoticed. A clear process for reporting incidents—such as submitting a Trust & Safety form with details and screenshots—helps security teams respond quickly.


