Zoom and Video Call Security: How to Stop Meeting Hijacking and Zoombombing


You are three minutes into a team meeting or a school class when a stranger's camera pops up, blasting loud music or graphic images before the host can react. This is meeting hijacking, still commonly called "Zoombombing" even though it now happens across Zoom, Google Meet, Microsoft Teams, and Webex alike. Years after the term became famous, it is still happening in 2026 — to classrooms, HR meetings, city council sessions, and support groups — because most people never changed the basic settings that allow it.

Why meeting hijacking still happens

Video conferencing tools were built for speed and openness: click a link, join instantly, no account required. That same convenience is what attackers exploit. Meeting links get shared publicly on social media, forums, or leaked chat groups; meeting IDs get reused week after week; and "waiting rooms" or passwords get turned off because they add one extra click for legitimate guests. Once someone has a link or a guessable meeting ID, an open meeting with no lobby and no password has effectively no lock on the door.

Attackers also use automated tools that scan for exposed meeting IDs across common numbering patterns, especially on platforms where a personal meeting ID stays the same for every call. A personal ID that gets shared once, even accidentally in a screenshot or a public calendar invite, can be reused indefinitely.

Warning signs your meeting is exposed

  • You are using the same personal meeting ID/link for every session instead of generating a new one.
  • The meeting link has ever been posted somewhere public — a public calendar, a social media post, a public Slack, or a forwarded email chain you do not fully control.
  • Waiting room or "knock to join" is turned off.
  • Anyone can join without a passcode.
  • Screen sharing is open to all participants by default, not just the host.
  • You do not recognize a name that appears in the participant list right before something disruptive happens.

How to lock down your video calls

  1. Never reuse your personal meeting ID for anything sensitive. Generate a random, one-time meeting ID for classes, webinars, or any call whose link might be shared beyond your immediate group.
  2. Turn on the waiting room. This lets the host approve each participant before they enter, which is the single most effective control against uninvited guests.
  3. Require a passcode to join, and share it only through the same channel as the meeting link — not in a separate public post.
  4. Lock the meeting once everyone expected has joined. Most platforms let a host lock a session so no new participants can enter at all, even with the correct link.
  5. Restrict screen sharing to the host or to hosts and co-hosts only, and change this back after the meeting if it needs to be open for a specific segment.
  6. Disable "Join Before Host" so no one can enter an empty room and set up trouble before you arrive.
  7. Limit file transfer and chat file-sharing in platform settings if your meetings do not need it — this closes off a path attackers use to drop malicious files.
  8. Use platform-level account security too: turn on two-factor authentication for your Zoom/Teams/Meet account itself, since a compromised host account can be used to reconfigure settings or hijack future meetings.
  9. Vet where you share links. Send meeting invitations through a school portal, a company calendar, or direct email — not a public social media post, public Discord, or unmoderated group chat.

If a meeting gets hijacked

If a disruptive or malicious participant joins a live meeting, act immediately as host or co-host:

  • Remove the disruptive participant and, if the platform allows it, report them at the same time so they cannot simply rejoin under the same account.
  • Lock the meeting right after removal to prevent them (or accomplices) from re-entering with a different name.
  • If the disruption is severe, end the meeting entirely and restart with a brand-new meeting ID, waiting room enabled, and a fresh passcode shared only with confirmed participants.
  • Screen-record or screenshot the incident (participant name, time, and behavior) before removing them, in case you need to report it to your platform, your school, or your employer's IT/security team.
  • Report the incident through the platform's trust and safety tools — Zoom, Teams, and Meet all have reporting flows for meeting abuse — and notify participants afterward so they understand what happened and that it has been handled.
  • If sensitive information was exposed or the meeting involved minors, escalate to your organization's IT/security team and, where illegal content or threats were involved, consider a report to local law enforcement.

The Bottom Line

Meeting hijacking is not a mysterious hack — it is almost always a link that ended up somewhere it should not have been, combined with settings that never asked for a second form of confirmation. A waiting room, a real passcode, a locked meeting once everyone has arrived, and a fresh ID for anything sensitive turn an open room into a controlled one. Five minutes spent adjusting default settings is the difference between a smooth call and an incident you have to explain afterward.

Comments

Popular posts from this blog

Best Antivirus Software of 2026: Top 5 Compared After Real Testing

Public Wi-Fi Dangers: 7 Critical Steps to Stay Safe

Best Identity Theft Protection Services of 2026: Top 5 Ranked and Reviewed