Half a Million Hacked Zoom Accounts Flood Dark Web Markets

Over 500,000 stolen Zoom credentials are circulating on hacker forums and the dark web, often sold for less than a penny each. These accounts are compromised through credential stuffing attacks using login details from older data breaches.

Over 500,000 compromised Zoom accounts are currently circulating on hacker forums and the dark web, often sold for less than a penny each or given away for free. Threat actors obtain these login credentials through credential stuffing attacks, which involve using email and password combinations leaked in previous, unrelated data breaches to break into Zoom accounts. The successful logins are then compiled into massive lists for distribution.

Cybersecurity intelligence firm Cyble discovers that some hackers share these accounts for free to build reputation within the hacking community, while others sell them in bulk at fractions of a cent per account. Cyble purchases approximately 530,000 of these credentials for $0.0020 each to analyze the threat and warn their customers. The stolen data includes sensitive information such as email addresses, passwords, personal meeting URLs, and HostKeys.

The compromised accounts belong to a wide range of victims, including major companies like Chase and Citibank, as well as numerous educational institutions such as the University of Vermont and Dartmouth. While some affected users note that the exposed passwords are outdated, Cyble confirms that many of the compromised credentials remain active and valid.

Read More at the original source →