Previous All Posts Next

U.S. Intel Warns: Foreign Spies Exploit Zoom for Espionage

Posted: May 12, 2020 to News.

Tags: Work from Home, Malware, Data Breach

US Intel Officials warn that Americans are being targeted by foreign spies on Zoom and other video chat platforms. We have been following the saga that is Zoom security since the beginning of the work-from-home boom stemming from the pandemic, and even as Zoom attempts to update its security, more bad press keeps popping up. We had cybercriminals going on phishing expeditions and "Zoombombing" businesses, which was bad enough, but now cyberspies are getting into the mix... especially those from China, who have a vested interest in spying on US businesses.  And Zoom is very attractive to Chinese virtual spies, especially after it was made known in early April that Zoom's weaknesses favor China, seeing as not only were encryption keys actually routed through servers in China, but the fact that Zoom is reliant on Chinese labor, it could make the newly popular business somewhat vulnerable from the pressure of Chinese politicians. It is important to note that as of this moment, China has not compromised Zoom, at least not knowingly, but the Zoom security issues that have been uncovered leave the company at higher risk than its counterparts, and that it appears that spies are combing the vulnerable app for  potentially sensitive conversations, especially surrounding finances, business and product development, leads and intellectual properties.  They are seemingly focusing on educational, corporate and government meetings. As such, US authorities have issued a warning about discussing such sensitive information on Zoom or any other video conferencing app.  In fact, late last week the Senate's Sergeant-at-Arms warned fellow senators not to use Zoom. In response to this negative press, Zoom is publicly promising to address and fix these vulnerabilities in their security, including updating their encryption, which was not, as they initially stated, actually "end-to-end."  Which is a problem, considering that even though Zoom is a San Jose-based company, they were keeping at least some of their decryption keys on a server in China, even though the conversations were occurring in North America. Which isn't too surprising because even though its headquarters are located in CA, most of the development occurred in China.  And though they don't really appear to be apologizing for their less-than-lackluster security, they do appear to be taking steps to tighten up.  In fact, Eric Yuan, Zoom's CEO, has been in contact with the former chief security officer at Facebook and Yahoo, Alex Stamos, about working together to beef up security. But will that be enough?  Only time will tell.  Several senators and states' attorney generals have begun asking around about Zoom and how they handled their security.  It looks like this saga is far from over. We here at Petronella Technology Group recommend that you take control of the security in your home office - do not rely on an app to keep you safe.  A great way to begin layering your cyber security at home is by downloading our Free Remote Security Checklist.  And as always, you can schedule an appointment by clicking here, or give us a call at 919-422-2607.

Protect Your Business Today

Petronella Technology Group has provided cybersecurity, compliance, and managed IT services from Raleigh, NC for over 23 years. Contact us today for a free consultation and technology assessment.

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent more than 30 years working at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential (RP-1372) issued by the Cyber AB, is an NC Licensed Digital Forensics Examiner (License #604180-DFE), and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. Craig also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served 2,500+ clients, maintained a zero-breach record among compliant clients, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Need Cybersecurity or Compliance Help?

Schedule a free consultation with our cybersecurity experts to discuss your security needs.

Schedule Free Consultation
Previous All Posts Next
Free cybersecurity consultation available Schedule Now