Demand for remote communication has grown significantly as the majority of business, education and other institutions has moved part of their activities to virtual communication amid the continuing COVID-19 emergency situation in Lithuania. The National Cyber Security Centre under the Ministry of National Defence warns about vulnerabilities of Zoom, one of the most popular video conferencing and webinars platform: data privacy issue and increasing numbers of system counterfeit used to obtain confidential user data and overtake devices are identified.
Cybersecurity experts of the National Cyber Security Centre have found that detected security shortfalls enabled interception of different user data: e-mail addresses, images, login data, permission to use camera and microphone, record conversations, etc. Zoom also sent data to Facebook even in cases of users who did not have Facebook accounts.
National Cyber Security Centre experts invite Zoom users to stay cautious and not to use the platform to transfer confidential data.
Cybersecurity experts advise to use only the video feature for video conferencing on Zoom and to use another platform for chatting, or at least open Zoom through browser without installing the platform on the device. Users are also invited to be particularly vigilant when using Zoom via browser because counterfeits of the platform aiming to illegally obtain user data or get to download malware have been seen proliferating.
In the cases when the platform needs to be installed on the device, its most current version is recommended. Organisations are advised against making Zoom chat channel ID public, Zoom Rooms should be protected by passwords. Experts also remind of the device security – if a compromised device is used, the question of security of the conference platform becomes irrelevant.
Experts of the National Cyber Security Centre advise users to be cautious at all times and pay particular attention to the reliability of links and files they get.
National Cyber Security Centre website: https://www.nksc.lt/