Tag Archives: Zoom

Why risk management IS important to an organization

Image by <a href="https://pixabay.com/users/geralt-9301/?utm_source=link-attribution&utm_medium=referral&utm_campaign=image&utm_content=909710">Gerd Altmann</a> from <a href="https://pixabay.com/?utm_source=link-attribution&utm_medium=referral&utm_campaign=image&utm_content=909710">Pixabay</a>

Without the management of risk, business functions become in jeopardy. Especially when those functions have been identified as critical to achieving the strategic mission of the organization.  Ensuring that financial data is backed up, for example, can keep a business functioning via maintaining sales data, paying its employees, and could be a component of a law that the organization must follow to stay in business. However, if the backup mechanism fails and there is no “Plan B,” the organization is in serious detriment. By knowing how business functions are prioritized, risk management activities can be implemented to protect them.

Within the video communications industry, Zoom was affected by a security breach in 2020. Hackers took advantage of the fact that more people were using the application during the early part of the pandemic and that the application itself had poor programming and security measures. They used a brute force-type of attack, called credential stuffing to gain access to login credentials, email addresses, and personal URLs of meetings of over 500,000 users. The harvested data was given away for free or sold on the dark web for a penny.

The hackers collected databases of usernames and passwords from a variety of attacks from 2013 through 2020. Then they wrote a “…configuration file for an application stress testing tool” (Winder, 2020). The configuration file aimed the stress tool at Zoom. To avoid being discovered as a DoS attack, the configuration file enabled multiple bots to carry out the attempted logins and also varied the time between login attempts to make the logins seem normal. All the password and usernames were then vetted to make sure they worked and collected into one database that was then sold in online forums on the dark web.

Ironically, Zoom’s mission statement is to “…make video communications frictionless” (Zoom, 2019). Unfortunately that has not been the case as the hackers. This incident resulted in privacy lawsuits backed up by California’s Consumer Privacy Act and a huge downturn in the value of its stock.