Zoom says it is under investigation by the SEC and two US attorney offices over security and privacy issues and interactions with China and other governments
- Company says data security, privacy actions under review — Videoconferencing firm's contacts with China spur scrutiny
Context & Ripple Effects
Zoom's 2020 security reckoning is escalating from state-level complaints to federal probes. After New York's AG flagged vulnerabilities as sensitive work moved onto the platform in letters to the company and the FTC extracted a proposed security-enhancement settlement over encryption claims, the SEC and two US attorney offices are now examining the same issues — plus a dimension the earlier actions only touched: Zoom's contacts with China.
That China thread has its own record. Zoom deactivated US-based activists' accounts at Beijing's demand in June before pledging such requests would not affect users outside mainland China, and the concern resurfaced when the FCC cited Zoom's China ties while reviewing its Five9 acquisition bid. This investigation puts the company's government interactions under formal legal scrutiny rather than policy promises.
First-order effects
- Zoom must respond to parallel SEC and US attorney inquiries spanning data security, privacy disclosures, and communications with Chinese and other governments — a disclosure-exposure problem on top of the remediation it already agreed to with the FTC.
Second-order effects
- Regulatory scrutiny of Zoom's China ties spills into its dealmaking: the FCC's review of the $15B Five9 acquisition already cites those ties, so federal investigators' findings become inputs to whether the merger clears.
Third-order effects
- If the pattern holds, US platforms operating between both governments face a standing compliance tax — the arc here runs from state AG letters through the FTC settlement to this probe and eventually Zoom's $18M offer to settle the SEC case four years later, suggesting multi-year, multi-agency oversight becomes the norm for companies with China exposure.
The trend: US-China tension is turning cross-border data handling and government contacts into a permanent regulatory liability for American software companies, enforced agency by agency rather than by any single ruling.