Research finds most Zoom-bombing incidents, especially in high schools and colleges, originate with participants who post the link publicly to invite trolls in
Researchers have found that most calls to disrupt videoconferences originate with the participants, especially in high schools and colleges.
Context & Ripple Effects
When Zoombombing first surfaced in spring 2020, trolls were framed as outsiders exploiting Zoom's screen-sharing on public calls; by April, reporting showed thousands coordinating attacks through group chats, message boards, and social platforms. The new research closes the loop on how those attackers find their targets: not by hunting links themselves, but because insiders — disproportionately students in high schools and colleges — post them publicly to invite disruption.
That finding retroactively validates Zoom's defensive bet: its At-Risk Meeting Notifier, launched last November, scans the web for exposed meeting links precisely because leaked links are the attack vector. If most leaks come from inside the meeting, though, scanning alone can't stop the first post.
First-order effects
- Schools and universities running classes over Zoom face a discipline problem more than a cryptography problem: the immediate fix is host-side controls like waiting rooms and locked meetings, plus consequences for students who share links.
- Zoom's At-Risk Meeting Notifier becomes a detection layer rather than prevention — it alerts organizers after a link is already out, so institutions must pair it with access rules that assume insiders will leak.
Second-order effects
- The coordinated Zoombombing networks documented in April 2020 depend on publicly posted links for target discovery; if hosts lock down sharing, those campaigns lose their supply chain and shift toward social engineering of participants instead.
- Competing videoconferencing vendors gain a selling point: defaults that don't rely on shareable public links become a differentiator against Zoom's original open-invite design.
Third-order effects
- Collaboration tools broadly are being pushed from a link-as-credential model toward authenticated, role-based access as the default — treating meeting invitations the way enterprises treat documents, with insider leakage as the primary threat model rather than outside hacking.
The trend: Videoconferencing security is shifting from blocking outside intruders to controlling insider behavior, as research shows the weakest link in meeting access is the invited participant.