Anyone else asked to get on a Zoom call and the link secretly installs surveillance software? | Community
Skip to main content
New Member
July 1, 2026
Question

Anyone else asked to get on a Zoom call and the link secretly installs surveillance software?

  • July 1, 2026
  • 2 replies
  • 40 views

Hi, I own a small dog training business and I have a website wherein people can email me. I offer a free in-home consultation to dog guardians who live within a particular boundary in my area. In the last week and a half, two different people have emailed me, asking for a Zoom consultation to evaluate their dogs for training. Both emails were worded similarly and didn’t mention their dogs’ names, breeds or ages. Each time I clicked on the links they sent, I could never get connected. The second person who wanted a Zoom consultation sent me a link in which I tried for hours to get connected. I finally looked up the link and it secretly installs surveillance software on a laptop or desktop computer. I’m relieved that my laptop didn’t connect using the link because I would have unknowlingly allowed someone to spy on me.

Has anyone else experienced this? How did you resolve it? Thank you in advance.​​​

    2 replies

    mudasir123
    Newcomer
    Newcomer
    July 2, 2026

    This is a highly dangerous, well-known Cybersecurity Phishing Scam targeting small businesses. Hackers use fake Zoom look-alike links to deliver Info-Stealers or Remote Access Trojans (RATs).

    Since you clicked the link and tried for hours, even if it didn't look like it connected, the background script might have successfully executed in your browser cache.

    Immediate Action Plan to Secure Your Laptop:

    1. Run a Malware Scan: Immediately download and run a deep scan using Malwarebytes (Free version) and Windows Defender to detect any hidden surveillance payloads.

    2. Clear Browser Data: Clear your entire browser history, cache, and cookies right away, as these links often utilize drive-by download vulnerabilities.

    3. Change Critical Passwords: Change passwords for your bank accounts, emails, and business dashboard—ideally from a different device (like your phone) until your laptop is proven clean.

    4. Future Safety Rule: Never click a Zoom link sent by the client. As the business owner, you should always generate the Zoom/Google Meet link from your own secure account and send it to them.

    Stay safe, you caught it just in time before worse damage

    Employee
    July 6, 2026

    HI ​@Debbie Tangen 

    I’m so sorry to hear that you’ve experienced this.

    Resolutions That Have Helped Others

    1. Stop and verify

      • Always hover over links before clicking; make sure the URL aligns with zoom.us or your account’s subdomain.
      • Instead of using the link in the email, launch the Zoom app manually or paste the Meeting ID to join securely.
    2. Check the sender’s details carefully

      • Confirm if the email truly comes from the person’s known business address, not a generic or spoofed address.
    3. Report & escalate

      • Mark suspicious emails as phishing/spam in your email client. If you have an IT or support team, alert them immediately.
    4. Reset credentials promptly if compromised

      • If you clicked a malicious link, change your Zoom password (and any other accounts that may be impacted) and enable MFA where possible.
    5. Implement layered security

      • Consider adding an email gateway that scans for malicious links, implement DNS or URL filtering, and deploy browser isolation to contain risks.
    6. Conduct training and awareness

      • Share phishing examples with staff or collaborators. Train everyone to spot red flags—urgent phrasing, mismatched domains, unexpected invites—before engaging.

    Yes—you're not alone. Small business owners—especially in service sectors—are being targeted with phishing emails containing malicious Zoom links. The tactics include urgency, deceptive links, and malware downloads. Effective defenses include verifying links, reporting suspicious messages, securing accounts with MFA, using email/URL filtering, and fostering security awareness. Many peers have successfully thwarted these threats by applying these strategies promptly.

    Appreciate your time in reporting this. Thank you!