In April 2020, cybersecurity firm Cyble said it had purchased around 530,000 Zoom accounts from a hacker on the dark web, a story first reported by BleepingComputer. The accounts were listed on hacker forums for less than a penny each, and some were given away for free. Most of them were gathered through credential stuffing attacks, where hackers reuse login details stolen from older data breaches. This guide explains what happened, why it still matters in 2026, and how to keep your Zoom account safe.
What Happened in the 2020 Zoom Account Leak
Cyble, a cybersecurity firm that monitors dark web activity, said it started seeing Zoom accounts for sale around April 1, 2020. The company bought the accounts in bulk to warn its customers about the threat. Cyble reported paying less than $0.0020 per account, which means the entire batch cost only a few hundred dollars.
The leaked data included email addresses, passwords, and in some cases the six-digit meeting PIN assigned to users hosting Zoom meetings. Hackers shared these records through text-sharing sites. Buyers used them for Zoom-bombing pranks, spam, and other suspicious activity during the early pandemic surge in video calls.
How Hackers Got the Accounts
The accounts were not obtained by breaking into Zoom’s own servers. Instead, attackers used credential stuffing. They took email and password combinations leaked from other sites and tried them against Zoom, banking on the fact that many people reuse the same password everywhere. Any account that matched was collected and added to the dark web listings.
This is why a single strong password is not enough. If the same password protects your Zoom login, your bank, and your email, one breach anywhere can expose all of them. A password manager that generates a unique password for every service is the simplest fix.
Why It Still Matters in 2026
Credential stuffing remains one of the most common attack methods years later, and video calling is now a permanent part of work and school. Compromised meeting credentials can still lead to Zoombombing, where uninvited people crash a meeting and disrupt it with offensive content.
The 2020 incident also showed how quickly stolen credentials spread. Similar account dumps have hit other platforms, including the 1.6 lakh Nintendo accounts that were hacked. The lesson from every one of these events is the same: treat reused passwords as an active risk and enable two-factor authentication wherever you can.
How to Check If Your Zoom Account Was Exposed
Start by checking your email address against breach databases. Have I Been Pwned and Cyble’s own AmIBreached service both let you search for free. If your email shows up in any breach, change the password on every site where you used the same combination.
You should also watch for phishing emails that try to look like official Zoom messages. These emails often ask you to click a link and enter your login details, which is exactly how more accounts end up on the dark web. Our guide to the three common Zoom phishing emails explains how to spot them.
How to Protect Your Zoom Account in 2026
Use a unique, strong password for Zoom and store it in a password manager. A good password combines letters, numbers, and symbols, and it should never be reused anywhere else. Enable two-factor authentication in Zoom settings so a stolen password alone is not enough to get in.
Turn on meeting passwords and enable the waiting room for every meeting you host. Keep your Zoom app updated, since the company regularly ships security patches. If you get a suspicious email that claims to be from Zoom, do not click the links, and report it through the official support channels. The same habits that stop spam email overload also protect you from account takeover attempts.
Finally, review the devices and sessions attached to your account periodically, and sign out of anything you do not recognize. If you prefer to move away from Zoom entirely, our roundup of the best alternatives to Zoom lists the top options with their platforms and pricing.
Zoom Account Security FAQ
Were the 530,000 Zoom accounts hacked from Zoom itself? No. The accounts were collected through credential stuffing, which reuses passwords leaked from other sites. Zoom’s own systems were not breached in this incident.
How much did the Zoom accounts sell for? Cyble reported buying accounts for less than $0.0020 each, and some were shared for free on hacker forums.
How can I check if my Zoom account was leaked? Search your email address on Have I Been Pwned or AmIBreached. If it appears in any breach, change your passwords immediately.
Does two-factor authentication stop credential stuffing? Yes. Even if attackers have your password, they cannot log in without the second factor, which makes stolen password lists far less useful.
