Choice can get this wrong — tell us if something's off.
1–12 of 12
Corporate conductSettlementAgainst
Zoom had its shared screens hijacked by attackers
Zoom has also come under fire for security flaws, including a vulnerability that allowed an attacker to remove attendees from meetings, spoof messages from users and hijack shared screens.
Zoom has also come under fire for security flaws, including a vulnerability that allowed an attacker to remove attendees from meetings, spoof messages from users and hijack shared screens.
Zoom settles US class action privacy lawsuit for $86m
Privacy & surveillanceRulingAgainst
The Federal Trade Commission required Zoom to enhance its security practices as part of a settlement
FTC Requires Zoom to Enhance its Security Practices as Part of Settlement.
The FTC says pandemic staple Zoom misled users about its end-to-end encryption.
"Zoom’s security practices didn’t line up with its promises, and this action will help to make sure that Zoom meetings and data about Zoom users are protected.”
Zoom settles with FTC over allegations of 'deceptive' security practices
Zoom settles with FTC over allegations of 'deceptive' security practices - ABC News
Zoom Video Communications is facing increased scrutiny over customer privacy this month as New York's top prosecutor is probing the suddenly popular teleconferencing company's security practices during the coronavirus work-from-home movement.
Lawsuit: Zoom illegally sold users' personal data - CBS News
In addition, the FTC charges that Zoom’s installation of the ZoomOpener unfairly circumvented third-party privacy and security safeguards and that Zoom deceptively failed to give consumers the full scoop about the ZoomOpener.
According to a just-announced FTC complaint, Zoom allegedly engaged in deceptive and unfair practices that misled consumers about the security of their communications on the platform and that put certain users at risk when the company undermined a security feature built into the Safari browser.
The proposed administrative complaint alleges Zoom violated the FTC Act by making deceptive end-to-end encryption claims, false promises about the level of encryption it provided, and misleading representations regarding secured cloud storage for recorded meetings.
Zoom Video Communications, Inc. will be required to implement a robust information security program to settle FTC allegations that the video conferencing provider engaged in a series of deceptive and unfair practices that undermined the security of its users.
FTC Requires Zoom to Enhance its Security Practices as Part of Settlement
PRESS RELEASE: FTC Gives Final Approval to Settlement with Zoom over Allegations the Company Misled Consumers about Its Data Security Practices
“Zoom’s security practices didn’t line up with its promises, and this action will help to make sure that Zoom meetings and data about Zoom users are protected.”
Zoom’s misleading claims gave users a false sense of security, according to the FTC’s complaint, especially for those who used the company’s platform to discuss sensitive topics such as health and financial information.
FTC Requires Zoom to Enhance its Security Practices as Part of Settlement
The complaint also alleges that Zoom’s release notes for the July 2018 update were deceptive because they did not adequately disclose that the app update would install the ZoomOpener web server on users’ computers, that it would circumvent a Safari browser safeguard, or that it would remain on users’ computers even after users deleted the Zoom app.
In its complaint, the FTC alleged that, since at least 2016, Zoom misled users by touting that it offered “end-to-end, 256-bit encryption” to secure users’ communications, when in fact it provided a lower level of security.
In reality, the FTC alleges, Zoom maintained the cryptographic keys that could allow Zoom to access the content of its customers’ meetings, and secured its Zoom Meetings, in part, with a lower level of encryption than promised.
FTC Requires Zoom to Enhance its Security Practices as Part of Settlement | Federal Trade Commission
FTC Gives Final Approval to Settlement with Zoom over Allegations the Company Misled Consumers about Its Data Security Practices | Federal Trade Commission
FTC Requires Zoom to Enhance its Security Practices as Part of Settlement
The program also requires Zoom to implement specific privacy safeguards, such as implementing data deletion policies, procedures, and technical measures; limiting access to consumers’ personal information to only those employees who need such access to perform their job; using a default, randomized naming convention for saving recorded meetings; and implementing policies, procedures and technical measures to reduce the risk of third parties using users’ log-in credentials without authorization.
For example, it requires Zoom to implement data deletion policies, procedures, and technical measures; limit access to consumers’ personal information to only those employees who need such access to perform their job; use a default, randomized naming convention for saving recorded meetings; and implement policies, procedures and technical measures to reduce the risk of third parties using users’ log-in credentials without authorization.
Zoom’s conduct may have violated key aspects of the framework, and I believe the Commission should have taken action accordingly. The Commission should now fully cooperate with our international partners to ensure that they can proceed with appropriate sanctions. 7. Determine whether third-party assessments are effective. A common provision in FTC orders requires the defendant to retain a third party to monitor compliance and the company’s data protection protocols. However, it is unclear whether those assessments are truly effective when it comes to deterring or uncovering misconduct. For example, in the FTC’s investigation of Facebook for compliance with its privacy obligations under a 2012 Commission order, the FTC alleged major violations of the order even though an independent third party, PriceWaterhouseCoopers (PwC), was supposedly watching over the company’s compliance.28 27 Press Release, Fed.
For example, it prohibits Zoom from misrepresenting its privacy practices, and requires Zoom to implement changes to its naming procedures for saving or storing recorded videoconference meetings, and to develop data deletion policies and procedures.
February 1, 2021 Today the Commission finalizes a settlement with Zoom addressing allegations that it made misrepresentations regarding the strength of its security features and implemented a software update that circumvented a browser security feature.
Corporate conductAllegationAgainst
New York's top prosecutor is probing Zoom's security practices
Zoom Video Communications is facing increased scrutiny over customer privacy this month as New York's top prosecutor is probing the suddenly popular teleconferencing company's security practices during the coronavirus work-from-home movement.
Zoom Video Communications is facing increased scrutiny over customer privacy this month as New York's top prosecutor is probing the suddenly popular teleconferencing company's security practices during the coronavirus work-from-home movement.
Lawsuit: Zoom illegally sold users' personal data - CBS News
Privacy & surveillanceSettlementAgainst
Zoom settles $85 million privacy lawsuit
Zoom agreed to pay $85 million to settle claims it shared user data with Facebook, Google, and LinkedIn without permission.
$25 Zoom Settlement Via New Class-Action Lawsuit: Do You Qualify?
The settlement comes as a result of an $85 million class-action suit in which Zoom denies allegations — or attached liability — surrounding claims of improperly sharing personal user information and holding lax security protocols.
According to the lawsuit, Zoom was sharing personal data with Facebook Inc (NASDAQ: FB), Alphabet Inc's (NASDAQ: GOOGL) Google, and Linkedin, and letting hackers disrupt Zoom meetings in a practice called "Zoombombing."
Zoom Video Communications Inc (NASDAQ: ZM) has agreed to pay $85 million to settle a lawsuit claiming it violated users' privacy rights, Reuters reports.
Zoom Reaches $85M Settlement In Lawsuit Over User Privacy
Zoom agreed to pay $85 million to settle the lawsuit alleging that it shared people's personal information with Facebook, Google and LinkedIn without permission — and allowed hackers to break into virtual meetings in a practice known as “Zoombombing” as the platform skyrocketed in popularity during the pandemic.
You might be eligible to get some cash from Zoom due to a class action settlement around its privacy practices during the pandemic.
Zoom has agreed to pay $85 million to settle a lawsuit claiming the company violated users’ privacy rights by sharing their personal information with Facebook, Google and LinkedIn without their permission, and allowing hackers to interrupt virtual meetings by “Zoombombing.”
Zoom reaches $85 million settlement in privacy and 'Zoombombing' lawsuit - CNET
The settlement compensates Zoom users for the consideration (either subscription payments or access to their personal data) that they would not have otherwise given to Zoom.60 Indeed, the court dismissed the plaintiffs’ negligence cause of action, as it pertained to emotional distress caused by Zoombombing.61 As explained above, the recoveries here are adequate to justify approval.
The Request for Exclusion must be received by the Claims Administrator by the Objection and Exclusion Deadline, hereby set as March 5, 2022: Claims Administrator In re: Zoom Video Communications, Inc. Privacy Litigation ATTN: Claims Administrator Address City State Zip Any member of the Settlement Class who does not file a valid and timely Request for Exclusion shall be bound by the terms of the Settlement Agreement upon entry of the Final Approval Order. Final Approval Hearing 21. The Final Approval Hearing shall be held by the Court on April 7, 2022, beginning at 1:30 p.m., in Courtroom 8, 4th Floor, of the United States District Court for the Northern District of California, 280 South 1st Street, San Jose, CA 95113.
Zoom has agreed to an $85 million settlement for a class action lawsuit that accused the company of improperly sharing user data through third-party software integrations with various digital platforms.
“Although plaintiffs firmly believe their liability case is strong and that class certification is warranted, it is uncertain whether the court ultimately would grant certification, deny a motion for summary judgment filed by Zoom, or ever find that plaintiffs are entitled to damages,” the plaintiff’s lawyers added.
Zoom to pay $85m to set aside privacy violation and zoombombing allegations - ZDNET
Speech & moderationAllegationYou decide
Zoom is accused of refusing to host a Palestinian activist speech
Zoom is accused of refusing to host a speech by a controversial Palestinian activist, citing its company policy.
And just as social media companies draw critics' ire when they flag a post or ban a user, Zoom is now being accused of censorship after refusing to host a speech by a controversial Palestinian activist.
Corporate conductAllegationAgainst
Zoom is accused of sharing data
Zoom is accused of sharing data, facing a class action lawsuit.
BACKGROUND AND PROCEDURAL HISTORY Zoom Flume is a seasonal water park located in East Durham, New York.2 In July 2022, the United States Department of Labor’s Wage and Hour Division (WHD) opened an investigation into Zoom Flume’s employment of minor workers, covering the period of July 9, 2020, through July 8, 2022.3 WHD’s investigation revealed that during the two-year investigatory period, 35 15-year-olds worked as dispatchers at the top of Zoom Flume’s elevated water slides.4 The water slides ranged in height from 12 to 44 feet and used electric pumps to convey water to the top of the slides, which then powered riders’ descents down the slide.5 Although the water slides were powered by a pump system, there was no machinery or equipment located at the top of the water slides where the 15-year- olds worked as dispatchers.6 As dispatchers, the minors monitored the line of riders, told riders when they could enter the slides’ towers, instructed riders how to go down the slides, helped riders into flotation devices at the top of certain slides, dispatched riders down the slides, kept order at the top of the slides, and notified supervisors of problems with the slides.7 Not all of the minors working as dispatchers were certified as 2 ALJ Order at 3.
On February 13, 2024, a United States Department of Labor Administrative Law Judge (ALJ) issued an Order Denying Respondent’s Motion for Summary Decision and Granting Administrator’s Motion for Summary Decision (ALJ Order), ruling that Zoom Flume violated the child labor laws and ordering it to pay $38,010 in civil money penalties (CMPs).
Speech & moderationConfirmedYou decide
Zoom CEO Eric Yuan promotes free speech
Zoom CEO Eric Yuan stated 'We’ll do all we can to promote free speech' in response to criticism over encryption and privacy.
‘We’ll Do All We Can to Promote Free Speech,’ Says Zoom CEO Eric Yuan After Criticism on Encryption and Privacy"
Privacy & surveillanceConfirmedYou decide
Eric Yuan raises alarm over Zoom's encryption plans
Eric Yuan, Zoom's CEO, raised alarm by stating Zoom planned to exclude free calls from end-to-end encryption to allow potential cooperation with law enforcement.
Eric Yuan, the company’s CEO, raised alarm among privacy advocates on Wednesday by saying Zoom planned to exclude free calls from end-to-end encryption so as to leave open the possibility of working with law enforcement.
Privacy & surveillanceConfirmedAgainst
Zoom discloses all material facts
Zoom is required to disclose all material facts to the assessor.
Part IV of the agreement requires Zoom to disclose all material facts to the assessor and prohibits Respondent from misrepresenting any fact material to the assessments required by Part III.
Part VI requires Zoom to submit a report to the Commission of its discovery of any Covered Incident.
Corporate conductRulingAgainst
Russian court fines Zoom $965,779
A Russian court fined Zoom 79.6 million roubles, equivalent to $965,779, for failing to comply with legal requirements for foreign entities in Russia.
(Reuters) -A Russian court has fined Zoom Communications 79.6 million roubles ($965,779) for failing to comply with legal requirements governing foreign entities operating in Russia's internet space, the Moscow courts press service said on Tuesday.
(Reuters) -A Russian court has fined Zoom Communications 79.6 million roubles ($965,779) for failing to comply with legal requirements governing foreign entities operating in Russia's internet space, the Moscow courts press service said on Tuesday.
Workplace equityConfirmedYou decide
Zoom lays off DEI team
Zoom laid off its DEI team, cutting back on diversity and inclusion initiatives.