How to Prevent Zoom Bombing: 12 Settings That Secure Your Video Calls
To prevent zoom bombing, you need three layers, not one: gated entry (approval or a waiting room), a meeting link you never publish, and participant permissions locked down before anyone joins. Research covering more than 200 hijacked calls found that passwords alone do not stop raids, because the link usually leaks from someone you invited.
That last finding is the part most security checklists skip. The standard advice — set a passcode, turn on the waiting room — treats zoom bombing as the work of outsiders who guessed a nine-digit number. The evidence points somewhere less comfortable: the person who let them in was already on your invite list.
This guide walks through the settings that genuinely reduce risk, the ones that only feel productive, and what to do in the 30 seconds after a stranger starts sharing their screen.
Table of Contents
- What Zoom Bombing Looks Like in 2026
- Where Zoom Bombing Attacks Actually Come From
- The 12 Settings That Stop Zoom Bombing
- Link Hygiene: The Habit That Beats Every Setting
- What to Do in the First 30 Seconds of a Raid
- Encryption, Explained Without the Jargon
- The 2026 Problem Settings Cannot Fix
- Building Security Into Your Default Setup
- Frequently Asked Questions
What Zoom Bombing Looks Like in 2026
The term dates to spring 2020, when the FBI's Boston field office warned that strangers were hijacking classrooms and public meetings to broadcast pornography and threats. CISA republished that guidance for defending against VTC hijacking on 2 April 2020, and every major platform tightened its defaults over the following months.
Six years later the loud version of zoom bombing has faded, but three quieter variants keep showing up:
- Disruption raids. A group joins mid-session, shares shock imagery or shouts over the speaker, then leaves. Schools, town halls, support groups and open community calls absorb most of these.
- Silent listeners. Someone joins with a camera off and a plausible name, says nothing, and stays for the pricing discussion. Nobody notices because nobody counts the tiles.
- Impersonation. An attacker appears as a colleague — sometimes with a synthetic face and voice — and asks for a payment, a password reset or a file.
That shift changes what "secure" has to mean. Defending against classic zoom bombing is a moderation problem: you need fast controls and a calm host. Defending against a silent listener or an impersonator is an access problem: you need to know who is in the room and why they belong there. The settings below cover both, which is why the order matters more than the length of the list.
Where Zoom Bombing Attacks Actually Come From
Researchers at Binghamton University and Boston University analysed more than 200 calls targeted during the first seven months of 2020 and published their results at IEEE Security & Privacy in 2021. Their conclusion cuts against the usual advice: zoom bombing rarely starts with a brute-forced meeting ID. Instead, someone with a legitimate invitation — often a student — posts the link on a public forum and asks strangers to come ruin the session.
The timing data makes the point sharply. The study found that 93% of the 4chan posts and 98% of the Twitter posts calling for a raid appeared while the meeting was already running. These were live invitations to an event in progress, not the product of patient reconnaissance. Assistant Professor Jeremy Blackburn summarised the work in three words: "Passwords don't work."
Insiders also coach the intruders. They share the passcode along with the link and tell arrivals to use the names of real participants, which defeats a host who is scanning the waiting room for anything unfamiliar.
Three practical consequences follow:
- A passcode protects against strangers, not against your own attendees. Treat it as a floor, never as the plan.
- Admission control needs a rule, not a vibe. "Does this name look plausible?" fails the moment someone borrows a classmate's name.
- The most valuable settings are the ones that limit what any participant can do, because they hold even after an intruder gets in.
The 12 Settings That Stop Zoom Bombing
Every platform labels these differently, but the underlying controls are the same. Work down the list in order — the top rows do the most work.
| # | Setting | What it stops | Best for |
|---|---|---|---|
| 1 | Host-only screen sharing | Shock imagery, hijacked presentations | Every meeting |
| 2 | Waiting room or join approval | Unknown names entering unnoticed | Classes, public events |
| 3 | Lock the room after the start | Late arrivals from a forwarded link | Board, HR, client calls |
| 4 | Unique link per meeting | Old links reused months later | Every meeting |
| 5 | Passcode kept out of public posts | Casual drive-by joining | Every meeting |
| 6 | Mute participants on entry | Audio raids and background chaos | Groups over 10 |
| 7 | Disable participant renaming | Impersonation of real attendees | Classes, town halls |
| 8 | Restrict private chat and file transfer | One-to-one harassment, malware links | Classes, support groups |
| 9 | Block removed participants from rejoining | Repeat disruption in the same session | Public events |
| 10 | Require sign-in for sensitive sessions | Anonymous attendance at internal calls | Internal, regulated calls |
| 11 | Record only with announced consent | Unlawful or unexpected recordings | Any recorded call |
| 12 | Join in a browser or keep clients patched | Exploits against outdated software | Every meeting |
Screen sharing sits at the top for a reason. A stranger who joins a locked-down meeting is a nuisance. A stranger who can share their screen becomes an incident that ends up in a complaint, a news story or a safeguarding report. Set sharing to host-only by default and grant it to individuals during the call when you need to.
Waiting rooms buy attention, not certainty. For a ten-person client call, the waiting room works: you know every name. For a 200-person webinar, it becomes theatre — nobody vets 200 entries in real time. Larger events need registration or sign-in requirements instead, so the platform does the vetting.
Locking the room is the underused one. Once everyone has arrived, a lock makes the link worthless for the rest of the session. It costs one click and it neutralises the exact scenario the research describes — an attendee sharing the link mid-meeting.
Renaming deserves more attention than it gets. When intruders can rename themselves, they adopt the identity of a real participant and buy several minutes of confusion. Turning renaming off keeps the participant list trustworthy, which matters even more if you moderate a room in a language you do not speak.
For the deeper platform-by-platform view of which providers enforce these controls by default, our comparison of the most secure video conferencing platforms scores them on encryption, data location and admin defaults.
Link Hygiene: The Habit That Beats Every Setting
Settings live in a menu. Link hygiene lives in your habits, and it prevents more zoom bombing than any toggle.
Start by retiring your personal meeting room for anything but internal one-to-ones. A personal room uses one permanent address, so every person who has ever joined keeps a working key to every future meeting. Generate a fresh link per meeting instead.
Next, separate the invitation from the credential. Put the link in the calendar invite and the passcode somewhere the recipient already has to authenticate — your chat tool, the learning platform, the ticket confirmation. Anyone forwarding the invite then forwards only half of what an intruder needs.
Watch the calendar layer itself. Calendar invites now carry real risk of their own: attackers send crafted invitations that pass SPF, DKIM and DMARC checks because a legitimate calendar service sent them. Keep your calendar private rather than public, strip meeting links out of event titles, and treat an unexpected invite the way you treat an unexpected attachment.
Finally, think about where the link ends up after the meeting. Screenshots of a call, a slide with the joining details, a support ticket, a recording of the moment someone shares their screen with the invite still open — each one leaks a working address. Our guide to setting up an online meeting covers the invite workflow end to end, including what belongs in the calendar entry and what does not.
What to Do in the First 30 Seconds of a Raid
Under pressure, hosts type into the chat and argue with the intruder. That is exactly the reaction a raid wants. Work the controls instead, in this order:
- Cut their reach. Stop the screen share and mute everyone. One click each in the security or participants panel.
- Remove the account and block the rejoin. Removing without blocking gets you the same person back in fifteen seconds under a new name.
- Lock the room. No one else joins after this point, whoever holds the link.
- Say what happened. One calm sentence to your participants — "someone joined who should not have; I have removed them" — prevents the rumour version.
- Decide: continue or restart. For a class or a public session with children present, end the session and reissue a fresh link. For an internal meeting, continuing is usually fine.
- Report and record. Note the display name, the join time and any content shared, and report the account to the platform's trust and safety team.
Encryption, Explained Without the Jargon
Security marketing muddles two different guarantees, and the difference decides what a compromised server can reveal.
Transport encryption protects the connection. Every browser-based call rides on WebRTC, which makes encryption mandatory: media travels over DTLS-SRTP, and the specification provides no way to switch it off. Nobody on your café Wi-Fi or your ISP's network sees your video. The provider's server, however, decrypts media in order to mix, record or transcribe it.
End-to-end encryption (E2EE) keeps the keys on the participants' devices. The forwarding server relays packets it cannot read. This is the stronger guarantee, and it comes with a trade-off worth understanding: because the server cannot see the content, server-side features that depend on reading it — cloud recording, some transcription pipelines — either switch off or move onto the participants' devices.
Ask a provider two questions rather than one: is the call encrypted in transit, and who holds the keys? A confident answer to the second question tells you more than any badge on a pricing page. Meeyra's security page sets out how calls stay encrypted, why audio processed for live translation is discarded rather than stored, and what the host controls.
The compliance dimension follows the same logic. Recording turns a transient meeting into a stored personal-data set, with retention, access and consent obligations attached. Our guide to GDPR-compliant video conferencing works through data location, processing agreements and consent requirements in detail.
The 2026 Problem Settings Cannot Fix
Waiting rooms assume you can recognise the people you invited. That assumption now has a crack in it.
In a Gartner survey of 302 cybersecurity leaders across North America, EMEA and Asia/Pacific, 62% of organisations reported at least one deepfake attack in the previous twelve months — a category that includes impersonating someone during a video or audio call. The best-documented case involved the engineering firm Arup: a finance employee in Hong Kong joined a video call with what appeared to be the CFO and several familiar colleagues, and approved 15 transfers totalling roughly $25 million. Every other participant on that call was synthetic.
No meeting setting prevents this, because the attacker arrives through the front door with a valid invitation. Process does the work instead:
- Never approve money or credentials inside a single call. Confirm through a second channel you initiated — a phone number you already had, not one from the meeting.
- Agree on a verification phrase for finance and admin requests, and expect it whenever urgency appears.
- Treat urgency plus secrecy as the signal. "Do not tell anyone, we need it today" is the constant across these cases.
- Ask an unscripted question. Real colleagues answer trivial specifics instantly; a live impersonation stumbles.
Building Security Into Your Default Setup
The hosts who never deal with a raid are not the ones with the longest checklists. They are the ones whose defaults already sit in a safe position, so the secure choice needs no decision at meeting time.
Almost everything that makes zoom bombing possible traces back to a default nobody changed. Spend ten minutes in your account settings today. Set screen sharing to host-only, turn off participant renaming, disable private chat, require a fresh link per meeting, and switch on approval for external guests. Those five defaults cover the majority of what goes wrong, and they apply to every meeting you schedule from now on without another thought.
Then add the two habits: lock the room once everyone has arrived, and keep the passcode out of anything public. If your calls involve participants across languages, choose a platform where the security controls and the translation both work in the browser — Meeyra runs encrypted calls with live AI translation in 42+ languages, so nobody has to install a client and the host keeps control of who joins, what gets shared and whether anything is recorded. Create a free account and set your defaults once.
Frequently Asked Questions
Can someone join my meeting without the link?
Randomly guessing a valid meeting ID is possible in principle but rare in practice, and platforms now rate-limit that behaviour. In documented cases the intruder had the real link, forwarded or posted publicly by someone who was invited. Protect the link and you remove the common path.
Does a meeting passcode stop zoom bombing?
Only partially, and the gap matters. A passcode blocks casual drive-by joining, but the Binghamton and Boston University research found that insiders posting raid invitations usually included the passcode alongside the link. Combine the passcode with a locked room and host-only screen sharing.
Is a waiting room enough for a large webinar?
No. Vetting works when you recognise the names, which stops being realistic past roughly 30 attendees. For larger audiences, use registration or a sign-in requirement so the platform verifies attendees, and rely on participant restrictions rather than on the door.
Are browser-based video calls less secure than desktop apps?
Not inherently. WebRTC makes media encryption mandatory in every compliant browser, and browsers update themselves, which removes the unpatched-client risk that affects installed software. The provider's architecture and host controls matter far more than the delivery format.
What should I do if someone records my meeting without permission?
Announce the recording rules at the start, disable participant recording where the platform allows it, and treat any unauthorised recording as a data protection incident: document what was captured, notify the people affected, and report it to your data protection officer if personal data was involved.
How do I secure a meeting where participants speak different languages?
Apply the same controls — host-only sharing, no renaming, restricted chat — and choose a platform with built-in live translation so you can follow what participants say and write. Moderating a room through a third-party interpreter tool leaves gaps exactly where you need visibility.