
What Is Zoom Bombing? Definition and Prevention Tips
You’re running a book club meeting, a town hall, or a work training session through Zoom when suddenly a stranger’s face pops up, a hateful slur is typed into the chat, and your screen is taken over by pornography. That moment of violation—an uninvited intruder seizing control of a video call—is known as zoom bombing.
Term coined: 2020 · Common disruption type: Offensive screen sharing and audio · Primary platform targeted: Zoom
Quick snapshot
- Uninvited intrusion into a video call (Oregon Department of Justice)
- Disruptive content like porn or hate speech (West Yorkshire Police)
- Became common in 2020 (CISA / FBI guidance summary)
- Can be prosecuted under computer fraud laws (U.S. Department of Justice, U.S. Attorney’s Office for the Eastern District of Michigan)
- Some states have specific anti-zoombombing laws (Oregon Department of Justice) (U.S. Department of Justice, U.S. Attorney’s Office for the Eastern District of Michigan)
- Penalties include fines and imprisonment (U.S. Department of Justice, U.S. Attorney’s Office for the Eastern District of Michigan) (U.S. Department of Justice, U.S. Attorney’s Office for the Eastern District of Michigan)
- Use meeting passwords and waiting rooms (University of California, Irvine Office of Information Technology)
- Disable screen sharing for attendees (University of California, Irvine Office of Information Technology) (University of California, Irvine Office of Information Technology)
- Lock meetings after all participants arrive (CISA / FBI guidance summary) (University of California, Irvine Office of Information Technology)
- Ongoing legal crackdown across multiple states (U.S. Department of Justice, U.S. Attorney’s Office for the Eastern District of Michigan)
- Platform security features continue to evolve (University of California, Irvine Office of Information Technology)
- User awareness remains the strongest defense
The table below outlines key dimensions of zoom bombing, from its origin to legal response.
| Fact | Value | Source |
|---|---|---|
| First major incidents | 2020 | CISA / FBI guidance summary |
| Typical disruption method | Offensive screen share | West Yorkshire Police |
| Primary platform | Zoom | — |
| Legal action examples | Federal charges under CFAA, state laws in Michigan, New York | U.S. Department of Justice, U.S. Attorney’s Office for the Eastern District of Michigan |
What does zoom bombing mean?
Zoom bombing is the unwanted, disruptive intrusion into a video-conference call by an uninvited participant, often with the intent to harass, shock, or offend attendees. The Oregon Department of Justice defines it as a situation where an uninvited person enters a meeting without permission. The FBI’s guidance treats it as a form of video-teleconferencing hijacking, and West Yorkshire Police describes the intrusion as typically involving offensive or explicit images.
“[A] situation where an uninvited person enters a meeting without permission.”
Oregon Department of Justice
“[T]he intrusion typically involves offensive or explicit images.”
West Yorkshire Police
What is Zoom Bombing?
The term zoom bombing emerged in early 2020 as the COVID-19 pandemic forced millions of people onto video calls for work, school, and social gatherings. The University of California, Irvine Office of Information Technology explains that uninvited participants gain access when meeting settings are left open. What started as isolated trolling quickly became a widespread nuisance.
The speed with which zoom bombing normalized—going from a prank to a recognized harassment vector in weeks—forced platform developers and law enforcement alike to catch up fast. The gap between technical response and user awareness continues to shape how safe public meetings actually feel.
University of California, Irvine Office of Information Technology notes that typical disruptions involve offensive screen sharing, hate speech, and obscene audio. The cost of a single incident can be significant: a school district, government committee, or therapy group that gets bombed loses not just a meeting but trust in the platform itself.
The implication: zoom bombing is not just a technical glitch—it is an intentional act of disruption that exploits open access by default, and its legal and social consequences depend heavily on where it happens and whom it targets.
Is zoom bombing illegal?
Whether zoom bombing breaks the law depends on jurisdiction, the content displayed, and the intent behind it. At the federal level, the U.S. Department of Justice, U.S. Attorney’s Office for the Eastern District of Michigan warned in April 2020 that teleconference hijacking can lead to state or federal charges, including disrupting a public meeting, computer intrusion, using a computer to commit a crime, hate crimes, fraud, or transmitting threatening communications.
Is Zoom bombing a crime?
In many cases, yes—but with nuance. The Oregon Department of Justice says zoom bombing may be a crime if explicit, specific, and imminent threats are made. Otherwise, the Oregon DOJ treats it as a non-criminal bias incident under state law—still harmful, but prosecuted differently. The Michigan warning emphasized that fines and imprisonment are potential outcomes.
- The Computer Fraud and Abuse Act (CFAA) can apply when an intruder accesses a meeting without authorization.
- State-specific hate crime or harassment statutes add layers depending on the nature of the disruption.
- New York and other states have considered or enacted legislation specifically targeting zoom bombing.
State attorneys general can prosecute some zoom bombings as crimes, but the threshold for what meets “imminent threat” leaves many victims without a criminal resolution. The result: platform reporting tools often carry more immediate weight than the legal system.
What this means: the legal landscape is patchwork. A zoom bomber who flashes hate symbols in Oregon may face a bias-incident report; the same act in Michigan could trigger a felony computer-intrusion charge. For hosts of public meetings, the safest bet is to assume the legal system will act slowly, and design security accordingly.
How do you stop zoom bombing?
Preventing zoom bombing is far easier than dealing with its aftermath. The CISA / FBI guidance summary lists a set of controls that, when applied together, block the vast majority of unauthorized entries. The key is not to rely on a single setting but to layer them.
How to prevent Zoom bombing?
- Require a meeting password for every session. The University of California, Irvine Office of Information Technology recommends unique meeting IDs and strong passwords for each meeting.
- Enable the waiting room feature to screen participants before admission. The UCI Office of Information Technology stresses this as a frontline defense.
- Restrict screen sharing to the host only. This single setting prevents a bomber from taking over the visual feed. The UCI OIT lists it as non-negotiable for public meetings.
- Lock the meeting once all expected participants have joined. This stops late-arriving intruders.
How to get rid of a Zoom bomber?
If a bomber gets in despite precautions, swift action limits the damage. The West Yorkshire Police advises victims to report the incident to the platform and, depending on the content, to local police. Follow these steps immediately:
- Click Security → Remove Participant to eject the intruder.
- Enable Mute All Participants to stop audio disruption.
- Use the Report function in Zoom to log the incident with the platform.
- Save the chat transcript and any screenshots as evidence.
How to deal with zoom bombing?
The human response matters as much as the technical one. For hosts of public meetings, announcing clear expectations at the start—listing the moderation tools being used—can deter casual intruders. The FBI/CISA guidance also stresses keeping videoconferencing software up to date as part of the defense.
The pattern: prevention is a process, not a toggle. The most secure meetings combine several controls, and the moments of greatest vulnerability are when a host forgets even one.
What are examples of zoom bombing?
Real incidents make the abstract problem concrete. During the peak of 2020, public lectures, school classes, and community meetings were repeatedly targeted. Oregon Department of Justice documents examples where intruders displayed pornography, shouted racial slurs, and typed hate speech into chat windows. The West Yorkshire Police confirms the pattern: offensive or explicit images are the most common form of disruption.
- A university lecture on race and law was bombed with white supremacist imagery.
- A middle school class had a meeting link shared on a public Discord server, leading to a stream of profanity.
- A town hall meeting for a local government was disrupted by someone mimicking a public official’s name.
The catch: if you search for meeting IDs online, automated tools and bots have been known to scan for unprotected Zoom links and pass them to troll groups. The problem is not just individual bad actors—it is the infrastructure that makes those actors feel untouchable.
Why do people do zoom bombing?
Motivations range from simple mischief to targeted harassment. Some perpetrators treat it as a prank—a way to get laughs from an online audience. Others use zoom bombing to make political or ideological statements. The CISA / FBI guidance does not analyze motive, but law enforcement actions suggest a spectrum from juvenile trolling to hate crimes.
- Trolling for attention: Live-streaming the disruption to an audience on platforms like Twitch or Discord.
- Political statements: Using a public meeting to broadcast slogans or symbols.
- Mischief: Bored individuals looking for an easy target.
- Automated tools: Bots that scan for non-password-protected meeting IDs.
The paradox: anonymity fuels the behavior, but the same anonymity makes it harder for law enforcement to identify every perpetrator. The result: a high-disruption, low-risk environment for the bomber—unless they get caught in one of the jurisdictions actively prosecuting these cases.
digitalrightslawyers.org, vertexlegal.org, en.wikipedia.org, lmc.org, lawfaremedia.org, astrill.com, nordvpn.com
Frequently asked questions
Can zoom bombing happen on other video platforms?
Yes. While the term “zoom bombing” specifically references Zoom, the same type of intrusion can happen on any video-conferencing platform—Google Meet, Microsoft Teams, Cisco Webex, and others—if meeting settings are left open. The FBI’s guidance applies broadly to video-teleconferencing hijacking.
What should I do immediately if a Zoom bomber appears?
Remove the participant using the Security menu, mute all participants, lock the meeting, and report the incident through Zoom’s reporting tool. Save evidence such as chat logs and screenshots, and contact local law enforcement if the content involved threats or hate speech.
Do I need to use a password for every Zoom meeting?
The University of California, Irvine Office of Information Technology recommends unique meeting IDs and strong passwords for each session. It is the single most effective prevention step you can take.
Is zoom bombing a felony?
Depending on jurisdiction and content, yes. Under the Computer Fraud and Abuse Act and state-level computer intrusion laws, zoom bombing can be prosecuted as a felony, particularly if it involves threats, hate speech, or unauthorized access to a government or educational meeting.
How common is zoom bombing today?
Exact numbers are not systematically tracked, but public awareness and platform security improvements have reduced its visibility. However, the practice persists—especially in open, non-password-protected public meetings.
Does Zoom have built-in reporting tools?
Yes. Zoom provides a reporting function within the app that logs the incident details. West Yorkshire Police advises victims to report to the platform first and then to local police if the content warrants legal action.