IsThisAScam
Trang chủBlogBảng giáGiới thiệuHistoryAPIExtension
Upgrade
VI
Sign in
Sign in
IsThisAScam

Independent scam & phishing analysis. Free for individuals. APIs for developers.

© 2026 Zeplik, Inc.
1111B S Governors Ave, Dover, DE 19904
+1 (838) 221-7030
[email protected]
Sản phẩm
  • Home
  • Blog
  • Pricing
  • Giới thiệu
  • Methodology
  • History
  • Chrome Extension
Resources
  • Developers
  • Tài liệu API
  • Website trust reports
  • Scam type briefs
  • How-to guides
  • Scam glossary
  • Compare tools
  • Apple scams
  • PayPal scams
Pháp lý
  • Chính sách bảo mật
  • Điều khoản dịch vụ
  • [email protected]

© 2026 Zeplik, Inc. Mọi quyền được bảo lưu.

Built for the calm, the cautious, and the careful.

IsThisAScam is a Zeplik product. Explore our other tools: Arteza (AI image and video), OptiPix (privacy-first image tools).

Home/Blog/Scam Alerts
Scam Alerts

Fake Zoom Meeting Invitations: A New Phishing Technique

By IsThisAScam Research TeamPublished April 4, 20263 min read
Contents
  1. Fake Zoom Meeting Invitations: A New Phishing Technique
  2. What the Fake Invitation Looks Like
  3. Three Attack Vectors
  4. Red Flags to Watch For
  5. How to Safely Join Zoom Meetings
  6. After Clicking a Suspicious Link

Fake Zoom Meeting Invitations: A New Phishing Technique

The shift to remote and hybrid work created a permanent opening for phishing attacks disguised as meeting invitations. In January 2026, a coordinated campaign sent fake Zoom invitations to over 50,000 corporate email addresses in a single week. The emails were indistinguishable from real Zoom notifications to most recipients. Seventeen percent clicked the link. Of those, nearly half entered their credentials on the phishing page.

What the Fake Invitation Looks Like

The phishing email mimics Zoom's standard meeting invitation format:

"Hi,

James Wilson is inviting you to a scheduled Zoom meeting.

Topic: Q2 Planning Review
Time: Apr 4, 2026, 10:00 AM Eastern

Join Zoom Meeting
https://zoom.us/j/82341556789

Meeting ID: 823 4155 6789
Passcode: 847291"

Everything looks correct — the formatting, the meeting ID format, even the passcode. But the hyperlink behind the text doesn't actually point to zoom.us. It points to zoom-us-meeting.com or zoom.us.secure-join.net. The text displays the legitimate URL while the actual link goes elsewhere.

Three Attack Vectors

Credential theft. The link opens a page that looks like the Zoom web client, asking you to "Sign in to join this meeting." You enter your Zoom credentials, and they're captured. Since many organizations use SSO, your Zoom password may be the same as your corporate network credentials — giving attackers access to far more than just Zoom.

Got a suspicious email?

Paste it here for an instant analysis.

No signup · 6 detection layers · Results in seconds · Cmd+Enter

Malware installation. The phishing page displays a message: "This meeting requires the latest version of Zoom. Click here to update." The "update" is malware — typically an infostealer that captures passwords, browser cookies, and cryptocurrency wallets, or a remote access trojan that gives attackers persistent access to your computer.

Man-in-the-middle attacks. More sophisticated campaigns proxy the real Zoom login. You actually sign into Zoom through the attacker's server, which captures your session token. You join a real meeting (or see an error that the meeting ended), while the attacker now has an authenticated session to your Zoom account.

Red Flags to Watch For

You weren't expecting the meeting. If you receive a Zoom invitation for a meeting you don't remember being invited to, verify with the supposed host before clicking. This is especially important for invitations from people outside your organization.

The sender address is wrong. Real Zoom invitations come from [email protected]. Phishing versions come from lookalike addresses like [email protected] or [email protected] (with zeros instead of o's).

The join link doesn't match. Hover over the link before clicking. The displayed text might show zoom.us/j/82341556789, but the actual URL (visible in the bottom-left corner of your browser) points elsewhere. This is the single most reliable way to detect the scam.

It asks you to download something. If you click a meeting link and are told to install or update Zoom, stop. Open Zoom separately from your Applications folder or Start menu. If an update is genuinely needed, Zoom will prompt you to update through the app itself, not through a browser page.

It asks for credentials you shouldn't need. If you're already signed into Zoom and a meeting link asks you to sign in again, something is wrong. Real Zoom links open directly in the app or launch the web client using your existing session.

How to Safely Join Zoom Meetings

Instead of clicking links in emails, copy the Meeting ID and paste it into the Zoom app directly. Open Zoom, click "Join," enter the Meeting ID and passcode, and join from there. This bypasses any phishing links entirely.

If you use a calendar integration (Google Calendar, Outlook), joining through the calendar event is safer than clicking email links, because the calendar event was typically created by the real Zoom scheduling system.

For organizations, configure Zoom SSO so that authentication happens only through your identity provider. This means even if an employee clicks a phishing link and sees a fake Zoom login page, they'll recognize it's not the usual SSO login flow.

After Clicking a Suspicious Link

If you entered your Zoom credentials on a suspicious page, change your Zoom password immediately at zoom.us/profile. If you use the same password elsewhere, change those too. Enable two-factor authentication on your Zoom account. If you downloaded anything, disconnect from the network and run a full malware scan. Notify your IT team if this is a work account — the attacker may have already accessed meeting recordings, chat logs, or contact lists.

Meeting invitations are part of daily work life, and that's exactly why they make such effective phishing lures. Build the habit of verifying links before clicking, and join meetings through the app rather than through email links.

Received something suspicious? Check it now for free →

Related reading:

  • Payoneer Scams: How Freelancers Get Targeted
  • Is Temu Legit or a Scam? What Shoppers Should Know
  • Is Shein Legit or a Scam? An Honest Look
  • PayPal Invoice Scam: Why Real PayPal Emails Can Be Fraud

Received something suspicious? You can check if an email is a scam in seconds with our free 6-layer scanner. Read our full guide to phishing scams for tactics, examples, and reporting steps.

Share this article
XLinkedInFacebookWhatsApp
zoomphishingremote work
Related Articles
Guides4 min

Is Temu Legit or a Scam? What Shoppers Should Know

Guides4 min

Is Shein Legit or a Scam? An Honest Look

Scam Alerts4 min

PayPal Invoice Scam: Why Real PayPal Emails Can Be Fraud

CHROME EXTENSION

Stop scams before you click

Scans emails in Gmail automatically. Right-click any link to check it. Warnings appear before you reach dangerous sites.

Add to Chrome — Free →

One-click install · No account needed · Works with Gmail

PRO

Need more than 5 scans a day?

Pro gives you 200 scans/month, detailed AI analysis, 30-day history, and the Chrome extension for $2.99/mo.

See pricing →

Check any suspicious message

Six detection layers. Instant verdict. Free.

No signup · 6 detection layers · Results in seconds · Cmd+Enter