Your Microsoft Teams or Zoom calls could be getting hacked in a really bizarre way

Woman waving on a video call using her laptop
(Image credit: djile / Shutterstock)

Your humble eyeglasses could give hackers a secret window into your company's valuable data on video calls, security experts have claimed.

Researchers from the University of Michigan in the US and Zhejiang University in China recently published a report in which they explain how eyeglasses reflections could be used to steal sensitive or private data, through video conferencing tools such as Zoom or Microsoft Teams

The report said it is possible to reconstruct and recognize, with more than 75% accuracy, on-screen texts that have heights as small as 10mm, all while using nothing more than a 720p webcam.

Peaking through the reflections

Truth be told, the experiment was done in a controlled lab setting, meaning results in real-life use might differ. In fact, the researchers are saying there are many factors that can contribute to the accuracy of the method, including the participant's skin color, how well-lit the room is, the brightness of the display the contrast between the text and the background on the display, as well as the eyeglasses.

Still, the risk is real, especially for users with 4K cameras, with the team stating, "We found future 4k cameras will be able to peek at most header texts on almost all websites and some text documents."

In fact, when researchers set out to just identify the specific website the eyeglasses-wearing person was looking at, success rate for Alexa’s top 100 websites was 94%.

Discussing potential use cases for this type of attack, researchers said they could be used to “cause discomforts” in daily activities, such as bosses monitoring what the employees are looking at, during meetings. A more serious potential scenario is losing key negotiation-related information this way.

As for possible mitigations, Zoom apparently has a filter with reflection-blocking capabilities - however other tools are yet to catch up.

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
A finger touching the google chrome icon in the Windows 10 start menu
A new Chrome browser highjacking attack could affect billions of users - here's how to fight it
Optical system for data encryption
Is it quantum-resistant? Researchers create 'uncrackable' encryption system by pairing AI and holograms produced by laser
Photograph of a hand holding a smartphone with two googly eyes
Every tap, every message – how to stop your smartphone spying on you
Magnifying glass enlarging the word 'malware' in computer machine code
Microsoft Teams and AnyDesk abused to deploy dangerous malware, so be on your guard
Robotic hand clicking on captcha 'I am not a robot'.
Double clicking danger - experts warn just two clicks can let attackers steal your accounts
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough