Teams, Zoom, Webex: for most employees, web meetings have become as routine as the telephone once was. You click a link, turn on the camera, share your screen, and barely think about security. That is exactly what makes web meetings so attractive to attackers. They combine the trust created by faces and voices with real-time pressure and direct access to whatever is happening on screen.
It does not always take a Hollywood-grade deepfake production. Often a credible pretext, a fake meeting link, or a carelessly shared window is enough. And sometimes the risk does not come from outside at all, but from your own desk.
The July Cyber Snack makes exactly that tangible: it starts with what is probably the most expensive video call in the world and then shows which everyday situations in web meetings become dangerous, and which six rules really protect you.
The Arup case: probably the most expensive video call in the world
In the Arup case, every face on the call was fake, except the victim's.
In early February 2024, Hong Kong police made public a case that has since become a textbook example. An employee in the finance department of a multinational company received an email, supposedly from the UK-based chief financial officer, about a confidential, 'secret' transaction. At first, the employee reacted exactly right: he suspected a phishing attempt.
But the fraudsters were prepared. They pulled him into a video conference where he saw and heard the CFO and several familiar colleagues. According to the police, every person he saw on that call was fake: the perpetrators had apparently used publicly available video and audio material in advance and turned it into convincing AI deepfakes. The apparent discussion among executives removed his remaining doubts. The employee made 15 transfers to five bank accounts in Hong Kong, a total of HK$200 million, or roughly US$25 million. The fraud only came to light when he later checked with the company's head office.
In May 2024, the British engineering and design firm Arup confirmed that it was the company involved. Arup stated that fake voices and images had been used and that none of its internal systems had been compromised. That is the real lesson: no system was hacked. What was hacked was one person's trust.
In a web meeting, what matters is not who you see, but whether the request fits the agreed processes.
Why web meetings are so attractive to attackers
Deepfakes like the one at Arup are the tip of the iceberg. Most attacks via web meetings are much simpler, and that is exactly why they happen more often. There are several reasons for this.
First, attackers in a meeting can apply pressure in real time and adapt their tactics to the other person's reactions on the spot. Seeing the facial expressions and impatience of an apparent manager creates stress faster than an email does. Second, screen sharing makes it possible to guide a victim step by step: the attacker sees live which warning appears and immediately explains why it is safe to click it away.
Third, a face inspires trust. When we see and hear someone, our brain quickly switches to trust, so personal interaction does not make attackers more suspicious, it makes them more credible. The price for this: such an attack takes much more effort than a phishing email that reaches thousands of people with one click. That is why web meetings are used mainly where the effort pays off: in targeted attacks on finance departments, executives, IT, or HR.
Three everyday pretexts
In web meetings, social engineers usually rely on perfectly ordinary occasions. An apparent new customer shares documents in the chat that they want to discuss right away, and hides malware in them. A supposed HR department wants to 'reconcile employee data' and collects names, roles, and contact details for the next attack. A fake colleague from IT asks you to quickly install a piece of software to fix a problem, and gains full control of the computer.
The methods differ, but the goal is the same: confidential information, access, and ultimately money. To build trust, attackers pose as customers, suppliers, or job applicants, or they use hacked accounts of real colleagues. This is classic social engineering, just with a camera and screen sharing.
The danger starts before the meeting
The attack often starts before the meeting: with a link that leads to a fake login page or a fake update.
The danger often begins before anyone has even joined the meeting. A typical scenario: a new contact writes via LinkedIn, you agree on a short call, and soon after an invitation arrives with an apparently normal Teams link. Anyone who clicks it lands on a page asking them to sign in with their Microsoft account. In reality, the page is fake and harvests credentials.
Tom's Guide showed in August 2025, citing Cloudflare, how professional such campaigns have become: using compromised accounts, attackers even abused the link-wrapping features of email security services to make their links look harmless. The lures included fake notifications styled like Microsoft Teams messages; the target was Microsoft 365 credentials.
A second trick relies on impatience. In February 2026, Malwarebytes described a fake Zoom page that simulates an ongoing meeting with participants and 'network problems'. After a few seconds, an alleged mandatory update appears with a countdown, and in the background a file is downloaded that installs a misused copy of the commercial monitoring software Teramind. Among other things, it can record keystrokes and screen content. Anyone rushing from one meeting to the next is quick to click through something like that.
When the risk comes from your own desk
Shared windows, whiteboards, and smart speakers: many leaks start at your own workplace.
Not every risk is an attack. Sometimes we are simply careless ourselves. An unknown guest sitting silently in the call may be a social engineer recording the entire meeting, including internal matters, strategies, and figures. An accidentally shared Outlook window is a classic: even subject lines can reveal project codes, sales figures, or the names of new customers.
Then there are the devices and objects in the room. Smart speakers wait for their wake word; if a word in the conversation sounds similar, the device can activate unintentionally and send fragments of the conversation to the cloud. And a whiteboard in the background is a problem even if it was only briefly in view: if the meeting is recorded, the video can later be paused and analysed at leisure.
A screenshot takes one second
During a presentation, you briefly switch to your inbox to look for a file. For two seconds, your Outlook is visible to everyone, with subject lines about an ongoing offer, a project code, and the name of a new customer. One participant takes a screenshot at that very moment. Nobody noticed, and it will be analysed later at leisure.
Six rules for safe web meetings
1. Know your participants
Check who is on the call. Unknown guests or duplicate names are suspicious. Ask actively, and do not share sensitive information until you are sure all participants are legitimate.
2. Share only what is necessary
Share individual windows or applications, never your entire screen. That keeps Outlook notifications, chats, and private messages out of view.
3. Create a safe environment
Keep smart speakers out of your workspace and use background blur so that whiteboards and documents stay out of the picture.
4. Be careful with links and attachments
With first contacts, do not open attachments without checking them and never install software on request. Updates for Teams or Zoom come only through the official app.
5. Verify unusual requests
For payments, software downloads, or data requests, get confirmation through a second, known channel, for example by calling back on a number you already know.
6. Do not let yourself be pressured
Fraudsters use time pressure. Stick to the defined internal processes, no matter who is sitting across from you on screen.
What about security software?
Security software is an important building block: antivirus, email filters, and endpoint protection block much of the malware that arrives via attachments or fake updates. But it has limits. It cannot recognise a convincing conversation partner, it does not stop a payment that someone makes voluntarily, and legitimate remote support or monitoring tools cannot always be reliably distinguished from malicious use. That is why attackers in meetings deliberately play down warnings or try to get their victim to switch off protection themselves. The rule is simple: anyone who asks you to disable a security feature is a warning sign, not a helper.
What awareness teams should take from this
For CISOs and awareness managers, the most important lesson is this: web meetings are not a fringe IT topic but a central place of work, and therefore a central place of attack. Technical measures such as lobby settings, restrictions for external participants, or controlled software distribution are important. What matters most, however, is that employees know they are allowed to say no when the pressure is on.
This is not achieved through bans, but through clear processes and practice: mandatory call-back procedures for payment instructions, an unambiguous rule that IT never asks people to install software during a meeting, and executives who explicitly welcome verification instead of seeing it as distrust. People who have experienced manipulation first-hand recognise it more easily.
Our insight Experiencing manipulation live shows what manipulation feels like in a conversation. AI agents describes how voices can now be faked just like faces, and our insight on ransomware shows what happens once an attacker has gained access to a computer.
Conclusion
Web meetings feel familiar and harmless. That is exactly why they are an ideal entry point: a face creates trust, time pressure pushes doubts aside, and screen sharing opens doors that would otherwise stay closed. The Arup case shows how far this can go; the everyday cases show how often it happens.
The best protection is not new software, but an attitude: stay alert whenever something deviates from the usual, no matter who is on the screen.
Sources
The Register, February 5, 2024: "Deepfake CFO tricks Hong Kong biz out of $25 million"; CNN, February 4, 2024: "Finance worker pays out $25 million after video call with deepfake 'chief financial officer'".
CNN, May 16, 2024: "British engineering giant Arup revealed as $25 million deepfake scam victim".
Tom's Guide, August 4, 2025: "Email security features are being hijacked to steal Microsoft 365 logins - what you need to know".
Malwarebytes, February 24, 2026: "Fake Zoom meeting 'update' silently installs unauthorized version of monitoring tool abused by cybercriminals to spy on victims".