Zishing is phishing carried out through Zoom or a similar video collaboration platform. Attackers use meetings, chat, or impersonation to deliver malicious links, extract information, or convince targets to act. The technique works because users tend to trust live collaboration channels more than unfamiliar email or web prompts.
How zishing works in collaboration platforms
Zishing is effective because it uses the trust, urgency, and conversational flow of live collaboration tools. A target may see a meeting invite, a chat message, or a familiar-looking participant name and treat it as routine rather than suspicious.
The attacker’s advantage is social context. Video collaboration platforms compress identification, instruction, and action into one channel, so a link, file, or request can feel more legitimate than the same content delivered through email.
Common attack patterns and delivery methods
In practice, zishing often shows up as impersonation, meeting hijacking, chat-based lure messages, or fake support contacts. Attackers may rename accounts, reuse branding, or exploit the platform’s own notification behavior to increase credibility.
Some campaigns rely on a short path from engagement to compromise: join a meeting, click a shared link, enter credentials, or approve a request. Others aim for data collection first, then follow up with deeper social engineering once the target has responded.
Security implications for users and organizations
Zishing is not just a messaging problem. It can expose credentials, internal documents, payment details, or sensitive operational information, and it can also be used to seed malware or direct targets to fraudulent login pages. The risk increases when collaboration tools are treated as inherently trusted because they are familiar and interactive.
Organizations also face control blind spots when collaboration traffic is excluded from the same scrutiny used for email or web content. That can leave room for impersonation, unauthorized sharing, and fast-moving abuse inside a platform that users are encouraged to act on immediately.
How to interpret zishing as a broader security pattern
Zishing is best understood as phishing adapted to a real-time collaboration environment. The underlying pattern is the same as other social engineering attacks, but the channel changes the defender’s assumptions: users may trust the platform, trust the participant list, or trust the immediacy of a live conversation.
That makes zishing a useful reminder that trust should be earned by verification, not by channel familiarity. When a platform supports meetings, chat, screen sharing, or external invitations, each of those features can become part of the attacker’s delivery path.
Risk and Threat Considerations
Zishing creates a concentrated trust risk because collaboration tools often sit inside the normal workday and are treated as low-friction, high-trust channels. Attackers exploit that trust to deliver malicious links, extract information quickly, or push targets into actions they would question in email.
Failure mechanism: The platform’s legitimacy, the speed of interaction, and the social pressure of a live exchange reduce the chance that the target pauses to verify the requester, destination, or instruction.
Impact: Successful zishing can lead to credential theft, unauthorized disclosure, fraud, account compromise, or downstream malware delivery, especially when the target acts before secondary verification.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication and Access Control | Zishing often exploits credential prompts and access decisions in trusted collaboration channels. |
| DE.CM-01 — Networks and Network Services Monitored | Collaboration abuse benefits from low visibility into real-time communications and link delivery. | |
| Recommendation — Harden collaboration access flows with least-privilege and verified authentication prompts. Monitor collaboration activity for anomalous invitations, chat lures, and external contact patterns. | ||
| NIST SP 800-53 Rev 5 | AU-2 — Event Logging | Collaboration abuse is easier to investigate when meeting, chat, and invitation activity are logged. |
| IA-2 — Identification and Authentication (Organizational Users) | Zishing commonly relies on impersonation and account abuse inside collaboration tools. | |
| Recommendation — Log collaboration events so impersonation and suspicious invites can be investigated quickly. Require strong user authentication to reduce impersonation opportunities in collaboration platforms. | ||
| MITRE ATT&CK | T1566 — Phishing | Zishing is phishing delivered through a collaboration platform rather than email. |
| Recommendation — Map collaboration-based lures to phishing detections and hunt for user interaction patterns. | ||
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org