Summary
The core message of this session is that secure video conferencing cannot be treated as secure merely because the service, infrastructure, and managed devices have been formally assessed; the full user journey, including dial-in behavior and room-device identity, must also be tested. Oscar Koeroo and Allon Knetemann frame the talk around a practical question: what happens when a device meant to let trusted colleagues speak confidentially can be abused by someone outside the meeting? They open by stating that the findings were responsibly disclosed to relevant authorities and that, although parts of the story sound unusual, the events really happened.
The speakers explain the background from the Dutch COVID period, when the Ministry of Health, Welfare and Sports needed new security capacity and began working with outside specialists. That collaboration evolved into a continuous red-teaming arrangement with a deliberately simple rule of engagement: the testers had to be able to explain over coffee what they had done. The team later examined video conferencing in the Dutch government context, where Webex had been widely adopted and was assessed for use up to and including departmental confidential information, one level below state secret.
The first concrete issue came from ordinary Webex dial-in invitations. Users calling by phone receive a local number, enter a meeting ID, and then a password or participant ID. The speakers demonstrate that if a caller does not know the password, pressing pound could still let them in. Their expected mitigation was to disable the feature, but the initial response they encountered was complicated by the fact that the organization had paid for that capability. After repeated demonstrations, reconfiguration was pursued across the Dutch government environment in collaboration with other teams.
They then connect the work to public reporting about leaked German military Webex audio related to Ukraine, while emphasizing that they do not know how that incident was actually carried out. Instead, they describe their own proof-of-concept: creating a fake Rijksoverheid-style support site and phone exchange that appeared to support Zoom, Webex, and Teams dial-in. By placing their phone exchange between the user and the real Webex exchange, they could act as a rogue man in the middle and record meetings both ways without participants seeing it. The available transcript ends as they introduce a further challenge around managed room devices that have their own identity and do not require user login, password, or MFA.
Key Topics
5 key topics from Oscar Koeroo and Allon Knetemann at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Test complete conferencing workflows, not only core infrastructure.
- Disable insecure dial-in bypasses, even if they are paid features.
- Validate room-device identities separately from user authentication controls.
- Use controlled red teaming to prove realistic abuse paths.
- Treat phone dial-in flows as part of the security boundary.
“what if this device that basically shares whatever you're sharing with somebody across the world is abused by somebody outside of your meeting?”
Up Next



Next in agenda
The Rising Sun: CTI as accelerator of your stakeholders

Also on social engineering
Vishing At Scale: Humans vs. Voice Agents
Indy Mellink
Also on social engineering
The hype is killing kittens, but not that grumpy old cat
Edwin van Andel