The onus should be on the service operators to clearly define what's authorized and what isn't; and if they miss something, the liability should be borne by the service operator, not the person who found their gap.
My proposal would require companies to actually take security very seriously.
https://www.troyhunt.com/we-take-security-seriously-otherwis...
Are they discussing national secrets over Zoom? Without end-to-end encryption?! That's some form of criminal negligence and/or mishandling of classified information in every jurisdiction I know.
If not, it's little more than a nuisance and a reminder that Zoom should not be relied on for important communications.