Glossary

Social Engineering Glossary

Plain-language definitions of social engineering terms, attack techniques, and human risk concepts — with practical defensive guidance for each.

A

Account Takeover (ATO)
Account takeover is an attack in which a criminal gains control of a legitimate user account and operates it for fraud, theft, or further attacks.
Advance-Fee Fraud
Advance-fee fraud promises a large payout in exchange for an upfront fee that grows until the victim quits. How the classic 419 scam still works today.
Adversary-in-the-Middle (AiTM)
An adversary-in-the-middle (AiTM) attack proxies a real login page to steal both credentials and the session token issued after MFA is completed.
Angler Phishing
Angler phishing is a social media attack where criminals pose as a brand's customer support account to intercept complaints and steal credentials or payment data.

B

Baiting
Baiting is a social engineering attack that lures victims with a tempting item — such as a USB drive, free download, or prize — to deliver malware or harvest credentials.
Blue Team
A blue team is the defensive side of security — the people who detect, respond to and harden against attacks, including social engineering.
Browser-in-the-Browser Attack
A browser-in-the-browser (BitB) attack fakes a single sign-on popup window inside a web page to steal credentials on a pixel-perfect fake login form.
Brushing Scam
A brushing scam is the delivery of unordered packages so a seller can post fake verified reviews — increasingly paired with QR codes that lead to phishing sites.
Business Email Compromise (BEC)
Business email compromise is a targeted attack where criminals impersonate executives or trusted partners via email to trick employees into transferring money or sensitive data.
BYOD (Bring Your Own Device)
BYOD (bring your own device) lets employees use personal phones and laptops for work — expanding productivity and the attack surface at the same time.

C

Callback Phishing
Callback phishing (TOAD) is an attack where an email lures the victim into phoning a fake support line, moving the scam to a live phone call.
CEO Fraud
CEO fraud is a social engineering attack where criminals impersonate a senior executive to pressure an employee into urgent wire transfers or data disclosure.
ClickFix
ClickFix is a social engineering attack that uses fake CAPTCHAs or error prompts to trick victims into pasting and running malicious commands themselves.
Clone Phishing
Clone phishing copies a real email the victim already received, swaps its links or attachments for malicious ones, and resends it as a follow-up.
Consent Phishing
Consent phishing tricks users into granting a malicious OAuth app access to their cloud account — bypassing passwords and MFA entirely via legitimate consent screens.
Credential Harvesting
Credential harvesting is the collection of usernames and passwords at scale, usually through fake login pages, phishing kits or infostealer malware.
Credential Stuffing
Credential stuffing is an automated attack that tries username-password pairs stolen from one breach against many other sites, exploiting password reuse.
Crypto Drainer
A crypto drainer is a malicious script or phishing kit that tricks victims into signing wallet transactions that empty their cryptocurrency holdings.
Cyber Hygiene
Cyber hygiene is the set of routine practices — updates, strong authentication, least privilege, awareness — that keeps users and systems resistant to attack.

D

Dark Web
The dark web is the part of the internet reachable only through anonymizing networks like Tor, where stolen credentials and criminal services are traded.
Data Breach
A data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.
Data Exfiltration
Data exfiltration is the unauthorized transfer of data out of an organization — by external attackers, malicious insiders, or careless employees.
Data Loss Prevention (DLP)
Data loss prevention (DLP) is a set of controls that detect and block sensitive data leaving an organization via email, uploads, AI prompts, or devices.
Deepfake
A deepfake is AI-generated synthetic media — audio, video, or images — used in social engineering to impersonate trusted individuals convincingly.
Device Code Phishing
Device code phishing tricks users into entering an attacker's code on a legitimate login page, handing over OAuth tokens without stealing a password.
Digital Footprint
A digital footprint is the trail of data a person or company leaves online — the raw material attackers mine for targeted phishing and impersonation.
Digital Operational Resilience Act (DORA)
DORA (EU 2022/2554) is the EU regulation making financial entities manage ICT risk — with compulsory security awareness training for all staff and management.
Doxxing
Doxxing is the deliberate gathering and publication of someone's private information — home address, phone, employer — to intimidate, harass, or enable attacks.
Dumpster Diving
Dumpster diving is the practice of searching an organization's discarded trash for documents, media, or hardware that reveal sensitive information for attacks.

E

Email Bombing
Email bombing floods a victim's inbox with thousands of messages to bury security alerts or set up a fake IT support rescue call.
Employment Scam
An employment scam uses a fake job offer, recruiter or new-boss message to steal money, personal data or credentials from job seekers and newly hired employees.
Evil Twin Attack
An evil twin attack uses a rogue Wi-Fi access point that mimics a legitimate network to intercept traffic and steal credentials from users who connect.

G

GDPR
The GDPR is the EU's data protection law. Its security, training, and 72-hour breach notification duties make employee behavior a compliance matter.
Gift Card Scam
A gift card scam is a fraud in which attackers impersonate executives or vendors to pressure employees into buying gift cards and sending the redemption codes.

H

Help Desk Fraud
Help desk fraud is a social engineering attack where a caller impersonates an employee to trick the IT service desk into resetting passwords or MFA.
HIPAA
HIPAA sets US rules for protecting health information — including a required security awareness and training program for the entire workforce.
Honey Trap
A honey trap is a social engineering attack that builds a fake romantic or personal relationship to extract credentials, secrets, or access from a target.
Human Firewall
A human firewall is a workforce trained and measured to recognize, resist and report social engineering — the defensive layer technology cannot replace.

I

Infostealer
An infostealer is malware that silently harvests saved passwords, cookies and session tokens from a device and sells them into the criminal economy.
Initial Access Broker
An initial access broker (IAB) is a criminal who breaks into organizations and sells that access to other attackers, such as ransomware groups.
Insider Threat
An insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.
Invoice Fraud
Invoice fraud tricks a company into paying a fake or altered invoice, typically by impersonating a real supplier and changing the bank account details.
ISO 27001
ISO/IEC 27001 is the international standard for information security management systems — and it makes security awareness a required, auditable control.

J

Juice Jacking
Juice jacking is an attack that uses compromised public USB charging stations to steal data from or install malware on devices plugged in to charge.
Just-in-Time Training
Just-in-time training delivers a short security lesson at the moment a risky behavior occurs — such as right after a simulated phishing click — instead of in an annual course.

K

Keylogger
A keylogger is software or hardware that secretly records keystrokes to steal passwords, messages, and card numbers, feeding credential-based attacks.

M

Malvertising
Malvertising is the use of online advertising to spread malware or lead users to phishing pages, often through legitimate ad networks and search ads.
MFA Bypass
MFA bypass is any technique that defeats multi-factor authentication — from push fatigue and AiTM proxies to help desk resets and SIM swapping.
MFA Fatigue Attack
An MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
Money Mule
A money mule moves stolen funds through their own accounts for criminals — knowingly or not. How mule recruitment works and how to keep employees out of it.
Multi-Factor Authentication (MFA)
Multi-factor authentication (MFA) requires two or more independent proofs of identity to log in, so a stolen password alone is not enough for account access.

N

NIS2 Directive
The NIS2 Directive (EU 2022/2555) is the EU cybersecurity law for 18 critical sectors, mandating risk management, training and 24-hour incident reporting.

O

Offboarding (Leaver Risk)
Offboarding is the controlled removal of a departing employee's access and data. Done late or incompletely, it leaves accounts attackers and insiders can use.
OSINT (Open-Source Intelligence)
OSINT is intelligence gathered from publicly available sources. Attackers use it to research targets and build convincing social engineering pretexts.

P

Passkey
A passkey is a phishing-resistant FIDO2/WebAuthn credential — a cryptographic key pair bound to one website — that replaces passwords and one-time codes.
Password Manager
A password manager generates, stores, and autofills unique credentials — a core defense against credential stuffing, password reuse, and lookalike phishing sites.
Password Spraying
Password spraying is a brute-force technique that tries a few common passwords against many accounts, staying under lockout thresholds while hunting weak credentials.
Payroll Diversion
Payroll diversion is a business email compromise variant in which an attacker impersonates an employee to redirect their salary to a bank account the attacker controls.
PCI DSS
PCI DSS is the security standard for organizations handling card payments. Requirement 12.6 makes ongoing security awareness training mandatory.
Pharming
Pharming is an attack that silently redirects users from legitimate websites to fraudulent copies by corrupting DNS resolution — no click on a bad link required.
Phishing
Phishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.
Phishing Kit
A phishing kit is a ready-made package of fake login pages, scripts and evasion tools that lets low-skill attackers run professional phishing campaigns.
Pig Butchering Scam
Pig butchering is a long-con investment scam where fraudsters build trust over weeks, then lure victims into fake crypto platforms and drain their funds.
Pretexting
Pretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.
Principle of Least Privilege
Least privilege means every user, process and system gets only the access it needs, for only as long as it needs it — limiting what a compromised account can do.
Privileged Access Management (PAM)
Privileged access management (PAM) secures and monitors the powerful accounts — admins, service accounts, root — that attackers and insiders prize most.
Prompt Injection
Prompt injection is an attack that hides malicious instructions in content an AI assistant processes, manipulating it into leaking data or taking harmful actions.
Purple Team
Purple teaming pairs attackers and defenders in one collaborative exercise: attack, observe detection, fix, retest — until defenses provably improve.

Q

Quid Pro Quo Attack
A quid pro quo attack is a social engineering technique that offers a service or benefit — often fake IT support — in exchange for access, credentials, or data.
Quishing
Quishing (QR code phishing) is a social engineering attack that uses malicious QR codes to direct victims to credential-harvesting sites or malware downloads.

R

Ransomware
Ransomware is malware that encrypts or steals an organization's data and demands payment, most often delivered through phishing and stolen credentials.
Red Team
A red team is a group authorized to simulate real attackers against an organization, including social engineering, to test defenses end to end.
Rogue Access Point
A rogue access point is an unauthorized Wi-Fi radio on or near your network — planted or naive — that lets attackers bypass the perimeter or harvest traffic.
Romance Scam
A romance scam builds a fake online relationship to extract money or information — and increasingly reaches employees through workplace-adjacent platforms.

S

Scareware
Scareware is malicious software or fake alerts that frighten victims into installing malware or paying for useless 'security' products by faking an infection.
Security Champion
A security champion is an employee inside a business team who acts as its first point of contact for security, reinforcing good behavior and reporting risk back.
Security Culture
Security culture is the shared attitudes, norms and habits that shape how people in an organization actually behave around security when nobody is checking.
Security Nudge
A security nudge is a small, well-timed prompt — a banner, a warning, a reminder — that steers employees toward the safe choice without blocking them or requiring training.
Security Operations Center (SOC)
A security operations center (SOC) is the team that monitors, detects and responds to security events — including the ones people report.
SEO Poisoning
SEO poisoning manipulates search rankings so malicious sites appear as top results, luring users to fake downloads, login pages, and support numbers.
Session Hijacking
Session hijacking is the theft or takeover of an authenticated session — via stolen cookies or tokens — letting an attacker bypass login and MFA entirely.
Sextortion
Sextortion is a form of blackmail in which attackers threaten to release intimate or compromising material unless the victim pays or complies.
Shadow AI
Shadow AI is employees' use of AI tools without IT approval — chatbots, assistants, note-takers — creating invisible data leakage and compliance risk.
Shadow IT
Shadow IT is technology used without IT approval — unsanctioned apps, accounts, and AI tools that expand attack surface outside security's visibility.
Shoulder Surfing
Shoulder surfing is observing someone's screen or keyboard to steal passwords, PINs, or confidential data — in person or via cameras in public spaces.
SIM Swapping
SIM swapping is an attack where criminals socially engineer a mobile carrier into transferring a victim's phone number to their SIM, hijacking SMS codes and accounts.
Smart Contract Scam
Smart contract scams hide theft inside blockchain code — fake tokens, malicious approvals, rug pulls. How they work and how to protect employees.
Smishing
Smishing (SMS phishing) is a social engineering attack that uses text messages to trick recipients into clicking malicious links or sharing sensitive information.
SOC 2
SOC 2 is an audit framework for how service organizations protect customer data. What the Trust Services Criteria cover and where the human layer fits.
Social Engineering
Social engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.
Spear Phishing
Spear phishing is a targeted phishing attack that uses personalized information about the victim to increase its effectiveness.
Spoofing
Spoofing is the falsification of an identity signal — sender address, caller ID, domain, or website — to make an attack appear to come from a trusted source.
Spyware
Spyware is malicious software that covertly monitors a device — harvesting credentials, messages, and activity — and feeds social-engineering attacks.
Supply Chain Attack
A supply chain attack compromises a trusted vendor, software update, or service provider to reach that supplier's customers — trust as the attack vector.
Synthetic Identity Fraud
Synthetic identity fraud combines real and fabricated personal data into a new, fake identity used to open accounts, pass checks, or get hired.

T

Tailgating (Piggybacking)
Tailgating is a physical social engineering attack where an unauthorized person follows an employee through a secured door into a restricted area.
Tech Support Scam
A tech support scam impersonates IT or vendor support to gain remote access or payment, often via fake virus pop-ups, cold calls, or search ads.
Typosquatting
Typosquatting registers look-alike domains — misspellings or swapped characters — to catch mistyped URLs and lend fake emails and sites credibility.

U

USB Drop Attack
A USB drop attack seeds infected flash drives where targets will find them, exploiting curiosity to get malware or keyloggers inside a network.
User Behavior Analytics (UBA)
User behavior analytics (UBA) baselines how each account normally behaves and flags anomalies — a key control for spotting insider risk and account takeover.

V

Vendor Email Compromise (VEC)
Vendor email compromise hijacks a supplier's real email account or thread to redirect customer payments — BEC's hardest-to-spot variant.
Virtual Private Network (VPN)
A virtual private network (VPN) encrypts traffic between a device and a trusted network, protecting remote work from snooping and rogue Wi-Fi hotspots.
Vishing
Vishing (voice phishing) is a social engineering attack conducted over phone calls to manipulate victims into revealing sensitive information or taking harmful actions.
Voice Cloning
Voice cloning uses AI to replicate a person's voice from a short audio sample, letting attackers impersonate executives and colleagues over the phone.

W

Wardriving
Wardriving is scanning for Wi-Fi networks from a moving vehicle to map targets. How attackers use it and how to keep your wireless edge off the map.
Watering Hole Attack
A watering hole attack compromises a website a target group already trusts and visits, infecting visitors instead of approaching them directly.
Whaling
Whaling is a spear phishing attack specifically targeting senior executives or high-value individuals within an organization.

Z

Zero Trust
Zero trust is a security model that grants no implicit trust based on network location or identity claims — every access request is verified. Where the human layer fits.