Cybersecurity terms,explained clearly
Plain-language definitions of the phishing, social engineering, and human-risk terms that matter, written for security teams and the people they protect.
A
Account Takeover
When an attacker gains unauthorized control of a user's online account, typically through stolen credentials, and uses it for fraud or further attacks.
Adversary-in-the-Middle (AiTM) Phishing
A real-time phishing technique that uses a proxy server to relay a victim's login between them and the real website, stealing the session cookie and bypassing most multi-factor authentication.
Angler Phishing
A social-media phishing technique where attackers run fake customer support accounts that intercept public complaints and reply with a malicious link or a request for account details before the real brand responds.
Attack Surface
The total set of points, technical and human, where an attacker could attempt to gain entry to a system or extract data, including every account, endpoint, application, exposed service, and employee.
B
Baiting
An attack that lures victims with a tempting offer, such as free software or a found USB drive, to get them to install malware or expose credentials.
Barrel Phishing
Barrel phishing, also called double-barrel phishing, is a two-stage attack in which a harmless first email builds trust and rapport, so that the second email carrying the malicious link or request slips past the recipient's guard.
Botnet
A network of compromised devices controlled remotely by an attacker and used to carry out attacks at scale.
Brand Impersonation
A phishing tactic where attackers mimic a well known company's branding, tone, and communication style to make fraudulent messages appear legitimate.
Brute Force Attack
An attack that tries many credential combinations systematically until one works.
Business Continuity Plan
A documented plan for keeping essential operations running during and after a disruption.
Business Email Compromise
A targeted financial fraud where an attacker poses as a trusted executive, supplier, or colleague over email to trick an employee into transferring money or sensitive data.
C
Callback Phishing
A phishing attack that avoids malicious links entirely, instead pressuring the victim to call a phone number where a live scammer completes the attack.
Clone Phishing
Clone phishing is an attack that copies a real, previously delivered email and resends it with malicious links or attachments swapped in, exploiting the trust the recipient already placed in the original message.
Credential Harvesting
Credential harvesting is the theft of usernames, passwords, and other login data, usually through fake login pages or deceptive messages, so attackers can access accounts and systems.
Credential Stuffing
An automated attack that tries usernames and passwords stolen from one data breach against many other websites, exploiting people who reuse the same password across accounts.
D
Data Breach
An incident in which sensitive, protected, or confidential information is accessed, disclosed, or stolen without authorization.
DDoS Attack
An attack that overwhelms a service with traffic from many sources at once so legitimate users cannot reach it.
Deepfake
AI-generated synthetic audio, video, or images that convincingly imitate a real person's voice or likeness.
Disaster Recovery
The plans and capabilities that restore IT systems and data after a disruptive event.
Dwell Time
The length of time an attacker remains undetected inside a network or system after an initial compromise, from breach to discovery.
E
Email Authentication (SPF, DKIM, DMARC)
The set of DNS-based standards, SPF, DKIM, and DMARC, that let a receiving mail server verify an email genuinely came from the domain it claims and decide what to do if it did not.
Email Spoofing
Forging the sender address of an email so it appears to come from a trusted person or domain, typically by exploiting a domain that lacks proper SPF, DKIM, and DMARC protections.
H
I
K
M
Malvertising
Malicious code delivered through legitimate online advertising networks, so that even a trusted, high-traffic website can unknowingly serve a compromised ad that installs malware or redirects visitors to a fake page.
Malware
Any software intentionally designed to damage, disrupt, or gain unauthorized access to a device or network.
MFA Fatigue
An attack that bombards a victim with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
P
Passkey
A passwordless sign-in method using cryptographic key pairs, tied to a device and biometric or PIN unlock, that resists phishing by design.
Password Manager
A tool that securely generates, stores, and autofills unique passwords for every account, so users never need to reuse or memorize them.
Password Spraying
An attack that tries a small number of common passwords against a large number of accounts, one password at a time, to avoid triggering account lockout policies.
Penetration Testing
An authorised simulated attack against systems to find exploitable weaknesses before a real attacker does.
Pharming
An attack that redirects victims from a legitimate website's correct address to a fake copy of it by tampering with DNS resolution or a local hosts file, so even a correctly typed address lands on the attacker's page.
Phish-Prone Rate
The percentage of employees who fail a simulated phishing test by clicking a link, opening an attachment, or submitting credentials.
Phishing
Phishing is a social engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware.
Phishing Simulation
A controlled, authorized exercise that sends realistic but harmless fake phishing messages to employees to measure how they respond and to train safer behavior.
Phishing-Resistant MFA
Multi-factor authentication cryptographically bound to the legitimate website's origin, such as FIDO2 security keys and passkeys, that cannot be phished or relayed the way SMS codes and push approvals can.
Pretexting
A social engineering tactic where an attacker invents a false scenario to trick a target into revealing information or granting access.
S
Security Awareness Training
Security awareness training is structured education that teaches employees to recognize and respond to cyber threats such as phishing, social engineering, and unsafe data handling.
Security Culture
The shared attitudes, beliefs, and everyday behaviors around security that exist across an organization, beyond formal policy and training.
Security Operations Center
The team and function responsible for monitoring, detecting and responding to security events, often around the clock.
Session Hijacking
The theft or forgery of a valid session token or cookie, letting an attacker impersonate an already logged-in user without ever needing their password.
SIEM
A platform that centralises log data from across an estate, correlates it, and raises alerts on suspicious patterns.
SIM Swapping
A social-engineering attack in which a criminal convinces or bribes a mobile carrier to transfer a victim's phone number to a SIM card the attacker controls, intercepting calls and SMS one-time passwords.
Single Sign-On (SSO)
An authentication method where one identity provider verifies a user once and that single login grants access to many connected applications, typically via SAML or OpenID Connect.
Smishing
Smishing is phishing carried out over SMS or other text messaging, where attackers send fraudulent texts to trick people into revealing data, clicking malicious links, or sending money.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Spear Phishing
A targeted phishing attack that uses personalized details about a specific individual or organization to make a fraudulent message far more convincing.
Spyware
Software that secretly monitors a user's activity and collects information such as browsing habits, keystrokes, or credentials without consent.
T
Tailgating
A physical security breach where an unauthorized person follows an authorized employee through a secured door or checkpoint.
Trojan
Malware disguised as legitimate software, which relies on the user choosing to install it.
Typosquatting
Registering a domain name that closely resembles a legitimate one, relying on typing mistakes or visual similarity to trick visitors.
V
Vishing
Vishing is a voice-based social engineering attack where a caller impersonates a trusted party over the phone to trick victims into revealing sensitive information or authorizing fraudulent actions.
Vulnerability Assessment
A systematic review that identifies, classifies and prioritises known weaknesses across systems.
W
Watering Hole Attack
An attack that compromises a legitimate website frequently visited by a target group, infecting visitors instead of attacking them directly.
Whaling
A highly targeted phishing attack aimed at senior executives and other high-value individuals to steal money, credentials, or sensitive data.
Z
Zero Trust
A security model that assumes no user or device should be trusted by default, requiring continuous verification for every access request.
Zero-Day
A software vulnerability that is unknown to the vendor and has no available patch, leaving no time (zero days) to prepare a defense before it is exploited.
Put the theory into practice
See how Claro turns awareness into measurable behavior change.
Request a demo