Glossary
Cybercriminals are constantly evolving their tactics, exploiting human vulnerabilities to bypass traditional security measures.
"The Ultimate Social Engineering Glossary" provides a comprehensive list of terms and definitions to help you understand the techniques, tactics, and concepts behind social engineering attacks. Use this resource to stay informed and strengthen your defenses against phishing, vishing, smishing, and other human-targeted threats.
a
AI-Driven Phishing
Phishing attacks enhanced by artificial intelligence to generate realistic and personalized messages or scenarios.
AI-Forged Evidence
Creating fake evidence, such as contracts or emails, using AI to manipulate targets.
API Exploitation
Misusing open APIs to extract sensitive organizational data.
Account Takeover
When attackers gain control of a victim's online accounts through credential compromise.
Active Directory
A critical component developed by Microsoft for managing network resources and user permissions.
Ad Fraud
Manipulating online advertising systems to generate illegitimate revenue or redirect users.
Adversarial AI
The use of artificial intelligence by attackers to bypass traditional security measures or create advanced threats.
Angler Phishing
Using fake customer service accounts on social media to lure victims into sharing sensitive information.
Attack Surface Management
Identifying and minimizing the points where an attacker can exploit vulnerabilities.
Authentication Bombing
Flooding a user with authentication requests to confuse or coerce them into granting access.
Authority Amplification
Simulating multiple trusted sources to strengthen a false claim.
Authority Exploitation
Using perceived authority to manipulate targets into compliance.
Automated Phishing Defense
Technological systems that use automation to detect, block, and respond to phishing attempts in real-time.
b
BEC (Business Email Compromise)
A sophisticated attack where an attacker impersonates a company executive or vendor to request unauthorized transfers of funds or data.
Baiting
Using false promises or enticing offers to lure individuals into a trap, such as downloading malware.
Behavioral Analytics
Monitoring user behavior to detect and respond to abnormal or potentially malicious activities.
Blockchain-Based Social Engineering
Leveraging blockchain tools for anonymity in fraudulent schemes.
Brow Phishing
Using fake browser pop-ups or alerts to deceive users into sharing credentials.
Browser-in-the-Browser (BitB) Attack
Simulating legitimate browser login prompts to steal credentials.
Business Logic Exploitation
Manipulating legitimate business processes to achieve malicious goals.
c
CEO Fraud
A specific type of BEC where the attacker pretends to be the CEO or another high-ranking official to manipulate employees into transferring money or sensitive information.
Catfishing
Creating fake online personas to gain trust and manipulate individuals into revealing personal details.
Clickbaiting
Creating enticing or misleading links to trick users into clicking.
Cognitive Load Exploitation
Overloading a target with information to confuse them and make them more likely to comply.
Cold Call Phishing
Using direct phone calls to build trust and extract sensitive details.
Compromised Account
An account that has been either hacked or accessed by unauthorized individuals or entities. In the context phishing simulations, compromised accounts are accounts for which the password has been leaked.
Consent Phishing
Tricking users into granting permissions that lead to unauthorized access.
Credential Harvesting
Collecting usernames, passwords, or other authentication details, often through phishing or malware.
Credential Stuffing
Using stolen username-password combinations from data breaches to access accounts across multiple systems.
Cryptocurrency Phishing
Targeting individuals or companies to steal cryptocurrency assets.
Cryptolocker
A type of ransomware that encrypts files and demands payment for decryption.
Cyber Crime
Criminal activities carried out using computers or the internet, such as hacking, fraud, or identity theft.
Cyber Deception
The use of deceptive strategies, such as honeypots or decoy systems, to mislead attackers and gather intelligence.
Cyber Hygiene
Practices and precautions taken to maintain the security of devices and data.
Cyber Resilience
The ability of an organization to prepare for, respond to, and recover from cyberattacks while minimizing disruption.
d
DKIM (DomainKeys Identified Mail)
An email authentication method that uses cryptographic keys to verify the authenticity of the sender.
DMARC (Domain-based Message Authentication, Reporting, and Conformance)
An email authentication protocol that helps prevent email spoofing and phishing attacks.
DNS
The Domain Name System is a decentralized system that translates domain names into IP addresses. It is used to locate websites and other resources on the internet.
DNS Spoofing
Redirecting users to malicious websites by altering the DNS entries of legitimate sites.
DNS Spoofing
Redirecting users to malicious websites by altering the DNS entries of legitimate sites.
Data Classification
Categorizing data based on its sensitivity to ensure appropriate protection and handling (e.g., public, private, confidential).
Data Exfiltration
Unauthorized transfer of data from a system or network to an external location.
Data Leaks
Unintentional exposure of sensitive data, often due to misconfigurations or human error.
Data Loss Prevention (DLP)
Tools and strategies used to prevent unauthorized access, sharing, or loss of sensitive data.
Data Poisoning
Introducing false data to undermine the integrity of AI systems.
Deepfake Phishing
The use of AI-generated audio or video to impersonate a trusted individual, often for BEC or other scams.
Deepfake Video Scams
Using AI-generated videos to impersonate executives or leaders.
Distributed Social Engineering
Coordinated attacks by multiple individuals to manipulate a target into revealing sensitive information.
Domain Poisoning
Manipulating DNS or domains to redirect users to malicious sites.
Domain Spoofing
Creating fake but convincing website domains to trick users into entering credentials.
Doxing
Publishing private or identifying information about an individual without their consent.
Dumpster Diving
Searching through physical trash or discarded materials to find sensitive information like passwords, documents, or hardware.
e
E-discovery
The process of identifying, collecting, and producing electronic information for legal purposes.
Eavesdropping
Intercepting verbal or electronic communications to gather sensitive information.
Electronic Communication
The exchange of information through electronic devices, such as emails, text messages, or social media.
Email Archiving
The process of storing and managing email messages for compliance, legal, or business purposes.
Email Filtering
The process of sorting and blocking unwanted or malicious emails.
Email Gateway
A security solution that filters and blocks malicious emails before they reach the recipient's inbox.
Email Header Spoofing
Altering email headers to make fraudulent messages appear legitimate.
Email Phishing
Phishing attempts carried out via email to trick recipients into clicking malicious links or providing credentials.
Email Scams
Fraudulent schemes conducted via email to deceive recipients into sending money or sensitive information.
Email Security
Measures and technologies used to protect email systems from cyber threats.
Emotional Anchoring
Using strong emotions to sway decision-making.
Encryption Techniques
Methods used to secure data by converting it into a code that can only be read by authorized parties.
Evil Maid Attack
Physical attacks on unattended devices to install malware or steal sensitive data.
Evil Twin Attack
Creating a fake Wi-Fi network to intercept data and credentials from unsuspecting users who connect.
Executive Impersonation
Pretending to be a senior executive to coerce employees into unauthorized actions.
f
FOMO (Fear of Missing Out) Exploitation
Creating urgency by implying a missed opportunity or critical deadline.
Fake Payment Confirmation
Sending falsified payment receipts to deceive targets into delivering goods or services.
Fear-Based Messaging
Using fear to compel action or disclosure of information.
Friend-in-Trouble Scam
Pretending to be a friend or acquaintance in distress to solicit money or information.
g
GenAI Phishing
Phishing attacks generated by advanced AI tools, enabling highly personalized and convincing messages at scale.
Gift Card Scams
Tricking victims into purchasing gift cards as a form of payment.
Graymail
Unwanted emails that are not classified as spam but are often ignored or deleted.
h
Hacking
Creating fake customer service numbers to intercept sensitive information.
Helpline Spoofing
Creating fake customer service numbers to intercept sensitive information.
Honey Credentials
Intentionally planting fake credentials to detect phishing or compromise attempts.
Honey Trap
Using fake romantic or personal relationships to manipulate a target into divulging confidential information.
Honeypot
A decoy system or network designed to attract and deceive attackers, gather intelligence, or divert attacks from critical assets.
Human Firewall
Employees trained to detect and prevent cyberattacks by adhering to security best practices.
Hybrid Attacks
Combining multiple social engineering vectors, such as phishing and smishing, for higher success.
i
ITDR (Identity Threat Detection and Response)
The process of identifying and responding to identity-related threats.
Impersonation
Pretending to be a trusted individual or entity to gain access to sensitive information or systems.
Imposter Syndrome Exploitation
Targeting individuals with self-doubt to extract sensitive information.
Incident Response
The process of identifying, containing, and recovering from security incidents.
Influence Campaigns
Coordinated efforts to manipulate public opinion or behavior.
Info Stealer Malware
Malware designed specifically to exfiltrate sensitive data from victims.
Insider Threat Engineering
Manipulating insiders to carry out malicious actions or provide unauthorized access.
IoT Exploitation
Targeting vulnerabilities in Internet of Things devices for information gathering or attacks.
j
Juice Jacking
Exploiting public charging stations to extract data or inject malware onto a victim's device.
l
Lateral Phishing
Using compromised accounts within an organization to launch phishing attacks on others.
Leaky Forms
Exploiting insecure online forms to extract sensitive user information.
Least Privilege
Limiting user access to only the data and resources necessary for their role.
m
Machine Learning Poisoning
Manipulating AI models to introduce vulnerabilities or bias into their decision-making.
Malvertising
Using malicious advertisements to direct victims to phishing sites or deliver malware.
Malvertising Campaigns
Using malicious advertisements to redirect victims to phishing sites or deliver malware.
Malware
Malicious software designed to damage, disrupt, or gain unauthorized access to systems.
Man-in-the-Browser (MitB) Attack
Intercepting and manipulating browser communication for malicious purposes.
Man-in-the-Middle (MitM) Attack
Intercepting and altering communication between two parties without their knowledge.
Microtargeting
Using data analytics to target specific individuals with customized social engineering attacks.
Mobile Security
Measures and technologies used to protect mobile devices from cyber threats.
Multi-Channel Phishing
Combining multiple methods (e.g., email, SMS, voice) to enhance phishing success rates.
n
Name-Drop Exploitation
Using references to known individuals to gain trust and access.
Nudge Attacks
Subtly influencing user behavior to make security-compromising decisions.
o
OSI Model (Open Systems Interconnection)
A conceptual framework that standardizes the functions of communication systems into seven layers: physical, data link, network, transport, session, presentation, and application.
p
Password Spraying
Using a few common passwords across many accounts to avoid detection.
Personally Identifiable Information (PII)
Any data that can be used to identify an individual, such as names, addresses, social security numbers, or biometric data.
Pharming
Redirecting users from legitimate websites to fake ones to steal sensitive information.
Phishing
Fraudulent attempts to obtain sensitive information, such as passwords or credit card details, by pretending to be a trustworthy entity.
Phone-Based Scams
Fraudulent calls aimed at extracting sensitive information or convincing victims to take harmful actions.
Piggybacking
Gaining access to restricted areas by closely following someone authorized, similar to tailgating but with implied consent.
Preloading
Manipulating cognitive biases to influence a target's behavior or decisions.
Pretexting
Creating a fabricated scenario to gain the trust of a target and extract information or access systems.
Pretexting Variants
Tailoring pretexting scenarios to align with specific victim profiles.
Pretexting for Reconnaissance
Using fabricated scenarios to gather preliminary information about a target.
Privilege Escalation
Gaining higher levels of access or permissions than intended.
Privileged Identity Management (PIM)
The process of managing and securing privileged accounts to prevent unauthorized access.
q
QR Code Phishing (Quishing)
Exploiting QR codes to direct users to malicious websites or download harmful content.
Quid Pro Quo Attack
A social engineering tactic where an attacker offers a benefit or service in exchange for sensitive information or access.
r
Ransomware
A type of malware that encrypts a victim's files, demanding payment for the decryption key.
Replay Attacks
Intercepting and reusing valid credentials or session tokens to gain unauthorized access.
Reverse Social Engineering
Convincing a target to contact the attacker for help, allowing the attacker to manipulate the target further.
Risk Management
The process of identifying, assessing, and mitigating risks to an organization's assets.
Rogue Wi-Fi Hotspots
Setting up fake Wi-Fi networks to intercept user data.
s
SIM Swapping
Taking over a victim's phone number by convincing the carrier to transfer it to a new SIM card.
SPF (Sender Policy Framework)
An email authentication protocol that helps prevent email spoofing by verifying the sender's IP address.
Sandbox
A secure, isolated environment used to test suspicious files or applications without risking the host system.
Security Awareness Training (SAT)
Educational programs designed to teach employees how to recognize and prevent cyber threats.
Security Operations Center (SOC)
A centralized team responsible for monitoring, detecting, and responding to cybersecurity threats.
Session Hijacking
Taking control of an active user session to gain unauthorized access.
Shoulder Surfing
Observing someone's private information, like passwords or PINs, by looking over their shoulder.
Smishing
Phishing attacks conducted via SMS or text messages to trick users into divulging personal or financial information.
Social Engineering
The use of psychological manipulation to deceive individuals into divulging confidential information or performing actions that compromise security.
Social Media Exploitation
Leveraging social media platforms to gather information about targets or deliver malicious content.
Social Proof Exploitation
Leveraging the influence of group behavior to manipulate a target.
Spam
Unsolicited or irrelevant messages sent in bulk, often for commercial purposes.
Spear Phishing
A targeted phishing attack directed at a specific individual or organization using personalized information to increase success rates.
Spear Smishing
Combining personalized spear phishing with SMS communication.
Spoofing
The act of impersonating a trusted source, such as an email address or phone number, to deceive victims.
Spyware
A type of malware that secretly gathers information about a user's activities without their knowledge.
t
Tailgating (Piggybacking)
Gaining physical access to a secured area by following someone authorized, without proper credentials.
Tech Support Scams
Pretending to offer technical assistance to gain access to devices or data.
Telemetry
The process of collecting and transmitting data from remote devices.
Threat Simulation
Staging mock cyberattacks to trick organizations into sharing security details.
Trojan Horse
A type of malware that disguises itself as legitimate software to gain access to a system.
Trust Anchoring
Exploiting trust in well-known brands or individuals to deceive targets.
Typosquatting
The practice of registering domains similar to legitimate ones to trick users into visiting malicious websites.
u
URL Shortener Abuse
Using shortened URLs to conceal malicious links and trick users into clicking them.
Unsolicited Social Proof
Providing fake reviews or endorsements to manipulate decision-making.
Urgency Tactics
Creating a sense of immediate action to bypass rational decision-making.
v
VPN (Virtual Private Network)
A secure connection that encrypts data transmitted between a user's device and the internet.
Virtual Meeting Phishing
Impersonating legitimate virtual meeting invitations to steal credentials.
Virus
A computer virus is a type of malware that can replicate itself and spread to other devices.
Vishing
Phishing conducted through voice calls, often involving impersonation of trusted entities like banks or government agencies.
Voice Cloning
Using AI-generated voice mimicking technology to impersonate trusted individuals and conduct scams.
w
Watering Hole Attack
Compromising a website frequently visited by a target to infect them with malware or gather credentials.
Weak Credential Targeting
Exploiting accounts protected by weak passwords.
Whaling
A type of spear phishing targeting high-profile individuals like executives or board members, often to exploit their access to sensitive data.
Whistleblower Impersonation
Pretending to be a whistleblower to gather confidential information from organizations.
x
XSS (Cross-Site Scripting)
A type of injection attack where malicious scripts are injected into web pages viewed by other users.
z
Zero Trust
A security model that assumes no user or system is trustworthy by default.
Zero-Day Social Engineering
Exploiting newly discovered vulnerabilities to manipulate users before patches are available.
Recognized by cybersecurity experts
The most innovative companies choose Arsen
Ready to see Arsen in action?
Discover how Arsen helps CISOs, cyber experts, and IT teams protect their organizations.