Glossary
Common terms, explained in one sentence.
- 2FA
- Two-factor authentication — a second login step beyond a password.
- Breach
- When attackers steal data from a company's systems.
- Encryption
- Scrambling data so only the right key can read it.
- Firewall
- A filter that controls what network traffic is allowed in or out.
- HTTPS
- An encrypted version of HTTP. Look for the padlock in your browser.
- Malware
- Any software designed to harm or spy on a device.
- Phishing
- Fake messages that try to steal info or money.
- Ransomware
- Malware that locks files and demands payment.
- Social engineering
- Manipulating people instead of hacking systems.
- VPN
- Virtual private network — encrypts traffic between your device and a server.
- Zero-day
- A vulnerability attackers find before a fix exists.
- Deepfake🌍 New
- AI-generated video, audio, or images that convincingly imitate a real person's face or voice.
- Quishing🌍 New
- Phishing via fake QR codes — a sticker covers the real one and routes you to a scam payment page.
- Business Email Compromise (BEC)🌍 New
- A scam where attackers impersonate an executive, colleague, or supplier by email to trigger an urgent payment or data transfer.
- Credential Theft🌍 New
- Stealing usernames and passwords through fake login pages, malware, or leaks so attackers can sign in as you.
- Account Takeover🌍 New
- When an attacker gains full control of one of your accounts, changes the recovery details, and locks you out.
- Supply Chain Attack🌍 New
- Compromising a trusted vendor, app update, or library so the malicious code reaches everyone who trusts it.
- Malvertising🌍 New
- Malicious code hidden inside online ads that infects or redirects visitors on otherwise legitimate sites.
- SIM Swapping🌍 New
- Tricking a mobile carrier into moving your number to the attacker's SIM so they receive your SMS codes.
- Insider Threat🌍 New
- Damage or data loss caused by someone inside an organisation — malicious, careless, or compromised.
- Voice Cloning🌍 New
- Using AI to copy someone's voice from a short recording and fake an urgent phone call or voice note.
- AI-Powered Social Engineering🌍 New
- Scams written or automated by AI, producing flawless, personalised messages at massive scale.
- AI-Generated Malware🌍 New
- Malicious software created or mutated with AI so each copy looks different and evades detection.
- Tech Support Scam🌍 New
- A fake alert or call claiming your device is infected, pushing you to pay or grant remote access.
- Mobile Threats🌍 New
- Risks specific to phones and tablets: rogue apps, over-broad permissions, and unpatched operating systems.
- Cloud Security Risk🌍 New
- Exposure caused by misconfigured cloud storage, over-shared links, or weak access controls.
- Browser Hijacking🌍 New
- Unwanted extensions or settings changes that redirect your searches, inject ads, and track browsing.
- Cryptojacking🌍 New
- Secretly using your device's processing power to mine cryptocurrency, slowing it down and heating it up.
- Credential Stuffing🌍 New
- Automated login attempts using passwords leaked from other breaches, which works whenever you reuse a password.
- Smishing🌍 New
- Phishing delivered by SMS or messaging apps, usually with a short link and an urgent excuse.
- Vishing🌍 New
- Voice phishing — a phone call impersonating your bank, a courier, or support to extract codes or payments.
- Passkey🌍 New
- A phishing-resistant login that replaces passwords, using your device's biometrics or PIN.