Attack encyclopedia
100 techniques explained, grouped into 10 families. Each article describes the mechanism, the warning signs, how to verify, and what to do — including if it already happened.
Social engineering
11 articlesAttacks that target the person rather than the machine: a message or a call pushes you to act against your own interest.
- Romance scamThe romance scam consists of building an emotional, long-distance relationship over several weeks or months, before asking for money under a pretext presented as exceptional and temporary.
- BaitingBaiting offers a desirable trade — content, software, an object, or a benefit — whose acquisition requires an action from the victim: opening a file, installing a program, plugging in a device, or providing information in exchange.
- Fake government officialThe fake government official scam is the impersonation of a public service — tax authority, social security agency, police, or an energy provider acting under delegation — to obtain a payment, personal information, or access, relying on the institution's authority.
- Fake tech supportThe fake tech support scam makes you believe your computer is infected or locked, in order to gain remote access to the machine or get you to pay for unnecessary assistance.
- Fake job offerThe fake job offer uses a fictitious hiring process to obtain personal documents, a payment presented as an upfront fee, or the use of the candidate's bank account to move funds of fraudulent origin.
- PhishingPhishing is a fraudulent message that imitates a legitimate sender — a bank, government agency, online service, or employer — to obtain credentials, banking details, or get a malicious attachment opened. Email is its most common channel; SMS, phone calls, and QR codes are variants covered separately.
- Pretexting (fabricated scenario)Pretexting is the construction of a plausible identity and situation, sustained across several exchanges, in order to obtain information or access without ever making a request that seems abnormal.
- Smishing (SMS phishing)Smishing is a text-message scam that imitates a trusted organization (often a bank) to push the victim into clicking a fraudulent link or sharing sensitive information.
- Identity impersonationIdentity impersonation, in the sense used by this family, is the act of borrowing an existing person's or organization's identity during an exchange, in order to benefit from the trust placed in them.
- Impersonating a relative by messageImpersonating a relative is a message received on a messaging app, presented as coming from a family member who supposedly changed their number, asking you to pay an amount on their behalf.
- Vishing (voice phishing)Vishing refers to phishing carried out by phone call: a caller presents themselves as a trusted organization and obtains, during the conversation, information or actions a written message wouldn't have obtained.
Website and browser attacks
11 articlesAttacks that play out in the address bar and on the page itself: a site imitates a legitimate service, or one address looks like another.
- Homoglyph attackA homoglyph attack uses characters from different alphabets that are visually identical to Latin characters to compose a web address that looks genuine to the eye, while actually pointing to an entirely different domain.
- Clickjacking (hijacked click)Clickjacking consists of overlaying a visible page with a transparent element from another site, so that a click aimed at the displayed content is received by that hidden element instead.
- Browser hijackingBrowser hijacking is the persistent modification of browser settings — home page, search engine, new tab page, extensions — by software installed on the device, in order to redirect browsing.
- Malicious browser extensionA malicious browser extension is a module voluntarily installed by the user, whose permissions let it read or modify the content of the pages visited.
- Fake browser updateA fake update is a web page that imitates a browser or system notification to get a malicious program downloaded and run, presented as an essential update.
- Fake websiteA fake website is a reproduction of a legitimate service, hosted on a domain controlled by the attacker, whose function is to collect whatever the visitor enters there.
- Fake downloadA fake download is the substitution of a malicious program for the expected file, either through a misleading button on a download page, or through an installer that adds unrequested software.
- MalvertisingMalvertising is the distribution of malicious content through advertising networks, which lets it be displayed on legitimate sites without those sites being compromised.
- Quishing (fraudulent QR code)Quishing is the use of a QR code to direct people to a fraudulent site: the code hides the destination address, which is therefore not readable before it's opened.
- Tabnabbing (swapped tab)Tabnabbing consists of changing the content of an inactive tab to display a fake login page in it, exploiting the fact that users attribute to a tab the origin it had when they opened it.
- TyposquattingTyposquatting consists of registering a domain name very close to a legitimate site — a missing letter, a swap, a different extension — to catch visitors who mistype the address or read too quickly.
Financial fraud
12 articlesAttacks with a direct objective: a payment, a transfer, or your full bank details.
- Investment scamThe investment scam offers an investment presented as safe and highly profitable — crypto assets, energy, financial products — to obtain successive payments that will never be returned.
- Rental scamThe rental scam consists of publishing a listing for housing the poster doesn't own, in order to obtain a deposit, security deposit, or first month's rent before the victim can find out that no rental is actually possible.
- Classified ad scamThe classified ad scam targets people selling to one another: the attacker poses as an interested buyer and steers the conversation toward a fake payment scheme, in order to obtain banking credentials or a transfer.
- Fake traffic fineThe fake fine scam is a message imitating an official traffic-violation notice from a government agency, directing you to a payment page controlled by the attacker in order to collect the sum and full banking details.
- Fake online storeA fake online store is a shopping site created to collect payments without ever delivering, or to collect banking details under the guise of an order.
- Fake invoiceA fake invoice is a document demanding payment for a service that was never ordered or provided, sent to a business, an association, or a self-employed professional, and written to look like a routine bill.
- Fake bank advisorFake bank advisor fraud is a phone call in which the attacker poses as your bank's anti-fraud department to get you to validate a fraudulent operation yourself.
- Fake prize, fake lotteryThe fake prize scam announces the award of a sum of money, a prize, or an inheritance, and makes handing it over conditional on paying fees beforehand — taxes, processing fees, transfer fees, or notary fees — which are the sole purpose of the fraud.
- Fake courier / package on holdThe package scam is a text message or email claiming that a delivery is on hold and that a small payment — customs fees, reshipping fees, an adjustment — is needed to release it.
- Fake wire transfer order (CEO fraud)CEO fraud targets businesses and associations: a message presenting itself as coming from management or an executive asks for an urgent, confidential transfer that bypasses the usual procedures.
- Fake refundThe fake refund scam announces that a sum is owed to you — taxes, health insurance, energy, a subscription — and asks for your full banking details to "process the payment."
- Fake bank details changeThe fake bank details change fraud consists of getting a regular payee's — supplier, contractor, landlord, employer — banking details changed, in order to divert an expected payment.
Credentials and accounts
10 articlesAttacks that target access to an existing account: a password, a second factor, or the phone number tied to it.
- Brute-force attackA brute-force attack is the systematic trial of passwords until the right one is found, either directly against a service or offline against a stolen database of password hashes.
- Credential stuffingCredential stuffing is the reuse of username/password pairs obtained from a data breach against other services, betting that the same person used the same password elsewhere.
- Two-factor authentication bypassBypassing two-factor authentication targets the second factor itself: instead of breaking through it technically, the attacker gets the victim to hand it over or approve it.
- Account recovery hijackingAccount recovery hijacking is borrowing the procedure meant for users who've lost access, by satisfying the identity proofs it requires in place of the legitimate account holder.
- Session hijackingSession hijacking is a third party's reuse of the authentication token issued to a user after they log in, which grants access to the account without going through authentication again.
- SIM swappingSIM swapping consists of getting your phone number transferred to a card controlled by the attacker, who then receives calls and SMS verification codes meant for you.
- Infostealer (credential-stealing malware)An infostealer is malware whose sole function is to collect and exfiltrate credentials, session cookies, tokens, and payment data present on a device, then disappear.
- Social media account takeoverSocial media account takeover is gaining control of a person's authentic account, then used to approach their contacts, spread content in their name, or resell their audience.
- Email account takeoverEmail account takeover is gaining control of a mailbox, which grants access not only to messages but also to resetting every account linked to it.
- Password sprayingPassword spraying consists of testing a very small number of extremely common passwords against a very large number of accounts, staying below the attempt threshold that would trigger a lockout.
Malware
10 articlesPrograms installed on a device to spy on it, encrypt its files, hijack its processing power, or take control of it.
- BotnetA botnet is a set of compromised devices, remotely controlled by a single operator, and used collectively to send spam, overwhelm services, relay traffic, or test stolen credentials. The recruited device isn't the target of the attack: it's the instrument.
- Trojan HorseA trojan horse is malicious software hidden inside an apparently legitimate program, which the user installs themselves. Unlike a virus or a worm, it doesn't reproduce: it doesn't need to spread, since it gets itself run by the targeted person.
- CryptojackingCryptojacking is the unauthorized use of your device's computing power to produce cryptocurrency for a third party's benefit. It differs from other malware in what it targets: neither your data nor your accounts, but a hardware resource.
- KeyloggerA keylogger is a device — software, or a small piece of hardware inserted on the keyboard port — that captures the keys typed on a device and sends them to a third party. Its distinctive feature is that it works upstream of any website: whether the page you're typing on is legitimate makes no difference.
- SpywareSpyware is a program installed without the user's knowledge to observe their activity — pages visited, messages, credentials, location — and transmit it to a third party. This entry covers the case where that third party is a stranger acting remotely. When the installation is carried out by someone close to the victim with physical access to the device, it is stalkerware, which calls for a different course of action that accounts for the danger that person poses.
- RansomwareRansomware is malicious software that renders a device's files unreadable by encrypting them, then demands payment in exchange for the means to restore them. This isn't a theft of files but a denial of access: the data stays where it is, and it's the key that's missing.
- RootkitA rootkit is a set of malicious components that installs itself at an elevated privilege level in order to hide its own presence and that of other programs from the operating system itself. Its own purpose isn't to cause direct harm, but to make what does cause harm invisible.
- ScarewareScareware is software or a web page that manufactures an alarming security alert in order to get you to buy or install a supposed solution. This entry covers the software-based method; when a human caller contacts you or has you call them to get you to hand over control of your machine, that's fake tech support, which has its own entry. The two are frequently chained together, with the alert displaying a number to call.
- Computer WormA worm is malicious software that reproduces and moves through a network on its own, without needing any user action or host file. This autonomy sets it apart from a virus, which needs to be opened, and from a trojan horse, which needs to be installed.
- Computer VirusA computer virus is malicious software that reproduces by inserting a copy of itself into other files or programs, and that spreads when those files are opened or shared. In everyday language the word covers malware as a whole; this entry gives both meanings and points to the exact category in each case.
Phones and connected devices
10 articlesAttacks specific to the devices you keep on you or at home: phone, watch, camera, router, voice assistant.
- Premium-rate subscriptions and SMSA premium-rate subscription is a subscription to a carrier-billed service, often taken out unknowingly, triggered by an SMS, a call to a special number, or a confirmation on a mobile page.
- Malicious appA malicious app is a program voluntarily installed on a phone that performs a visible function while collecting data or carrying out actions the user did not ask for.
- Bluetooth attackA Bluetooth attack exploits a device's short-range wireless connectivity to send it unsolicited data, obtain abusive pairing, or take advantage of a flaw in its Bluetooth software stack.
- Overlay attackAn overlay attack is when an app installed on the phone displays a window on top of another app as soon as it launches, in order to intercept what the user types into it.
- Compromised router or gatewayA compromised home router is a household's internet access equipment whose configuration has been altered by a third party, letting them redirect or observe the traffic of every connected device.
- Hacked security cameraA hacked security camera is a home surveillance device that a third party has gained access to, generally through a factory credential, a reused password, or the device being directly exposed to the internet.
- Juice jacking (rigged charging station)Juice jacking refers to exploiting a public charging port or cable to establish a data connection with the device plugged into it, rather than a simple power supply.
- Compromised smart deviceA compromised smart device is a network-connected home appliance — lighting, a plug, a thermostat, a household appliance, a toy — that a third party has taken control of, usually through a factory-set credential or an unpatched software flaw.
- Excessive permissionsExcessive permissions refers to data collection made possible by permissions granted to an app that are disproportionate to the function it performs.
- Tracker stalkingTracker stalking is the misuse of a personal-item tracker to follow a person's movements without their knowledge, by hiding it in their belongings or vehicle.
Network and Wi-Fi attacks
8 articlesAttacks that insert themselves between your device and the internet: a fake network, traffic interception, hijacked address resolution.
- Man-in-the-Middle AttackA man-in-the-middle attack is any situation where a third party inserts itself between two parties who believe they are communicating directly, and is able to read or modify what passes between them. This is the general category; the entries in this family describe its concrete forms — a fake access point, spoofing on the local network, hijacked name resolution — and this page does not redefine any of them.
- Wi-Fi Deauthentication AttackA deauthentication attack consists of repeatedly forcing devices off their wireless network. It grants access to nothing by itself: its function is to be the setup for something else, usually a switch to a fake access point.
- Denial of ServiceA denial-of-service attack consists of making a service unavailable by flooding it with requests or exhausting its resources. It differs from everything else in this catalogue in its goal: neither data nor accounts, but interruption. When the flooding comes from many devices at once, it's called a distributed attack.
- DNS PoisoningDNS poisoning consists of tampering with the translation of a site name into a server address, so that a correctly typed address leads to a server controlled by a third party. It differs from typosquatting, where it is the address itself that differs: here the address is correct, and it's the destination that has changed.
- Evil Twin Wi-Fi HotspotA fake access point is a wireless network published by a third party under a name that imitates a legitimate one, so that devices connect to it and their traffic passes through it. It is the most common form of man-in-the-middle attack in a public place.
- Network Traffic InterceptionTraffic interception is the passive observation of data traveling over a network by a third party able to see it pass by. It changes nothing and leaves no trace for the person being observed, which makes it undetectable from their side — this entry therefore mainly explains what it actually allows, and what encryption protects.
- Malicious Captive PortalA captive portal is the access page that opens automatically when joining certain public networks. Its malicious version reuses that appearance to obtain credentials, a payment, or the installation of a component. It's the point where a fake access point most often produces its effect, and the mechanism is that of phishing — in a context where you specifically expect to see a login page.
- ARP SpoofingARP spoofing is a technique by which a device already present on a local network impersonates the gateway — the router or box — to the other devices, so that their traffic passes through it. It requires prior access to the network, which sets it apart from a fake access point, where the third party supplies the network itself.
Data and digital identity
9 articlesWhat happens to your personal information once it's out there: leaks, mass collection, cross-referencing, use of your identity.
- "Sign in with" permission abuseThird-party sign-in permission abuse means obtaining, through the legitimate "Sign in with…" mechanism, access to data or functions on your main account that goes beyond what the requesting service needs to know. The access granted is long-lasting, and it survives after you stop using the service.
- Personal data exposurePersonal data exposure refers to the unintentional availability of information about you through your own posts and settings. Unlike the other fiches in this family, there's no intrusion or third-party collector at the start: the data is provided, and the problem comes from what it enables once read by someone looking for it.
- ID document fraudID document fraud means obtaining a copy of an official document — ID card, passport, driver's license, proof of address, bank statement — under a plausible pretext, in order to build files in the person's name. It's the upstream step of identity theft: the document handed over is what makes the rest possible.
- Data breachA data breach is the disclosure, whether accidental or through an intrusion, of data an organization holds about its customers, users, or employees. This fiche takes the point of view of the person affected: what does it mean to be caught in a breach, and what can you usefully do about it.
- Data scrapingScraping is the automated collection of publicly accessible information — social media profiles, directories, listing sites, open registries — in order to build usable databases. No system is forced open: the technique consists of reading very fast what anyone could read slowly, which is what makes this topic different from the other fiches on this site.
- Re-identification of anonymous dataRe-identification means recovering the identity of people within a dataset whose direct identifiers have been removed, by cross-referencing it with other sources. It shows that "anonymous" describes an operation performed on a file, not a stable property of that file once it circulates.
- Resale of personal dataResale of personal data is the transfer, for payment or not, of contact and behavioral files to commercial third parties. It's lawful when it rests on validly obtained consent and on informing the people concerned; it accounts for a large share of the solicitations people receive, and the circulation it creates is what makes other methods described on this site possible.
- Abusive ad trackingAd tracking is the tracking of a person's activity across sites and apps in order to build a profile used for targeting. This fiche appears here not as an attack — most of the practice is lawful when consent is properly obtained — but because it produces the raw material other pages on this site describe, and because the consent requested is often obtained through an interface designed for that purpose.
- Identity theftIdentity theft is a third party's sustained use of a real person's identity to carry out acts in their name: taking out a loan or subscription, opening an account, completing an administrative procedure. It differs from identity impersonation in the social-engineering sense, which means posing as someone for the length of a single exchange: here, the borrowing isn't the method but the harm, and its effects are often discovered long afterward.
AI and synthetic content
9 articlesAttacks that use content fabricated by artificial intelligence: a cloned voice, a synthetic face, perfectly written text.
- Malicious chatbotA malicious chatbot is an automated chat interface, presented as support or an assistant, that collects information or steers the user toward a fraudulent action over the course of the conversation.
- Voice cloningVoice cloning is the synthetic reproduction of a person's voice from recorded samples, used to lend credibility to a fraudulent call or voice message.
- Deepfake video callA deepfake video call is the use of a synthetic face and voice in real time during a video call, to get a request — most often a wire transfer — approved by someone who believes they're seeing the person they know.
- Deepfake videoA deepfake video is a sequence fabricated or altered using machine learning, in which a real person's appearance and voice are reproduced to make them appear to say or do things that never happened.
- AI misuse of photosAI misuse of photos is the transformation of existing, publicly accessible images of a person into synthetically produced intimate or compromising content, without their consent.
- Fake AI appA fake AI app is a piece of software, browser extension, or mobile app that presents itself as a well-known artificial intelligence tool, or as privileged access to one, in order to collect credentials or data.
- AI-generated fake profileAn AI-generated fake profile is an account whose photograph, and sometimes its biography and posts, are synthetically produced, in order to present a credible, unverifiable identity.
- AI-generated fake news siteAn AI-generated fake news site is a site imitating the form of an online news outlet, whose articles are produced automatically, and which is used to give an apparent stamp of approval to an offer, a product, or a narrative.
- AI-generated phishingAI-generated phishing refers to fraudulent messages whose wording, personalization, and adaptation to the recipient are produced automatically, without the underlying mechanism of the attack changing.
Blackmail, harassment and personal harm
10 articlesAttacks that target the person directly: blackmail, distribution of content, harassment, surveillance by someone close to you.
- Extortion following a data breachExtortion following a data breach exploits a real compromise that happened at a third party: the perpetrator threatens to publish or resell information about a person or organization unless a payment is made.
- Fake hacking blackmailFake hacking blackmail is a mass-sent extortion message claiming that spyware filmed the victim, demanding payment to prevent a distribution that has no real basis.
- CyberharassmentCyberharassment is the repetition of hostile remarks or behavior directed at a person through electronic communications, resulting in a deterioration of their living conditions.
- Non-consensual sharing of intimate imagesNon-consensual sharing of intimate images is the publication or transmission, without the consent of the person concerned, of sexual content depicting them, generally obtained within a relationship of trust.
- DoxxingDoxxing is the collection and publication of information that identifies or locates a person in the real world, aimed at exposing them to retaliation, harassment, or physical intrusion.
- Harassment raidA harassment raid is a coordinated attack in which a large number of accounts target the same person simultaneously, following a public call-out made on another platform.
- SextortionSextortion is extortion based on intimate content: the perpetrator threatens to distribute it to the victim's circle — family, colleagues, followers — to obtain money, more images, or a continued relationship.
- Stalkerware (surveillance by someone close to you)Stalkerware refers to surveillance apps installed on a person's device by someone close to them with physical access — a spouse, ex-spouse, or parent — to track their communications, location, and activity without their knowledge.
- Swatting (fake emergency report)Swatting is causing law enforcement to intervene at a person's home by falsely reporting a serious situation — a hostage-taking, an armed threat, a bomb threat — in order to harm them.
- Social media profile impersonationProfile impersonation is the creation of an account reusing a real person's name, photograph, and public information, to deceive their circle or harm them by posting under their name.