• Journal
  • About
  • Contact
  • Menu Menu
Are You Familiar with Phishing, Sniffing or Spoofing?

Are You Familiar with Phishing, Sniffing or Spoofing?

Technology keeps inventing useful things. Unfortunately, criminals keep inventing new ways of stealing your passwords, money, identity, files, and occasionally your remaining faith in humanity.

Even if you’re reasonably good with computers, cybersecurity vocabulary has become a fucking zoo. Phishing, smishing, vishing, quishing, scareware, ransomware, spyware, infostealers, ClickFix, AiTM, MFA fatigue, token theft… apparently criminals now have a marketing department.

So here’s a dictionary for ordinary people. What the weird word means, what the nasty little bastard actually does, and how you avoid becoming its lunch.

Yeah, it’s quite long, so let’s start with the most common.

Scam

Let’s start with the broadest term. A scam is any scheme designed to trick you into giving somebody money, information, access, passwords, cryptocurrency, or something else valuable.

The technology changes constantly. Human greed, fear, curiosity, loneliness, and gullibility remain impressively backward-compatible.

How to avoid it: Be suspicious whenever an unexpected person creates urgency and then asks for money, information, access, or immediate action.

Phishing

Phishing is probably the celebrity of online scams. A criminal pretends to be your bank, Microsoft, Google, Amazon, Netflix, the government, your employer, or practically anybody else with a recognizable logo.

The message usually tries to make you click a link, enter a password, provide payment information, open a file, or approve something.

How to avoid it: Don’t use login links in unexpected emails or messages. Open the official app or type the website address yourself.

Spoofing

Spoofing means faking the identity or origin of something so it appears legitimate.

One of the most common examples is caller ID spoofing. A scammer can call somebody while making your phone number, your bank’s number, or another legitimate number appear on the recipient’s screen.

That can even result in innocent people receiving angry callbacks from strangers who genuinely believe they called them.

The same basic trick can be applied to email addresses, websites, domain names, and certain types of network traffic.

How to avoid it: Never trust a call, email, or message solely because the displayed sender looks legitimate. If your bank supposedly calls about something serious, hang up and call the bank yourself using a number you already know is genuine.

Smishing

Smishing is phishing by SMS or text message. Your package couldn’t be delivered. Your toll wasn’t paid. Your bank account has been suspended. Your Netflix payment failed.

Western civilization will apparently collapse unless you click the link within the next seven minutes.

How to avoid it: Don’t use links in unexpected texts. Open the official company’s app or website yourself.

Vishing

Vishing means voice phishing. Someone calls pretending to represent your bank, police department, government agency, Microsoft, Amazon, or another trusted organization.

They may want your password, card information, verification code, money, or remote access to your computer.

AI voice cloning makes the game even more interesting because a familiar voice is no longer absolute proof that you’re speaking to a familiar person.

How to avoid it: Hang up and contact the person or organization yourself through a trusted number.

Social Engineering

Social engineering means hacking the human instead of the computer.

Why spend six weeks defeating sophisticated security when Dave from accounting might reveal the password after a convincing five-minute phone call?

Phishing, fake support calls, romance scams, ClickFix, impersonation, and many other attacks are forms of social engineering.

How to avoid it: Become suspicious whenever somebody combines authority, urgency, fear, secrecy, curiosity, or greed with a request for action.

Impersonation Scam

An impersonation scam is exactly what it sounds like. The scammer pretends to be your bank, employer, police department, tax authority, delivery company, family member, or another trusted person or organization.

The costume changes. The objective usually doesn’t.

Give me your money. Give me your code. Give me access. Do it now.

How to avoid it: Independently contact the supposed person or organization before doing anything important.

Credential Harvesting

Credential harvesting means collecting usernames, passwords, PINs, authentication codes, and other login information.

A fake login page is the classic example. It looks exactly like Microsoft, Google, Facebook, or your bank.

You enter your password. The website says something went wrong.

Meanwhile your password has quietly traveled somewhere considerably less friendly.

How to avoid it: Check the domain before logging in and avoid login links sent through unexpected messages.

Account Takeover

An account takeover, often shortened to ATO, happens when somebody gains control of your online account. Email accounts are especially valuable because access to your email may allow criminals to reset passwords for everything else.

Once inside, attackers can steal information, impersonate you, change passwords, scam your contacts, or access financial services.

How to avoid it: Use unique passwords, MFA, and take unexpected login notifications seriously.

Verification Code or One-Time Password Scam

Your bank sends you a genuine verification code. Then somebody calls saying:

“We just sent you a security code. Please read it to me.”

The code is real.

The person asking for it isn’t.

In many cases, they caused the code to be sent because they’re currently trying to log into your account.

How to avoid it: Never give authentication or verification codes to somebody who contacts you.

MFA Fatigue, MFA Bombing or Push Bombing

Your phone says:

Approve this login?

No.

A minute later:

Approve this login?

No.

Again.

Again.

Again.

Eventually somebody thinks, Jesus Christ, fine, and taps Approve.

That’s MFA fatigue, also called MFA bombing or push bombing.

How to avoid it: Never approve a login you didn’t initiate. Repeated requests may mean somebody already knows your password, so change it.

Password Reuse

Password reuse isn’t an attack by itself, but it makes several attacks dramatically easier.

If the same password unlocks your email, Facebook, Amazon, and some questionable forum you registered for in 2017, the security of all those accounts is now approximately equal to the security of the shittiest one.

How to avoid it: Use a unique password for every important account and let a password manager remember them.

Credential Stuffing

Credential stuffing takes usernames and passwords leaked from one service and automatically tries them on other services.

Your password doesn’t need to be guessed if you already generously gave the same one to a website that got hacked.

How to avoid it: Don’t reuse passwords.

Scareware

Scareware tries to scare you into doing something stupid.

YOUR COMPUTER HAS 8,472 VIRUSES!

YOUR IP ADDRESS HAS BEEN COMPROMISED!

HACKERS ARE WATCHING YOU!

Conveniently, a huge flashing button underneath can fix everything.

How to avoid it: Close the page. Don’t call the number, install the program, or enter payment information.

Tech Support Scam

Someone claiming to be Microsoft, Apple, Norton, your Internet provider, or another technology company tells you that your computer has a serious problem.

Naturally, they need remote access. And maybe your credit card. What could possibly go wrong?

How to avoid it: Never give unsolicited callers remote access to your computer.

Fake Update

A website announces:

Your browser is outdated.

Update Flash Player.

Install this security update immediately.

Except the “update” is malware.

Real browser and operating-system updates generally come from the software itself or the vendor’s official update system, not from some random page screaming at you.

How to avoid it: Update software through its built-in updater or official website.

Malware

Malware means malicious software. It’s the umbrella term. Viruses, Trojans, worms, ransomware, spyware, infostealers, rootkits, and plenty of other unpleasant little creatures all fit underneath it.

So saying “my computer has malware” basically means some shitty software is living in there.

How to avoid it: Keep software updated, use reputable security software, maintain backups, and don’t install random garbage.

Virus

A computer virus is malware that can reproduce by infecting other files or programs.

People often call every malicious program a virus, although technically that’s a little like calling every car a Toyota.

How to avoid it: Keep your operating system and security software updated and don’t execute suspicious files.

Trojan

A Trojan pretends to be something legitimate or desirable while secretly doing something malicious.

It might look like software, a game, a crack, an installer, a document, or a browser extension.

The term comes from the Trojan Horse, meaning humanity has apparently been falling for approximately the same security problem for several thousand years.

How to avoid it: Download programs from trustworthy sources and be particularly suspicious of cracks, cheats, pirated programs, and mystery executables.

Spyware

Spyware secretly monitors or collects information about you.

Depending on the software, that might include browsing activity, messages, passwords, screenshots, files, location information, or keystrokes.

Basically an unwanted digital roommate with serious boundary issues.

How to avoid it: Install software only from trustworthy sources and review app and browser-extension permissions.

Adware

Adware displays advertising, sometimes in places where advertising absolutely wasn’t invited.

The nastier varieties inject ads into websites, redirect searches, track browsing, change browser settings, or bundle themselves with other software.

How to avoid it: Pay attention during software installation instead of treating the Next button like a competitive sport.

Browser Hijacking

Browser hijacking changes how your browser behaves. Your homepage changes. Your searches suddenly go through some weird search engine. Random pages open. Ads appear everywhere.

Your browser has basically acquired a new owner without consulting you.

How to avoid it: Remove suspicious extensions and software, and don’t approve browser changes you didn’t request.

Malicious Browser Extension

Browser extensions can have enormous access to what happens inside your browser. A malicious extension may read websites, redirect searches, inject advertising, steal information, or manipulate pages.

And being inside an official extension store does not automatically make something immortal and trustworthy. Malicious extensions occasionally slip through.

How to avoid it: Install as few extensions as possible, check who made them, and review their requested permissions.

Infostealer

An infostealer is malware specifically designed to steal useful information. It may grab saved browser passwords, cookies, authentication tokens, cryptocurrency wallets, autofill information, documents, and other credentials.

Modern infostealers increasingly target both Windows and macOS systems, including attacks delivered through fake software and ClickFix-style prompts.

How to avoid it: Avoid mystery installers, cracks, fake apps, suspicious extensions, and commands copied from strange websites.

Keylogger

A keylogger records what you type. Passwords. Messages. Credit card numbers. Private conversations. That highly questionable Google search at 2:37 AM.

Everything can potentially become interesting.

How to avoid it: Keep devices clean, use trusted software, and enable MFA so a stolen password alone is less useful.

Ransomware

Ransomware locks or encrypts files and demands money for restoring them. Modern ransomware attacks may also steal the data first and threaten to publish it if the victim refuses to pay.

Paying doesn’t guarantee you’ll get anything back either. Criminal customer support tends to have inconsistent service standards.

How to avoid it: Maintain backups that ransomware cannot easily reach, install updates, and be careful with attachments and software.

Double Extortion

Double extortion is ransomware with an additional kick in the balls. Attackers don’t merely encrypt your files. They steal copies first.

Now they can demand money for decrypting the files and demand money for not publishing the stolen data.

How to avoid it: The same defenses as ransomware apply, but businesses also need good access controls and monitoring for unusual data transfers.

Romance Scam

Someone meets you online. They’re charming. They’re interested. They’re conveniently living somewhere far away. Eventually something terrible happens involving money. Or they discover an amazing investment opportunity.

Romance scammers build trust first because emotional manipulation works better when it has had time to marinate.

How to avoid it: Don’t send significant money or cryptocurrency to somebody you’ve never actually met.

Cryptocurrency Investment Scam or Pig Butchering

The attacker builds a relationship with you first. Then they introduce an amazing investment platform where your cryptocurrency appears to produce spectacular returns.

You invest a little. The numbers go up. You invest more. Then you try to withdraw the money.

Suddenly there are taxes, fees, verification payments, frozen accounts, and several new varieties of bullshit.

How to avoid it: Never take investment advice from a random online acquaintance or romantic interest.

Fake Job and Task Scam

A stranger contacts you through SMS, WhatsApp, Telegram, or another service with an unusually easy remote job. You might be asked to rate products, click things, “optimize” listings, boost apps, or complete simple online tasks.

Eventually, you’ll need to deposit your own money to unlock work or withdraw your imaginary earnings.

The FTC continues to warn about fake recruiters and task scams in 2026.

How to avoid it: Never pay money in order to receive wages or unlock earnings.

Money Mule

A money mule receives or transfers money for somebody else. The money may come from fraud, stolen accounts, or other crimes.

Some people knowingly participate. Others think they’re working a legitimate job or helping an online romantic partner.

Either way, your bank account can become part of somebody else’s criminal plumbing. The FBI specifically warns that fake jobs and romantic relationships are common ways people get recruited as money mules.

How to avoid it: Don’t let strangers use your bank account to receive or forward money.

Deepfake Scam

AI can generate increasingly convincing fake voices, images, and videos. That means your boss can apparently call asking for money while your actual boss is somewhere eating lunch and completely unaware of his exciting new criminal career.

How to avoid it: Independently verify unusual requests involving money or sensitive information, even when the voice or video appears familiar.

Sextortion

Sextortion is blackmail involving sexual or intimate material. A scammer may obtain real images, trick somebody into sending them, fabricate them, or simply claim to have them.

Then comes the demand: Pay me or I send this to everyone you know.

How to avoid it: Be cautious about sending intimate material to people you only know online. If blackmail begins, remember that paying does not guarantee the threats will stop.

SIM Swapping

SIM swapping happens when a criminal convinces or tricks a cellular carrier into transferring your phone number to a SIM or eSIM they control.

Now they receive your calls and SMS verification codes.

Suddenly SMS-based authentication looks considerably less impressive.

How to avoid it: Add additional security to your cellular account and prefer authenticator apps, passkeys, or hardware keys for important services.

Session Hijacking, Cookie Theft or Token Theft

After you log into a website, your browser normally receives a session cookie or authentication token. That’s how the website remembers that you’ve already logged in.

If somebody steals that token, they may be able to impersonate your authenticated browser session without entering your password again.

This is one reason modern infostealers love browser data.

How to avoid it: Protect your computer from malware, avoid suspicious extensions, and sign out or revoke active sessions after an account compromise.

Business Email Compromise

Business Email Compromise, usually called BEC, targets companies. A criminal compromises or impersonates somebody’s email account and requests a payment, invoice change, bank-account change, gift cards, or confidential information.

“Hi, it’s the CEO. I’m in a meeting. Transfer $85,000 immediately and don’t call me.”

Apparently being in a meeting has become a major financial security vulnerability.

How to avoid it: Verify unusual payment requests through another communication method.

Spear Phishing

Regular phishing throws thousands of hooks into the ocean.

Spear phishing chooses a particular victim.

The attacker may research your name, employer, coworkers, suppliers, job title, or projects and make the message specifically relevant to you.

How to avoid it: Don’t assume an email is genuine merely because it knows accurate information about you.

Whaling

Whaling is spear phishing aimed at senior executives, business owners, or other high-value people.

Why catch 500 tiny fish when Bob the CFO can authorize a $600,000 payment before lunch?

How to avoid it: Sensitive financial actions should require independent verification and preferably more than one person’s approval.

Quishing

Because apparently phishing didn’t already have enough cousins. Quishing means phishing through QR codes.

You scan the QR code and land on a fake payment page, login form, or malicious website.

The advantage for criminals is obvious: humans cannot look at a square full of black dots and immediately recognize absolutely-not-your-bank.ru.

How to avoid it: Check the destination before entering passwords or payment information.

Malvertising

Malvertising means malicious advertising. Attackers buy or compromise online advertisements that lead to phishing pages, fake software, malware, or scams.

This can happen even when you’re using a perfectly legitimate search engine.

How to avoid it: Be careful with sponsored search results and download software directly from the developer whenever possible.

SEO Poisoning

SEO poisoning manipulates search results so malicious pages appear when people search for legitimate programs, services, documents, support pages, or information.

A criminal doesn’t necessarily need to send you a malicious link.

Sometimes they simply wait for you to Google it.

Microsoft has documented SEO manipulation being used alongside modern ClickFix campaigns.

How to avoid it: Don’t automatically trust the first search result.

Typosquatting

Typosquatting uses domain names that closely resemble legitimate websites.

Maybe one letter is different. Maybe rn replaces m. Maybe .com becomes something else. You think you’re visiting Microsoft.

You’re visiting Microsofft’s slightly criminal cousin.

How to avoid it: Check important domain names carefully and bookmark frequently used banking or financial sites.

ClickFix

ClickFix is one of the newer attack names worth knowing. A malicious webpage claims something isn’t working and gives you instructions to “fix” the problem.

You might be told to copy something, open Windows Run, PowerShell, Command Prompt, or macOS Terminal, paste the command, and press Enter.

Congratulations. Instead of malware breaking into your computer, you’ve just been persuaded to install it yourself.

ClickFix continues to be actively used in 2026, including campaigns distributing information-stealing malware.

How to avoid it: Never run commands copied from a website simply because the page claims they’re required for verification, downloading, CAPTCHA completion, or fixing an error.

Fake CAPTCHA Scam

A CAPTCHA is supposed to prove you’re human. A fake CAPTCHA may instead tell you to press strange keyboard combinations, open Windows Run, paste something, or execute a command. A real CAPTCHA does not require PowerShell.

Unless Google has become considerably more adventurous than expected.

How to avoid it: If a CAPTCHA asks you to execute commands or install something, leave the site.

CrashFix

CrashFix is a newer variation of ClickFix. Instead of merely pretending something has broken, the attack deliberately causes browser problems and then offers instructions supposedly explaining how to repair them.

Microsoft documented CrashFix in early 2026, where a malicious browser extension deliberately disrupted the browser before convincing victims to execute malicious commands.

How to avoid it: If a website or extension suddenly breaks your browser and then tells you to run system commands, don’t.

OAuth or Consent Phishing

Some attacks don’t need your password at all. Instead, you’re asked to authorize an application to access your account. The Microsoft or Google permission page may be completely genuine. The problem is the application you’re approving.

You may be giving the attacker permission to read your email, files, contacts, or other information.

How to avoid it: Read permission screens instead of treating Allow as decorative furniture.

Device Code Phishing

Some services let televisions, consoles, and other devices log in by displaying a code that you enter on another device. Attackers can abuse this process by giving you their authorization code and convincing you to enter it.

The website itself may be genuine. You’re simply authorizing somebody else’s device.

How to avoid it: Never enter a device code sent by somebody unexpectedly.

Phishing-as-a-Service

We have Software-as-a-Service. Naturally, criminals wanted subscriptions too.

Phishing-as-a-Service, or PhaaS, provides ready-made phishing kits, fake login pages, hosting, dashboards, credential collection, and sometimes MFA interception to other criminals.

The customer no longer needs to be technically impressive.

They just need a credit card and questionable ethics.

How to avoid it: You don’t specifically avoid PhaaS. You avoid the phishing attacks it creates.

Sniffing or Packet Sniffing

Now we get to sniffing. Packet sniffing means capturing and examining network traffic.

Importantly, sniffing itself isn’t automatically malicious. Network administrators and tools such as Wireshark legitimately capture packets to diagnose network problems. NIST defines a packet sniffer as software that monitors network traffic and captures packets.

It becomes a security problem when somebody monitors traffic they aren’t authorized to see.

If sensitive information travels without proper encryption, a malicious sniffer may be able to read it.

How to avoid it: Use encrypted websites and services, keep devices updated, and avoid sending sensitive information over questionable networks.

Man-in-the-Middle Attack

A man-in-the-middle attack, usually shortened to MITM, places an attacker between two communicating systems. You think you’re communicating directly with a website. The website thinks it’s communicating directly with you.

Somebody unwanted is sitting in the middle.

How to avoid it: Use encrypted connections, don’t ignore certificate warnings, and be cautious on untrusted networks.

Adversary-in-the-Middle Attack

Adversary-in-the-middle, or AiTM, is a modern term often used for more sophisticated attacks that proxy communications in real time.

In phishing attacks, you may even interact with the genuine authentication service through the attacker’s proxy.

You enter your password. You complete MFA. The attacker steals the resulting session token.

Very considerate of you.

How to avoid it: Use phishing-resistant authentication such as passkeys or hardware security keys where available.

Evil Twin Wi-Fi

An evil twin is a fake Wi-Fi network pretending to be a legitimate one. You’re at an airport and expect:

Airport_Free_WiFi

The attacker creates:

Airport_Free_WiFi

Your laptop happily connects.

The airport didn’t suddenly become evil. You’re simply connected to somebody else’s network.

How to avoid it: Verify public Wi-Fi names and prefer cellular data for sensitive activity.

Skimming

Skimming steals payment-card information using hardware secretly attached to ATMs, gas pumps, or payment terminals.

Some skimmers also capture PINs using hidden cameras or fake keypads. The FBI continues to list skimming among common real-world frauds.

How to avoid it: Inspect suspicious-looking card readers, cover the keypad when entering your PIN, and use contactless payment where possible.

Formjacking or Web Skimming

Web skimming is the online cousin of card skimming.

Malicious code gets inserted into a legitimate shopping website and quietly copies the information you enter into payment forms.

You may actually be buying something from the real store.

Unfortunately, somebody else is also receiving your card information.

How to avoid it: Customers have limited control over compromised websites, but payment services and virtual card numbers can reduce exposure.

Brute-Force Attack

A brute-force attack repeatedly guesses passwords until one works. It isn’t necessarily sophisticated.

It’s the digital equivalent of trying every key on an enormous keyring, except computers don’t get bored.

How to avoid it: Use long passwords, MFA, and unique credentials.

Dictionary Attack

A dictionary attack is a slightly smarter version of brute force. Instead of trying every possible character combination, it starts with common words, passwords, names, and predictable patterns.

password123 probably enters the tournament fairly early.

How to avoid it: Use long, unpredictable passwords rather than ordinary words with a number glued onto the end.

Password Spraying

Password spraying tries a few common passwords against many different accounts.

That helps attackers avoid locking one account by repeatedly attacking it.

How to avoid it: Avoid common passwords and use MFA.

Botnet

A botnet is a collection of infected computers, servers, routers, cameras, and other devices controlled remotely. The owners may have absolutely no idea their hardware has joined organized cybercrime.

Botnets can distribute spam, spread malware, launch DDoS attacks, or perform other tasks.

How to avoid it: Update Internet-connected devices, change default passwords, and disable unnecessary remote access.

DDoS Attack

A Distributed Denial-of-Service, or DDoS, attack floods a website or service with more traffic than it can handle.

Imagine 100,000 people simultaneously standing in a supermarket entrance and refusing to move.

Nobody needs to steal anything. Nobody else can get inside.

How to avoid it: Ordinary users generally can’t. Website operators use specialized DDoS protection, filtering, CDNs, and redundant infrastructure.

Cryptojacking

Cryptojacking secretly uses your computing resources to mine cryptocurrency for somebody else. Your computer gets hotter. The fans get louder. Performance drops. Your electricity meter develops anxiety.

Someone you’ve never met earns the cryptocurrency.

How to avoid it: Keep systems updated and investigate unexplained CPU or GPU usage.

Worm

A worm is malware capable of spreading between computers automatically. Unlike a traditional virus, it may not require somebody to manually open an infected file on every machine.

Once inside a vulnerable network, it can travel by itself.

How to avoid it: Install security updates, use firewalls, and don’t expose unnecessary services directly to the Internet.

Remote Access Trojan

A Remote Access Trojan, or RAT, gives an attacker remote control over an infected machine. Depending on the malware, they may access files, execute commands, install programs, record keystrokes, or monitor activity.

It’s basically remote desktop software whose administrator you definitely didn’t hire.

How to avoid it: Don’t install unknown software or give remote access to strangers.

Rootkit

A rootkit is designed to hide malicious activity and maintain deep access to a computer.

Instead of merely breaking into the house, the burglar moves into the basement, paints himself the same color as the wall, and hopes nobody notices.

How to avoid it: Keep systems updated and use reputable security software. Serious rootkit infections may justify reinstalling the operating system from a known-clean source.

Backdoor

A backdoor provides hidden access to a computer, application, or network while bypassing normal authentication.

Attackers may install one so they can return later.

How to avoid it: Keep software patched and don’t install unknown programs.

Dropper and Loader

Some malware isn’t the final malware. A dropper or loader exists mainly to get something else onto the computer and execute it.

Think of it as the delivery driver.

The package is considerably less pleasant than pizza.

How to avoid it: The same rules apply: avoid unknown executables, fake installers, malicious documents, and strange commands.

Fileless Malware

Traditional malware makes you imagine a suspicious .exe file sitting somewhere. Fileless malware may operate primarily in memory or abuse legitimate tools already available on the computer.

That can make traditional file-based detection more difficult.

How to avoid it: Keep systems updated, use modern security protection, and don’t execute suspicious scripts or commands.

Living off the Land

Living off the land means attackers abuse legitimate tools already installed on the victim’s system.

PowerShell, scripting engines, system utilities, and administrative tools can all be useful to attackers.

Modern ClickFix attacks frequently rely on exactly this idea: instead of bringing a suspicious program through the front door, convince the victim to run legitimate system tools for them.

How to avoid it: Never assume a command is safe merely because it uses Windows or macOS tools.

Vulnerability

A vulnerability is a weakness in software, hardware, configuration, or design. It doesn’t necessarily mean somebody is actively exploiting it. It simply means there’s a door that perhaps shouldn’t be there.

How to avoid it: Keep operating systems, browsers, apps, routers, plugins, and other Internet-connected devices updated.

Exploit

An exploit is the technique or code used to take advantage of a vulnerability. The vulnerability is the hole.

The exploit is what somebody sticks through it.

How to avoid it: Install security updates and remove obsolete software that no longer receives them.

Zero-Day

A zero-day is a vulnerability that defenders had essentially no time to fix before it became usable or known to attackers, often because no patch existed yet.

The standard advice of “install the update” becomes somewhat inconvenient when the update hasn’t been invented.

How to avoid it: There is no magical defense. Updated systems, limited privileges, security software, isolation, and backups reduce the potential damage.

Zero-Click Attack

A zero-click attack requires little or no action from the victim.

No suspicious attachment.
No button.
No FREE_MOVIE.exe.

A vulnerable application may process malicious content automatically.

These attacks tend to be considerably more sophisticated than ordinary phishing.

How to avoid it: Keep devices and applications updated. With genuine zero-click vulnerabilities, platform security matters more than user cleverness.

Supply-Chain Attack

A supply-chain attack compromises something you already trust. Instead of attacking you directly, criminals compromise a software company, update system, package, library, service provider, or other supplier.

The malicious content then reaches users through what appears to be a legitimate channel.

How to avoid it: Ordinary users have limited control here. Keep software current, remove unnecessary applications, and use reputable vendors.

Watering-Hole Attack

A watering-hole attack compromises a website or online service regularly visited by a particular group of targets. Instead of hunting victims individually, attackers poison somewhere they already gather.

How to avoid it: Keep browsers and operating systems patched because even legitimate websites can occasionally become part of an attack.

Wiper Malware

Wiper malware is designed primarily to destroy data or make systems unusable. Ransomware says:

Give us money and perhaps we’ll give your files back.

A wiper may simply say:

No.

How to avoid it: Maintain offline or otherwise protected backups and keep critical systems properly secured.

Pharming

Pharming redirects users toward fake websites even when they believe they’re going somewhere legitimate.

This can involve compromised DNS settings, malware, routers, or network infrastructure.

Phishing asks you to walk into the wrong building.

Pharming changes the road signs.

How to avoid it: Secure and update your router, use trusted DNS services, and never ignore browser certificate warnings.

Baiting

Baiting uses curiosity or greed to make you perform the dangerous action yourself.

CONFIDENTIAL SALARIES.xlsx

PRIVATE PHOTOS.zip

FREE_MOVIE.exe

Or perhaps a USB drive conveniently abandoned somewhere.

Curiosity completes the attack.

How to avoid it: Don’t open mystery files or connect unknown USB devices simply because their contents look interesting.

Shoulder Surfing

After all this talk about malware, AI, encrypted sessions, and advanced cyberattacks, we arrive at the magnificent technology known as:

Looking over somebody’s shoulder.

Shoulder surfing means watching somebody enter a PIN, password, unlock code, or other sensitive information.

No malware.
No Russian hacker basement.

Just some asshole standing behind you.

How to avoid it: Be aware of who’s around you when entering sensitive information and cover PIN pads when appropriate.

The Most Important Security Term: Common Sense

There isn’t an antivirus program capable of completely protecting somebody who enthusiastically clicks every attachment, reuses one password everywhere, installs FREE_GTA7_CRACK_REAL_FINAL_v7.exe, approves unexpected login requests, gives strangers remote access, and pastes mysterious PowerShell commands because a CAPTCHA told them to.

And that’s perhaps the most important thing to understand about modern cybercrime.

The attacker increasingly doesn’t need to hack your computer.

They hack you.

Modern ClickFix attacks persuade users to execute malicious commands themselves. Infostealers steal already-authenticated browser sessions. MFA bombing tries to annoy people into approving access. Device-code phishing can abuse legitimate authentication systems. Malicious extensions can arrive disguised as useful browser tools.

But underneath all that complicated vocabulary, scammers still press the same ancient human buttons:

Fear. Urgency. Greed. Curiosity. Authority. Trust. Sex.

So perhaps the simplest cybersecurity rule is this:

If somebody unexpectedly wants your password, money, authentication code, personal information, remote access, permission, cryptocurrency, or immediate action, stop.

Don’t use their link. Don’t use their phone number. Don’t trust their explanation just because the email looks professional, the website looks convincing, or the correct phone number appears on your screen.

Verify it independently.

Technology will keep changing, and criminals will keep inventing new tricks, new names, and new ways to make old scams look convincing again. You don’t need to become a cybersecurity expert, but knowing what these terms mean makes it much harder for someone to catch you off guard.

The Internet should make life easier, not turn every email, phone call, QR code, login screen, and software update into a small exercise in suspicion.

Having to learn an entire dictionary of scams, malware, manipulation, and digital fraud just to use the Internet safely is ridiculous. It sucks.

Support and Keep the Frustration Online

IT SUCKS! is an independent blog built on sarcasm, bad decisions, and everyday nonsense. If you enjoy reading it, a small tip helps keep it going.

Leave a tip

Share this article

  1. Chris
    Chris says:
    September 1, 2026 at 1:14 am

    Solid advice; well presented, too, I’m bookmarking this as a handy reference list to share with others. Pragmatically speaking, however, most people are lazy, stupid, and complacent; all too entrenched in their bubble of convenience. In other words, people don’t bother with IT security.

    Case in point: I have literally begged my sister (a millennial working in marketing; not exactly a Luddite or IT-illiterate) to use a password manager, any password manager, even the browser’s. She stubbornly refuses to. It’s “too much of a hassle”, so she prefers to keep all her (insecure, manually created passwords) in a .docx sitting unencrypted on her drive (running Windows 11, may I add).

    Then again, there are people who don’t even bother using ublock, so when I talk about Veracrypt or gpg I surely come across as some alien species 🤷‍♂️

    Reply
    • Milan
      Milan says:
      September 1, 2026 at 7:53 am

      Hi Chris, thanks for the comment! Even as an experienced computer guy who has done IT support, I had to research some of these terms. Criminals keep inventing new tricks as technology evolves, and English makes it ridiculously easy to invent a new “-ishing” or “-jacking” word every week.

      I understand your sister to some extent. She is one of millions of people who simply don’t want to spend time thinking about security. That indifference is precisely what criminals exploit. People want convenience, and security usually introduces at least a little friction.

      I’m glad you mentioned VeraCrypt. I previously used TrueCrypt myself. Encrypting a drive provides excellent protection, particularly if a computer is lost or stolen. No backdoor has been discovered in VeraCrypt, and there is no credible public evidence that it contains one. The caveat is that there hasn’t been a comprehensive independent audit of the current code since the BSI evaluation published in 2020.

      At the very least, Windows users can enable BitLocker or Device Encryption where available. It takes only a few clicks, although they should also check where the recovery key is stored and keep their own safe copy. But as your sister demonstrates, even a few clicks can apparently be too much hassle. :)

      Reply

Leave a Comment

Do you have a different opinion, or does it suck in a different way? Leave a comment. No registration, no account setup, just say what you think. Thanks.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Related Articles

The Author

Browser Extension to Stop Autoplay Videos and Audio

26th May 2026 Read more
Ursula von der Leyen talking about AI

Is Europe Becoming an AI Superpower? Ursula Says So!

25th August 2026 Read more
Reddit co-founder and CEO Steven Huffman

Reddit Account Banned: What to Do?

10th August 2026 Read more
Icon

Random Articles

  • Nice People With No Responsibility
  • Interesting How I Became Lazy With AI
  • Dear Mister President, Use a PR Agency
  • Have You Backed Up Your Data?
  • Can AI Build a Complete App or Website?

Wisdom of the Day

Thursday is the day your productivity is technically present but emotionally dead in a ditch.

Legal & Fashionable Stuff

All right, here we go. Environmental Responsibility is included because that is very fashionable these days. Looking for a cookie policy? Bad luck. No cookies, no cookie policy, no annoying banner. Shocking, I know.

  • Gravatar

Legal

Terms and Conditions
Privacy Policy
Risk Management Statement

Editorial

Comment Policy
Media and Press Policy
Whistleblowing Policy

Responsibility

Environmental Responsibility
Diversity and Inclusion Statement
Supplier Code of Conduct

White logo IT SUCKS!

Copyright ©2026 IT SUCKS! All rights reserved. Sharing article links is fine. Copying, scraping, republishing, or pretending the content is yours is not.

Icon Mosquitoes Are Basically Biological TerroristsMosquito Icon Mark Zuckerberg Meta founder and CEOWho Killed the Friend?