
Cybersecurity Glossary
From account takeover to two-factor authentication: In our glossary, you’ll find clear definitions of the most important terms surrounding identity protection and cybersecurity.
We translate complex technical jargon into easy-to-understand language so you can understand the vocabulary of cybercriminals and proactively protect yourself against identity theft.
59 terms found
A
- Account Takeover (ATO)
Account takeover (ATO) refers to the theft of an online account by third parties. Criminals gain unauthorised access (using hacked passwords, for instance), often locking out the actual user, and then use the account to commit crimes such as fraud or stealing data.
- Anonymisation
Anonymisation is the process of changing personal data so that it can no longer be attributed to any specific person. Unlike pseudonymisation, this process usually cannot be undone and helps to protect people’s privacy.
B
- Brute Force
“Brute force” is when attackers use automated software to try out billions of password combinations per second until they find the correct credentials.
C
- Catfishing
In this case, scammers create falsified profiles in social networks or dating apps to establish emotional relationships with their victims so that they can financially exploit or manipulate them later.
- Credential Stuffing
An automated attack where criminals use lists containing stolen user names and passwords to log in to other services. Since many people use the same password everywhere, this scam is often successful.
- Cyber Intelligence
Comprehensive analysis of the position with regard to digital threats. It combines technical data with human analysis and geopolitical context to proactively protect organisations against attacks before they take place.
D
- Dark Web (Darknet)
A hidden part of the internet that is only accessible with special software (such as the Tor browser). It provides a high degree of anonymity, but is unfortunately often used as a marketplace for stolen data and illegal goods.
- Data Breach
A legal term (often in the context of EU GDPR) that describes when personal data is lost or has been illegally transmitted. Such breaches often need to be reported to the authorities.
- Data Leak
The unintentional disclosure of sensitive information (for example, due to an incorrect server configuration or a security gap) that allows unauthorised people to view data online.
- Data Security
The protection of data against loss, manipulation, or unauthorised access through technical measures such as encryption, firewalls, and backups.
- Deep Web
All the content on the internet that is not collected by search engines such as Google (e.g., password-protected databases or e-mail mailboxes). It is much bigger than the “visible” web and is not necessarily unsafe.
- Digital Identity
Your digital identity is the sum of all the traces you have left behind online – it is like your digital profile. It consists of data that you provide during online banking, through social media, or while shopping. Anyone who controls this profile can present themselves as a digital version of “you”.
- Doxing
Searching for and sharing a specific person’s private information (such as their address, phone number, or workplace) online with the intention of intimidating or doing harm to the victim.
E
- End-to-End Encryption
A security procedure where the sender’s data is encrypted and only decrypted again once it reaches the recipient. No one in between – not even the third-party provider – can read the content.
- External Attack Surface Management (EASM)
The continuous monitoring of all externally visible digital vulnerabilities in a company (e.g., forgotten sub-domains or open ports) to minimise the “attack surface” for hackers.
F
- Firewall
A digital protective wall that monitors a network’s incoming and outgoing data traffic and blocks suspicious connections based on defined security rules.
- Fraud Prevention
All the measures and technologies aimed at identifying and preventing fraudulent activities (such as credit card fraud or identity misuse) in real time.
G
- Gateway
A node connecting two networks. In terms of security, it often serves as a control point for filtering data from the internet before it reaches the company’s internal network.
- Geoblocking
A technology that restricts or blocks access to internet content based on the geographical location of the user (which is determined by the IP address).
H
- Hacking
The exploitation of security gaps in computer systems. While “ethical hackers” do this to close gaps, criminals do so to steal data or disrupt systems.
- Honeypot
A “honeypot” is a system that is consciously designed to be insecure as a trap for hackers. It lures in attackers to analyse their methods without jeopardising the company’s actual network.
- HTTPS
The encrypted version of internet protocol. It ensures that the transmission of data between you and a website is secure. However, HTTPS only protects the method of transmission; it does not provide protection against fraudulent content on the destination page.
I
- Identity Theft
Identity theft is when criminals use your personal data (for instance, your name, credit card number, or credentials) to impersonate you and commit crimes or fraud. Since stolen data often circulates online for many years, it is costly and time-consuming to clear up. According to the German Federal Office for Information Security (BSI), this is one of the three biggest risks for internet users.
- Incident Response
A company’s organised process for responding to a security incident (such as a hacker attack) to limit damages and restore normal operations quickly.
- Incognito Mode
A browser setting that prevents cookies, your history, or form data from being saved on your device. Caution: this does not make you invisible to your internet provider or the website itself!
- Infostealer
An “information stealer” is malware that ends up on your device unnoticed. It spies on passwords, catches e-mails, or records your keystrokes (keylogging) to send sensitive data to criminals.
- IP Address
The IP address is the digital address of your device on the internet. It is required to ensure that data packages find their destination or that a website can be displayed on your screen, for instance.
J
- Juice Jacking
An attack where criminals use manipulated USB charging stations (at airports, for instance) to secretly run malware on your mobile phone and steal data while you charge it.
K
- Keylogging
Keylogging is when malware logs each of your keystrokes in secret. Criminals use this as a digital bugging device for reading passwords, PINs, or confidential information as you enter them.
L
- Least Privilege Principle
A security concept where users and programmes are only given exactly the access rights that they absolutely require for their current task – nothing more and nothing less.
M
- Malware
Malware is the collective term for any “malicious software”. It includes viruses, trojans, or spyware programmed to cause harm on your device, steal data, or spy on you – often without your knowledge.
- Multi Factor Authentication (MFA)
A login method that requires at least two different forms of proof for your identity (for instance, both your password and your fingerprint or code on your mobile phone).
N
- Next Generation Firewall
A modern firewall that, as well as blocking IP addresses, also performs in-depth checks of the contents of data packages for hidden malware.
O
- Open Source Intelligence (OSINT)
The collection and analysis of information from publicly accessible sources (such as the internet, social media, public registers, etc.) to uncover security risks or threats at an early stage.
P
- Password Manager
A password manager is a digital tool that stores your password securely with encryption. You then just need to remember one single, strong main password. It is available as a programme for computers or as an app for smartphones.
- Phishing
Phishing is a type of scam where criminals try to steal your personal data. To do so, they send falsified e-mails or messages to trick you into revealing passwords or credit card numbers.
- Pig Butchering
An insidious kind of scam where the culprit spends weeks building up trust with a victim (“fattening them up”) to encourage them to then make large investments in fake crypto platforms (the “butchering”).
Q
- Quishing
An amalgamation of the terms “QR code” and “phishing”. This is when manipulated QR codes (on parking tickets or letters, for instance) are used to direct users to fraudulent payment sites.
R
- Ransomware
Extortion software that encrypts your files and only releases them again once a ransom has been paid (usually in Bitcoin). According to a 2025 report by the BSI, it remains one of the most critical threats that businesses face.
- Router
The router is the device that distributes the internet signal in your home. It receives the connection from your provider and relays it to your devices through a cable or WLAN.
S
- Sextortion
An extortion method where criminals claim to have intimate pictures of the victim (which is often a lie) and threaten to share them unless money is paid.
- Shadow IT
The use of hardware or software within an organisation without the consent or knowledge of the IT department. This poses a high security risk, because these tools are not monitored.
- SIM Swapping
SIM swapping is a type of identity theft where criminals copy your mobile phone number to their own SIM card. That lets them access your accounts linked to this number.
- Smishing
Smishing (SMS + phishing) refers to the theft of data through text messages. Criminals send SMS messages with urgent pretexts such as package deliveries or account blocks in order to get you to click on a link, where your passwords or bank details are collected on a fraudulent webpage.
- Spam Filter
The spam filter is a feature in e-mail programmes that moves undesired e-mails to a specific folder. That keeps your inbox free of unwanted advertising or scam attempts.
- Spyware
Software that specialises in spying on you in secret, recording your user behaviour, and sending this information to third parties without your knowledge.
- Strong Password
A strong password is hard to guess. It consists of a combination of uppercase and lowercase letters, numbers, and special characters and should be unique for every service.
- Suspicious SMS
A suspicious SMS is a fraudulent message that pressures you to click a link, for instance, to disclose your data or transfer money. You can often identify them by spelling mistakes, unknown senders, and urgent, threatening language. It is best to delete the SMS immediately and to never click on anything.
T
- Tor Browser
A specialist web browser that routes your connection across multiple servers worldwide (onion principle) to obscure your tracks online and enable access to the darknet.
- Trojan
Malware disguised as a useful programme. As soon as you open it, it installs other malware in the background or opens a back door for hackers.
- Two-Factor Authentication (2FA)
Two-factor authentication is an additional security measure for your accounts. Alongside your password, you require a second, unrelated form of proof (such as a code sent by SMS) to log in.
U
- URL Shortener
Services that convert long internet addresses into short links (for instance, bit.ly). Criminals often use them to conceal the actual destination of a dangerous link.
V
- Vishing
“Voice phishing” – attempts at fraud over the phone. Attackers pretend to be bank staff or support technicians to fraudulently obtain sensitive data or money transfers.
- VPN (Virtual Private Network)
A VPN is a service that establishes a secure and encrypted connection to the internet. It hides your IP address and protects your data, especially on public networks.
W
- Whaling
A targeted form of phishing aimed at “big fish” (board members, CEOs) in order to cause massive damage by exploiting their extensive powers.
X
- XML External Entity (XXE)
A technical attack on programmes that process XML data. In such cases, the system is forced to disclose internal files or attack other servers on the network.
Y
- YubiKey
A well known physical security key that is used for two-factor authentication. It usually has to be plugged into a USB port or held up to a mobile phone to approve a login.
Z
- Zero Trust Security
A security model that works based on the principle “never trust, always verify”. Every request to a network is checked, regardless of whether it comes from inside or outside the organisation.
Social engineering is a method where criminals do not hack computers, but manipulate people. Through deceitful means such as fraudulent calls from “support” or fake e-mails, you are tricked into willingly revealing passwords or transferring money. It is a kind of digital “grandparent scam”.