Account Takeover (ATO)
Account takeover means someone gains unauthorized access to an online account. Recovery must address sign-in, active sessions, and the methods that reset access.
Read term
Loading page...
Glossary
Short, practical explanations of the security terms used across our recovery guides.
Account takeover means someone gains unauthorized access to an online account. Recovery must address sign-in, active sessions, and the methods that reset access.
Read term
Business email compromise uses trusted identities to divert payments or sensitive information. Verify changed instructions through a known contact before acting.
Read term
A configuration profile on iPhone or iPad can install trusted settings, certificates, VPN, and management controls. Learn when profiles are normal and when to.
Read term
A copyright counter-notice is a formal response to a takedown claim. Learn what it means, why timelines matter, and when to get legal advice.
Read term
Credential stuffing is when attackers test stolen username/password pairs across many services. Learn how it works, why it succeeds, and defensive steps that.
Read term
The dark web is content accessible through anonymity networks like Tor. Learn what it is, how stolen data is traded, and what actions reduce real risk after.
Read term
A data breach is unauthorized exposure of personal or business data. Learn how breach data turns into credential stuffing, recovery abuse, and fraud, and what.
Read term
Deepfakes are AI-generated synthetic images, audio, or video used for impersonation and manipulation. Learn the common abuse patterns and safer verification habits.
Read term
DKIM signs outgoing email so receivers can verify it was authorized and not modified in transit. Learn how DKIM fits with SPF/DMARC and why it matters for.
Read term
A DMCA takedown is a copyright-removal request sent to a platform, host, or search provider. Learn what it can remove, what it cannot, and key process risks.
Read term
Doxxing publishes private personal information such as address, phone, or workplace. Learn why it escalates recovery risk and the defensive steps that reduce.
Read term
An incident response plan defines how to detect, contain, and recover from security incidents. Learn the failure modes and what makes a plan actually usable.
Read term
Infostealers steal passwords, cookies, and sessions from your device, then attackers reuse them for account takeovers. Learn what to do first and what makes it.
Read term
Malware is software designed to harm systems or steal data. Learn what malware is, common misconceptions, and safe response steps that improve recovery outcomes.
Read term
MFA fatigue floods you with push prompts until you approve one by mistake. Learn why it works, the warning signs, and defenses that reduce repeat takeovers.
Read term
Mobile Device Management (MDM) lets organizations enforce security policies on phones and tablets. Learn when it is normal, when it is risky, and what to check.
Read term
OAuth lets apps access your account without sharing your password. Learn how connected apps can become a persistence path after compromise, and what to review.
Read term
Passkeys replace passwords with device-backed sign-in. Learn what passkeys are, why they reduce phishing risk, and what to do when passkeys create recovery edge
Read term
Password managers store and generate unique passwords. Learn why they reduce credential stuffing risk, how they help detect phishing, and safe setup practices.
Read term
Password spraying is when attackers try a small set of common passwords across many accounts. Learn how it differs from brute force and what defensive controls.
Read term
Phishing uses deceptive messages or websites to obtain money, information, or account access. Verify requests directly with the service before following links.
Read term
Quishing is phishing delivered through a QR code. Check the destination and the request before entering login details, installing software, or making a payment.
Read term
Ransomware is malware that encrypts systems and demands payment. Learn how ransomware operations work, common entry points, and the steps that reduce damage and
Read term
Security keys are hardware authenticators that protect logins against phishing. Learn how security keys work, common failure modes, and safe setup practices for
Read term
Session hijacking is when an attacker steals or reuses an authenticated session token. Learn how it happens, why password changes can fail, and defensive.
Read term
Sextortion is blackmail involving sexual images or claims. Preserve the threat, avoid sending money or more material, and use appropriate reporting channels.
Read term
Sideloading means installing apps outside official app stores. Learn practical tradeoffs, common abuse patterns, and safer defensive habits.
Read term
SIM swapping transfers a phone number to another SIM or eSIM without permission. It can expose text codes and calls used to recover other accounts.
Read term
Smishing is phishing through text messages. A fake delivery, banking, or account alert may ask you to follow a link, share a code, or install an app.
Read term
Social engineering manipulates people into granting access, sharing information, or sending money. Independent verification interrupts the attacker's request.
Read term
Spear phishing targets a particular person or organization with convincing context. Familiar names and project details do not make a request trustworthy.
Read term
SPF is an email authentication standard that helps receivers detect spoofed mail. Learn what SPF does, how it fails, and why it matters for phishing and.
Read term
Spyware monitors device activity such as messages, location, and logins. Learn why spyware breaks recovery steps, common signs, and defensive ways to respond.
Read term
Stalkerware is monitoring software installed without meaningful consent. Learn why it matters for account recovery, common warning signs, and safer response steps.
Read term
Two-factor authentication (2FA) adds a second proof of identity to logins. Learn what 2FA is, how it fails, and how to use it safely for account recovery.
Read term
Vishing is phishing by voice call or voicemail. A familiar voice or caller ID does not verify the caller; contact the organization through a known number.
Read term
A zero-day vulnerability is a software flaw that is unknown to the vendor or has no patch available. Learn what zero-days mean in practice and how to reduce.
Read term