Cybersecurity Threats, Explained
Plain-language explanations of the attack methods that target businesses every day. No jargon, no fluff.
Social Engineering
Spear Phishing
Spear phishing is a targeted email attack where criminals research a specific person and craft a message designed just for them. Unlike mass spam, these emails reference real details about your job, your colleagues, or recent company events to appear legitimate. They are the number one way attackers breach organizations today.
Learn moreBusiness Email Compromise
Business email compromise is when an attacker impersonates a senior executive — usually the CEO or CFO — to trick an employee into wiring money or sharing sensitive data. These attacks don't require any malware or hacking; they rely entirely on convincing someone that a fraudulent request is coming from their boss. The FBI reports BEC has caused over $50 billion in losses worldwide.
Learn moreSocial Engineering
Social engineering is the practice of manipulating people into giving up confidential information or taking actions that compromise security. Instead of breaking through firewalls and encryption, attackers exploit trust, authority, urgency, and helpfulness — basic human instincts that no software patch can fix. It is the foundation of nearly every major breach.
Learn morePretexting
Pretexting is when an attacker creates a fabricated scenario — a "pretext" — to trick someone into sharing information or performing an action they normally wouldn't. Think of it as method acting for criminals: they invent a believable character and situation, then play that role convincingly enough to bypass your team's natural skepticism. The quality of the pretext depends entirely on how much real information the attacker can gather beforehand.
Learn moreWhaling
Whaling is a form of phishing that specifically targets senior executives — the "big fish" in an organization. These attacks are highly personalized, well-researched, and designed to exploit the authority and access that come with leadership positions. Because executives can authorize large transactions, access sensitive data, and override security procedures, a single successful whaling attack can have catastrophic consequences.
Learn moreVishing
Vishing — short for "voice phishing" — is when attackers use phone calls instead of emails to manipulate people into sharing sensitive information or taking harmful actions. Phone calls create a sense of immediacy and personal connection that emails can't match, and they bypass all of your email security filters. With AI voice cloning now widely available, attackers can even impersonate specific people your team knows and trusts.
Learn moreSmishing
Smishing is phishing delivered by SMS. Messages impersonate banks, parcel carriers, IT help desks, or executives and push victims to fake login pages or callback numbers. Mobile screens hide full URLs, which makes hasty taps especially dangerous.
Learn moreVendor Email Compromise
Vendor email compromise is BEC aimed through a trusted supplier. Attackers breach or spoof a vendor, then send altered invoices or payment instructions to that vendor's customers — riding existing business relationships that finance teams already trust.
Learn moreQuishing (QR Phishing)
Quishing is phishing that uses QR codes instead of (or in addition to) links. Victims scan with a phone, land on a malicious page, and often never see a full desktop URL bar. Printed mailers and slide decks make the tactic especially effective.
Learn moreDeepfake Vishing
Deepfake vishing combines voice phishing with AI-generated or cloned speech. Attackers impersonate an executive's voice on a call or voicemail to pressure finance or IT into urgent action. Public talks, podcasts, and webinars supply training audio.
Learn moreExecutive Impersonation
Executive impersonation is any channel — email, phone, Slack, Teams — where an attacker pretends to be a senior leader to coerce action. Whaling is the email-centric form; modern campaigns mix channels and deepfakes.
Learn moreHelp Desk Social Engineering
Help desk social engineering targets your support staff — not your executives. Attackers impersonate employees and persuade agents to reset MFA, enroll a new device, or unlock accounts. Good OSINT makes the caller sound like a tired coworker who just needs to get into email.
Learn moreCredential Attacks
Credential Stuffing
Credential stuffing is when attackers take usernames and passwords leaked from one breach and automatically try them on other services. Because most people reuse passwords, a breach at a shopping site or social network can give attackers working credentials for your corporate email, VPN, or cloud platforms. It is automated, fast, and alarmingly effective.
Learn moreMFA Fatigue
MFA fatigue is an attack where a criminal who already has your password repeatedly triggers multi-factor authentication prompts — the push notifications on your phone — until you approve one just to make them stop. It exploits the very security measure designed to protect you by turning it into an annoyance that people instinctively dismiss. This technique has been used in several high-profile breaches.
Learn morePassword Spraying
Password spraying tests a small set of common passwords against many usernames — the opposite of hammering one account. It stays under lockout thresholds while exploiting predictable passwords and exposed username formats.
Learn moreOAuth Phishing
OAuth phishing does not always steal your password. It tricks you into clicking "Allow" on a third-party app consent screen, granting mailbox or files access to an attacker-controlled application — access that can survive a password change.
Learn moreSession Hijacking
Session hijacking lets an attacker reuse an already-authenticated session — browser cookies, tokens, or SSO artifacts — instead of guessing your password. MFA that only protects login can be bypassed if the session itself is stolen.
Learn moreDark Web Credential Exposure
Dark web credential exposure means employee emails and passwords from previous breaches (or infostealer logs) are circulating in criminal markets. Attackers retry those pairs against your SSO, email, and VPN — often successfully when people reuse passwords.
Learn moreInfrastructure
Tenant Compromise
Tenant compromise is when an attacker gains administrative control over your organization's cloud environment — your Microsoft 365 tenant, Google Workspace, or AWS account. Unlike stealing a single employee's password, this gives the attacker the keys to everything: every email, every file, every application, and every user account in your cloud infrastructure. It is the most devastating outcome of a successful credential attack.
Learn moreRansomware
Ransomware is malware that locks your files or systems and demands payment for restoration. Modern campaigns often combine encryption with data theft and public shaming. Attackers rarely start with the ransomware itself — they start with reconnaissance to find who can authorize payment and which systems will hurt most if taken offline.
Learn moreSupply Chain Attack
A supply chain attack reaches your organization through a third party — software updates, managed providers, or operational vendors. Instead of breaking your front door, attackers break someone you already let inside.
Learn moreDNS Hijacking
DNS hijacking redirects users who type your real domain to attacker infrastructure by altering DNS records or registrar control. Victims see the correct hostname in the browser while landing on a fake site — a powerful path for mass credential theft.
Learn moreWatering Hole Attack
A watering hole attack compromises a website your target audience already trusts — an industry forum, local news site, or vendor portal — and waits for victims to visit. Instead of chasing users with email, attackers poison a place they already go.
Learn moreMalicious Email Forwarding Rules
After gaining mailbox access, attackers often create hidden forwarding or redirect rules that copy sensitive mail to an external address — or move fraud-related threads out of sight. Victims keep working while the attacker silently watches invoices, resets, and executive threads.
Learn moreReconnaissance
OSINT Reconnaissance
OSINT reconnaissance — Open Source Intelligence gathering — is the first phase of nearly every targeted cyberattack. It's the process of collecting publicly available information about an organization and its people to plan an attack. Everything from your company website and LinkedIn profiles to job postings, DNS records, and conference presentations becomes intelligence. This is exactly the same process AiVersary uses, but we do it first so you can fix what's exposed.
Learn moreLookalike Domains
Lookalike domains are registered names that visually or typographically resemble a trusted brand — rn instead of m, extra letters, or alternate TLDs. They power phishing sites, fraudulent invoices, and executive impersonation that bypass casual visual checks.
Learn moreInitial Access Broker
Initial access brokers are criminals who specialize in getting a foothold — VPN, RDP, Citrix, or cloud admin — then selling that access to ransomware crews and other buyers. They industrialize the first step of an intrusion.
Learn moreAttack Surface Management
Attack surface management is the practice of continuously discovering and tracking the systems you expose to the internet — domains, hosts, cloud assets, and certificates. It answers "what do we own that is reachable?" It does not by itself answer "how would an attacker socially engineer our people?"
Learn moreKnowledge is defense. Action is better.
AiVERSARY identifies which of these threats apply to your organization specifically. $499 per report.
Get Your Threat Report