Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-508 — Shoulder Surfing
CAPEC-508

Shoulder Surfing

TLP:CLEAR

Description

Typical severity: High. Likelihood of attack: High. In a shoulder surfing attack, an adversary observes an unaware individual's keystrokes, screen content, or conversations with the goal of obtaining sensitive information. One motive for this attack is to obtain sensitive information about the target for financial, personal, political, or other gains. From an insider threat perspective, an additional motive could be to obtain system/application credentials or cryptographic keys. Shoulder surfing attacks are accomplished by observing the content "over the victim's shoulder", as implied by the name of this attack.

Mitigation

Be mindful of your surroundings when discussing or viewing sensitive information in public areas. | Pertaining to insider threats, ensure that sensitive information is not displayed to nor discussed around individuals without need-to-know access to said information.

Details

Platforms
Physical-security
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.