Cyber Rebels

Cyber Threats Explained

Understanding what they are, how they appear and what helps reduce the risk

Cyber threats do not always arrive looking like attacks. They can appear as an ordinary email, a familiar login screen, a phone call, a supplier request, a file somebody needs for work or a message that arrives at exactly the right moment.

That is part of what makes them difficult to recognise. The technology matters, but so does the situation around it: who the request appears to come from, what somebody is trying to get done and whether anything feels unusual enough to justify stopping.

This guide explains some of the cyber threats people and organisations may encounter, what the terms actually mean, how they can appear during everyday work and the practical steps that can reduce the chance of them succeeding.

You do not need to memorise every threat on this page. The aim is to understand the patterns behind them well enough to recognise when something deserves another look.

Team discussing cybersecurity and phishing prevention strategies.

Emails, Messages & Calls

These are some of the most familiar cyber threats because they arrive through the same channels people already use for ordinary work. What makes them effective is often not how suspicious they look, but how naturally the request fits what somebody is already doing.

Phishing

What it isPhishing is when somebody uses a fake or compromised email or message to persuade you to click a link, open a file, enter information or take another action that benefits the attacker.

How it worksThe message is designed to feel familiar, relevant or believable. It may appear to come from a colleague, supplier or service you already use and often arrives with a reason to act now rather than investigate first.

What it can look likeYou are waiting for a document and an email arrives saying it is ready to review. The sender looks right and opening the file is exactly what you expected to do next.

What helps reduce the riskLook for unexpected changes in the request, route or destination rather than relying only on obvious warning signs. For sensitive actions, use a known route to verify the request. Organisations should also make reporting easy and use technical controls so recognising phishing does not depend entirely on the person receiving it.

Smishing

What it isSmishing is phishing carried out through SMS, text messages or similar mobile messaging services.

How it worksThe message usually gives somebody a believable reason to act quickly, such as a missed delivery, failed payment or account problem. Phones make it particularly easy to move from reading the message to tapping the link without seeing much information about where it leads.

What it can look likeA text says a parcel could not be delivered and asks you to pay a small fee. You happen to be expecting a parcel, so the request fits something already happening in your day.

What helps reduce the riskAvoid using unexpected message links for important actions. Open the organisation’s official website or app yourself and check the request there.

Vishing

What it isVishing is social engineering carried out through a phone or voice call.

How it worksThe caller may pretend to be from a bank, IT support team, supplier or another trusted organisation. A confident explanation, familiar terminology and a believable problem can make following their instructions feel entirely reasonable.

What it can look likeSomeone calls saying there has been suspicious activity on an account and offers to help secure it. They sound professional and already appear to know information about you or the organisation.

What helps reduce the riskIf the caller asks for credentials, sensitive information, a payment or an unusual action, end the call and contact the organisation through a number or route you already trust.

Business Email Compromise (BEC)

What it isBusiness Email Compromise is when attackers use a compromised or convincingly impersonated business email account to influence payments, information sharing or other valuable actions.

How it worksAttackers may monitor genuine conversations and wait for the right moment to introduce a small but important change, such as different bank details or a new payment instruction.

What it can look likeAn invoice is already expected. A message arrives inside the existing conversation with the same names, tone and project details, but asks for the payment to be sent to a different account.

What helps reduce the riskIndependently verify changes to payment details, sensitive financial instructions and other high-consequence requests through a known contact route. Do not use the contact information contained only in the request you are trying to verify.

Social Engineering

What it isSocial engineering is the use of manipulation, trust or context to influence somebody into sharing information, granting access or taking an action.

How it worksRather than attacking technology directly, the attacker creates a situation in which complying feels helpful, expected or necessary. Familiarity, authority, urgency and responsibility can all shape the decision.

What it can look likeSomeone who appears to be a colleague asks for urgent access because a deadline is approaching. The person is familiar and the work is genuine, so questioning the request can feel harder than simply helping.

What helps reduce the riskConsider the request as well as the identity being presented. Where access, payments, credentials or sensitive information are involved, use the appropriate verification route even when the person appears genuine.

Deepfakes & AI Impersonation

What it isDeepfakes and AI impersonation use generated or manipulated voice, video, images or writing to make communication appear to come from a real person.

How it worksPublicly available recordings, images and written material can help attackers imitate somebody’s appearance, voice or communication style. The technology strengthens the impersonation, but the request still relies on somebody trusting what they see or hear.

What it can look likeA call or voice message appears to come from a senior colleague asking for an urgent payment or sensitive action. The voice sounds convincing enough that checking can feel unnecessary.

What helps reduce the riskTreat unusual or high-consequence requests as something to verify independently, regardless of how convincing the voice, video or message appears.

Passwords, Logins & Account Access

Some attacks are aimed directly at getting into an account. Others steal or reuse something that already proves who you are. The result can be particularly difficult to spot because activity carried out through a genuine account can look completely legitimate.

Password Attacks

What it isPassword attacks include techniques such as brute force, password spraying and credential stuffing, all of which try to gain access by finding credentials that work.

How it worksBrute force tries many passwords against an account. Password spraying tries a small number of common passwords across many accounts. Credential stuffing takes usernames and passwords leaked elsewhere and tries them on other services where people may have reused them.

What it can look likeYou may see failed login alerts, an unexpected account lockout or a successful sign-in from somewhere unfamiliar. Sometimes there is no obvious sign until the account is already being used.

What helps reduce the riskUse passkeys where they are available. Where passwords are still required, use a unique password for each important account, preferably managed through a reputable password manager, and enable two-step verification where supported.

Credential Harvesting

What it isCredential harvesting is when attackers collect usernames, passwords or other login information through fake pages and deceptive prompts.

How it worksA familiar login page is copied closely enough that entering credentials feels like a normal part of the task. The information is then captured and used by the attacker.

What it can look likeYou click a document link and are asked to sign into Microsoft 365 or another familiar service. The page looks right and signing in is exactly what you expect to do before seeing the document.

What helps reduce the riskUse trusted bookmarks, apps or known web addresses for important logins rather than following unexpected authentication links. Passkeys can also reduce the usefulness of traditional credential-phishing attacks where the service supports them.

Account Takeover

What it isAccount takeover happens when somebody gains control of a legitimate account and begins using it as though they were the real owner.

How it worksThe attacker may use stolen credentials, a compromised session or another access method. Once inside, they can read conversations, reset access, gather information or send requests from an account people already trust.

What it can look likeA genuine colleague’s account sends you a perfectly believable request. The email address is correct because the attacker is actually using the colleague’s account.

What helps reduce the riskProtect accounts with strong authentication and take unexpected login activity seriously. Continue to verify unusual or high-consequence requests even when they come from a genuine account.

MFA Fatigue

What it isMFA fatigue, sometimes called push bombing, uses repeated authentication prompts to pressure somebody into approving access.

How it worksIf an attacker already has a password, repeated login attempts can generate approval requests on the real user’s device. The interruption itself becomes part of the attack.

What it can look likeYour phone keeps displaying login approvals you did not request. After several prompts, approving one can start to feel like the quickest way to make them stop.

What helps reduce the riskDo not approve an authentication request you did not initiate. Report repeated unexpected prompts. Organisations should also use stronger, phishing-resistant authentication approaches where they are available rather than relying entirely on repeated push approvals.

Session Hijacking

What it isSession hijacking is when an attacker gains access to an already authenticated session rather than logging in with the user’s password.

How it worksWeb services use session information to remember that somebody has already authenticated. If that session token is stolen, an attacker may be able to act as the logged-in user without repeating the normal login process.

What it can look likeAn account appears to have been accessed even though the password was not changed or obviously exposed. The attacker may already appear authenticated to the service.

What helps reduce the riskKeep browsers and devices updated, use secure authentication, avoid untrusted software and browser extensions, and report unusual account activity quickly. Organisations should also manage session security and access controls appropriately.

Files, Links & Downloads

Opening a file, installing a tool or following a link is part of ordinary digital work. These threats take advantage of those familiar actions by placing something harmful behind an otherwise believable task.

Malware

What it isMalware is malicious software designed to damage systems, steal information, spy on activity or give somebody unauthorised access.

How it worksMalware can arrive through attachments, downloads, compromised websites, malicious software or vulnerabilities in systems and applications.

What it can look likeA file or application appears useful and may even behave normally after it is opened. The malicious activity can happen quietly in the background, so there may be no dramatic warning at the point of compromise.

What helps reduce the riskKeep software and devices updated, use appropriate endpoint protection and only install software from trusted routes. Unexpected files and downloads should have a straightforward route for checking or reporting them.

Ransomware

What it isRansomware is malware that prevents access to systems or data, commonly by encrypting files. Attackers may also steal information and threaten to release it.

How it worksRansomware can follow phishing, compromised credentials, unpatched vulnerabilities or another form of initial access. The first action and the visible disruption may happen at very different times.

What it can look likeWork may continue normally until files become unavailable, systems stop responding or a ransom message appears. By then, the original route into the organisation may have been used much earlier.

What helps reduce the riskRansomware needs an organisational response, not just individual caution. Keep systems updated, control access, monitor for suspicious activity and maintain resilient backups that remain usable if the live environment is compromised.

QR Code Phishing (Quishing)

What it isQR code phishing, sometimes called quishing, uses a QR code to direct somebody towards a deceptive or malicious destination.

How it worksThe QR code hides the destination until it is scanned and often moves the interaction onto a phone, where the person may have less information available about the website they are opening.

What it can look likeA QR code appears in an email, invoice, poster or printed document and asks you to sign in, make a payment or confirm information.

What helps reduce the riskTreat QR codes as links. Consider where the code came from, check the destination before entering information and use the official website or app when the request involves something sensitive.

Malicious Browser Extensions

What it isA malicious browser extension is an add-on that appears useful but also collects information, monitors browsing or gains access it should not have.

How it worksBrowser extensions can receive significant permissions. A tool may perform the feature it promises while quietly using those permissions for another purpose.

What it can look likeAn extension promises to improve productivity, convert documents or add a useful browser feature. It works, so there is little reason for the person installing it to suspect anything else is happening.

What helps reduce the riskOnly install extensions through approved or trusted routes, review the permissions they request and remove extensions that are no longer needed. Organisations should control browser extensions where the risk warrants it.

Websites & Online Services

Not every cyber threat begins with somebody receiving a suspicious message. Websites and online services can also be attacked directly, compromised and then used to affect the organisation or the people who visit them.

Drive-by Downloads & Compromised Websites

What it isA drive-by attack uses a malicious or compromised website to deliver malware or exploit a vulnerability when somebody visits the site, sometimes without the person deliberately downloading anything.

How it worksAn attacker compromises a website or places malicious content on it. A vulnerable browser, plugin or device may then be exploited when the page is loaded. A trusted website can also be used as a watering hole when attackers know a particular group is likely to visit it.

What it can look likeYou visit a website you have used before and nothing obviously unusual happens. The site itself may have been compromised, so simply recognising the website does not guarantee that everything being served through it is safe.

What helps reduce the riskKeep browsers, operating systems and other software updated, remove unsupported plugins and use appropriate web and endpoint protections. Website owners also need to maintain and patch the systems, plugins and components their sites rely on.

Distributed Denial of Service (DDoS)

What it isA Distributed Denial of Service attack attempts to overwhelm a website, network or online service with traffic or requests so legitimate users cannot use it normally.

How it worksTraffic is generated from many sources at once, which can exhaust network capacity, processing power or another limited resource. Because the requests are distributed, separating attack traffic from genuine visitors can be difficult.

What it can look likeA website becomes extremely slow or unavailable even though the underlying application has not necessarily been breached. Customers or staff may simply see timeouts and failed connections.

What helps reduce the riskDDoS is mainly an organisational and technical resilience problem. Understand where services can become overloaded, discuss mitigations with hosting and network providers, consider appropriate DDoS protection or content-delivery services, monitor capacity and have a response plan for continuing or restoring the service.

Cross-Site Scripting (XSS)

What it isCross-Site Scripting is a web application vulnerability that allows malicious code, usually browser-side script, to be delivered through a website that users would otherwise trust.

How it worksThe application accepts data and includes it in a web page without handling it safely. An attacker can exploit that behaviour so their script runs in another visitor’s browser as part of the trusted site.

What it can look likeA website appears normal, but malicious script running through the page may steal information, alter what the visitor sees, impersonate actions or interfere with the user’s session.

What helps reduce the riskThis is primarily a website-development and application-security issue. Web applications should handle untrusted input safely, encode output correctly, use appropriate sanitisation where needed and apply modern browser security controls. Keeping frameworks and site components maintained is also important.

SQL Injection

What it isSQL injection is an attack where specially crafted input changes a database query because an application treats supplied data as part of the command being executed.

How it worksIf an application builds database queries unsafely, an attacker may be able to insert instructions rather than ordinary data. Depending on the vulnerability, this can expose, alter or delete information or allow other unauthorised actions.

What it can look likeFrom the user’s side, there may be nothing obvious to see. The attack happens through the way the website or application processes information behind the scenes.

What helps reduce the riskDevelopers should keep data separate from database commands by using safe, parameterised queries or prepared statements, apply appropriate validation and limit the permissions available to the application and database accounts.

Payments, Data & Everyday Business Risk

Some of the most damaging cyber incidents do not look particularly technical. They happen while somebody is paying an invoice, sharing a document, handling customer information or completing another ordinary business task.

Invoice & Payment Fraud

What it isInvoice and payment fraud is when somebody is deceived into sending money to the wrong account or authorising a fraudulent transaction.

How it worksThe attacker may impersonate a supplier, compromise a real conversation or issue a convincing invoice that fits existing work. The fraud succeeds because the payment itself often appears legitimate.

What it can look likeA genuine supplier, real invoice and expected payment are already in progress. The only thing that has changed is where the money is being sent.

What helps reduce the riskUse a consistent independent verification process for new or changed payment details and make sure staff know how that process works when the normal contact is unavailable or the payment is urgent.

Data Breach

What it isA data breach is an incident in which information is accessed, exposed, altered, lost or shared without the appropriate authorisation.

How it worksA breach can result from an attack, compromised account, weak permissions, lost device, accidental disclosure or another failure around how information is handled.

What it can look likeInformation appears somewhere it should not, is sent to the wrong person or becomes accessible to somebody who should not have it. Sometimes this is noticed immediately; sometimes it is discovered much later.

What helps reduce the riskLimit access to information according to need, use secure systems and sensible permissions, protect accounts and provide a clear route for reporting suspected loss or disclosure quickly.

Data Leakage & Accidental Sharing

What it isData leakage is when information goes further than intended through ordinary work rather than necessarily through a deliberate attack.

How it worksRushed emails, incorrect recipients, overly broad sharing permissions, the wrong attachment or copying information into an unsuitable service can all expose data.

What it can look likeA document needs to reach somebody quickly, so it is shared using the easiest available route. The task is completed successfully, but more people can access the information than intended.

What helps reduce the riskMake secure sharing routes straightforward to use, check recipients and permissions where information is sensitive and make it easy to report a mistake quickly so the organisation can respond.

Identity Theft

What it isIdentity theft is the use of somebody else’s personal or business information to impersonate them or carry out fraudulent activity.

How it worksInformation gathered through phishing, data breaches, social media, public records or other sources can be combined to make an impersonation more convincing.

What it can look likeAccounts are opened, passwords reset, purchases made or requests submitted using enough genuine information that the activity initially appears legitimate.

What helps reduce the riskProtect important accounts, be thoughtful about information that is shared publicly and investigate unexpected account changes, requests or transactions promptly.

Wider Cyber Threats You May Hear About

These terms are less likely to describe a decision somebody makes in an ordinary email or document, but they appear regularly in cyber news, incident reports and conversations about organisational security.

Man-in-the-Middle Attack

What it isA man-in-the-middle attack happens when an attacker secretly places themselves between two parties or systems that believe they are communicating directly.

How it worksThe attacker may intercept, observe or alter information travelling between the two sides. The attack can involve compromised networks, connections or other weaknesses in how communication is protected.

What it can look likeFrom the user’s perspective, the connection may appear completely normal. Information is sent and received as expected while somebody else is able to observe or interfere with the communication.

What helps reduce the riskUse maintained devices and software, secure encrypted services and trusted authentication. Organisations should protect networks and services appropriately rather than relying on users to identify interception themselves.

Supply Chain Attack

What it isA supply chain attack reaches an organisation through a supplier, software provider, service, component or other third party it already relies on.

How it worksInstead of attacking every organisation directly, an attacker compromises something used by several organisations. Trusted software, updates, services, access routes or supplier relationships can then become the path into downstream environments.

What it can look likeAn organisation uses a legitimate supplier or piece of software exactly as intended, but the supplier or component has already been compromised. Nothing about the normal relationship necessarily gives the customer an obvious reason to suspect it.

What helps reduce the riskUnderstand which suppliers and services have meaningful access to your systems or information, apply proportionate supplier assurance, limit unnecessary access and maintain visibility of important dependencies so a supplier incident can be assessed and contained.

Zero-Day Vulnerability

What it isA zero-day is a newly discovered software vulnerability for which a security fix is not yet publicly available.

How it worksIf attackers discover or obtain a way to exploit the weakness before a fix is available, they may be able to compromise affected systems even though the organisation has been following its normal patching process.

What it can look likeThere may be very little for an ordinary user to recognise. The term usually appears when a vendor, security organisation or news report announces that a vulnerability is already being exploited.

What helps reduce the riskOrganisations need effective vulnerability management, supported and maintained products, layered security controls and the ability to apply updates or other mitigations quickly when they become available.

The names change. The decisions often look familiar.

Cyber threats use different technologies, techniques and routes into an organisation, but many of them rely on very similar working conditions.

A request feels familiar. Something arrives at the right time. A person, supplier or system already appears trustworthy. Acting quickly is convenient, while stopping to check creates another step.

That is why knowing the name of every possible cyber threat is not the goal.

You do not need to identify the exact attack before you are allowed to question what is happening. If a request changes access, payment details, credentials, sensitive information or another important part of the task, it can be reasonable to verify it even when everything else looks normal.

The same applies to organisations. If people repeatedly know what they should do but cannot do it easily because the process is unclear, the control is awkward or nobody knows who owns the next step, another reminder to be careful may not solve the problem.

Understanding the threat matters. Understanding the decision around it matters just as much.

Shopping cart close