Threat Database
Explore common cybersecurity threats. Learn how each attack works, real-world statistics, prevention strategies, and how Beacky helps protect your organization.
Phishing
Email Phishing
Email phishing is the most widespread form of social engineering attack, where threat actors send fraudulent emails designed to trick recipients into revealing ...
Spear Phishing Attacks
Spear phishing is a highly targeted form of phishing where attackers craft personalized messages aimed at specific individuals or organizations. Unlike mass phi...
Business Email Compromise
Business Email Compromise (BEC) is a sophisticated scam targeting organizations that conduct wire transfers or handle sensitive financial transactions. Attacker...
Clone Site Phishing
Clone site phishing involves creating near-perfect replicas of legitimate websites to deceive visitors into entering their credentials, payment information, or ...
Domain Impersonation
Domain impersonation involves registering internet domains that closely resemble legitimate brand domains to deceive users into trusting malicious websites, ema...
Typosquatting Attacks
Typosquatting, also known as URL hijacking, is a social engineering technique where attackers register misspelled versions of popular domain names to capture tr...
Homograph Attacks
Homograph attacks exploit the visual similarity between characters from different writing systems (Unicode scripts) to create domain names that appear identical...
Phishing Kits
Phishing kits are pre-packaged collections of tools, templates, and scripts that enable attackers with minimal technical skill to launch sophisticated phishing ...
Brand Impersonation
Brand impersonation is the fraudulent use of a company's name, logo, visual identity, and content to deceive consumers into trusting malicious communications, w...
Social Media Phishing
Social media phishing uses platforms like Facebook, Instagram, LinkedIn, Twitter, and TikTok to deliver phishing attacks through direct messages, fake profiles,...
SMS Phishing (Smishing)
SMS phishing, commonly known as smishing, delivers phishing attacks through text messages to mobile devices. Attackers send fraudulent SMS messages that imperso...
Voice Phishing (Vishing)
Voice phishing, or vishing, uses phone calls and voice messages to manipulate victims into revealing sensitive information, authorizing transactions, or grantin...
Search Engine Phishing
Search engine phishing, also known as SEO poisoning, involves manipulating search engine results to place malicious websites in prominent positions for targeted...
Web Security
SSL Certificate Fraud
SSL certificate fraud encompasses the misuse, fraudulent issuance, or exploitation of SSL/TLS certificates to create a false sense of security on malicious webs...
Session Hijacking
Session hijacking is the exploitation of valid web session tokens to gain unauthorized access to a user's authenticated state on a website or application. Once ...
Cross-Site Scripting (XSS) Attacks
Cross-site scripting (XSS) attacks inject malicious scripts into web pages viewed by other users, exploiting vulnerabilities in web applications that fail to pr...
Clickjacking
Clickjacking, also known as UI redressing, is an attack that tricks users into clicking on hidden or disguised page elements by overlaying transparent layers on...
Supply Chain Attacks
Supply chain attacks target the software, services, and infrastructure that organizations depend on rather than attacking the organizations directly. By comprom...