Advice & guidance
Glossary of terms
Plain-language definitions of the terms you will meet across our guidance.
- Botnet
- A network of hijacked devices controlled by criminals, used to send spam, steal data or launch attacks.
- Credential stuffing
- Using username and password pairs leaked in one breach to break into accounts on other services.
- DDoS
- A distributed denial-of-service attack floods a service with traffic from many sources to knock it offline.
- Malware
- Any software designed to harm, spy on or take control of a device or network.
- Money mule
- A person recruited — often unknowingly — to move criminal funds through their own bank account.
- Passkey
- A cryptographic credential stored on your device that replaces a password and resists phishing.
- Phishing
- Fraudulent messages that trick you into revealing information or installing malware.
- Ransomware
- Malware that encrypts data and demands payment, usually in cryptocurrency, for its return.
- Social engineering
- Manipulating people into breaking security rules, rather than attacking the technology itself.
- Two-step verification (2SV)
- A second proof of identity — such as a code or app prompt — required alongside your password.