Skip to main content
European CyberCrime Centre

Advice & guidance

Glossary of terms

Plain-language definitions of the terms you will meet across our guidance.

Botnet
A network of hijacked devices controlled by criminals, used to send spam, steal data or launch attacks.
Credential stuffing
Using username and password pairs leaked in one breach to break into accounts on other services.
DDoS
A distributed denial-of-service attack floods a service with traffic from many sources to knock it offline.
Malware
Any software designed to harm, spy on or take control of a device or network.
Money mule
A person recruited — often unknowingly — to move criminal funds through their own bank account.
Passkey
A cryptographic credential stored on your device that replaces a password and resists phishing.
Phishing
Fraudulent messages that trick you into revealing information or installing malware.
Ransomware
Malware that encrypts data and demands payment, usually in cryptocurrency, for its return.
Social engineering
Manipulating people into breaking security rules, rather than attacking the technology itself.
Two-step verification (2SV)
A second proof of identity — such as a code or app prompt — required alongside your password.