Attacks & Threats
Dumpster Diving
Also known as: Trashing, Bin raiding
Definition
Searching through an organisation's or person's discarded materials — paper, removable media, hardware — to recover sensitive information.
Examples
- Recovering an org chart and password sticky-notes from a bin behind an office building.
- Pulling an unencrypted laptop from e-waste and recovering customer data.
Related terms
Social Engineering
The psychological manipulation of people into performing actions or disclosing confidential information that benefits an attacker.
Shoulder Surfing
Observing someone's screen, keyboard, or PIN pad over their shoulder — directly or via cameras — to steal credentials, codes, or sensitive information.
Pretexting
A social-engineering technique in which an attacker invents a believable scenario or identity to manipulate a target into disclosing information or performing an action.
Tailgating
A physical intrusion technique where an attacker slips through an access control by closely following an authorized person without their consent or awareness.
Phishing
A social-engineering attack in which an attacker impersonates a trusted party to trick a victim into revealing credentials, transferring money, or running malware.
Supply Chain Attack
An attack that compromises a trusted third-party software, hardware, or service provider in order to reach its downstream customers.