CyberGlossary

Attacks & Threats

Shoulder Surfing

Also known as: Visual eavesdropping

Definition

Observing someone's screen, keyboard, or PIN pad over their shoulder — directly or via cameras — to steal credentials, codes, or sensitive information.

Shoulder surfing is a low-tech, high-impact information-gathering technique. It includes glancing at a colleague's laptop during a flight, recording PIN entry at ATMs and POS terminals, watching MFA codes in shared offices, and using long-lens or ceiling cameras to capture data from a distance. Because the target is the human–device interface rather than the technology stack, traditional controls do not help directly. Mitigations include privacy screens, awkward typing angles, clean-desk and clear-screen policies, masked PIN displays, biometric or push-based MFA that does not leak codes, secure entry of credentials in private settings, and physical positioning that limits sightlines.

Examples

  • Reading a traveler's email through the screen on a packed train.
  • Using a hidden camera near an ATM to capture PINs and card details.

Related terms