Reference

Glossary

The vocabulary used across our research and product pages — attack techniques, data sources, and the controls that answer them.

Attacks and Fraud Techniques

Account Takeover (ATO)

A criminal gaining access to a legitimate user's existing account. The account is real, the owner is real, and the credentials are correct — which is why ATO passes most authentication checks.

Read more →
Credential Stuffing

Automated testing of stolen username and password pairs across many sites at once, betting on password reuse. Success rates are low, but the tooling is cheap enough that the economics still work.

Read more →
Credential Pair

A username or email address together with its password. Pairs matter more than either half alone — a password is only dangerous attached to the account it opens.

Business Email Compromise (BEC)

Targeted fraud in which an attacker impersonates an executive, vendor, or partner over email to move money or extract data. Unlike phishing, it often carries no link or attachment to detect.

Read more →
Card Testing

Running small or zero-value transactions against stolen card numbers to find which are still live, before using the working ones for real purchases.

Read more →
Synthetic Account

An account created with a fabricated or assembled identity rather than a stolen one. Nothing about it is reported stolen, so there is no victim to raise a flag.

Read more →
Sleeper Account

A fraudulent account created early and left dormant so it looks aged and established by the time it is used. Account age reads as trust to most risk models.

Read more →
Triangulation Fraud

Value taken from one account, laundered through an intermediary, and delivered to a paying stranger who has no idea they are part of the scheme. The final transaction looks entirely legitimate.

Read more →
Loyalty Fraud

Theft of points, miles, or stored value from loyalty accounts. Often detected at redemption, by which point the compromise happened days or weeks earlier at login.

Read more →
Phishing

Deceiving a user into surrendering credentials or authentication codes, usually through a message that impersonates a service they trust.

Read more →
Pig Butchering

A long-running confidence scam that builds trust over weeks or months before extracting money, typically through a fake investment platform.

Read more →
Infostealer

Malware that harvests saved credentials, session cookies, and autofill data straight off an infected device — bypassing the login page entirely.

Data and Intelligence

Live Data

Credentials observed as criminals actively use and test them. Because it reflects current activity, it indicates present risk rather than past exposure.

Read more →
Breach Data

Credentials recovered from a disclosed breach. Useful, but always behind: a breach must be discovered, processed, and distributed before the data reaches a defender.

Read more →
Darknet

Networks and marketplaces where stolen credentials and card data are traded. A source of intelligence, but only after data has already been packaged for sale.

Checker

A tool criminals use to validate stolen credentials against a specific site at scale. Observing checker traffic reveals which credentials are being tested against whom, right now.

Read more →
BIN (Bank Identification Number)

The leading digits of a payment card that identify its issuer and product. Monitoring a BIN range surfaces testing activity against cards you issued.

Read more →
Kill Chain

The sequence from initial breach through testing, sale, and attack to the victim organisation noticing. Where you intercept it determines how much damage is already done.

Read more →
Inbox Aging

Registering an email address and letting it accumulate history before using it, so it presents as an established identity at the moment of onboarding.

Read more →
Alias Fanout

Generating many addresses from a single controlled mailbox so one operator can present as many unrelated users.

Read more →

Defenses and Controls

Credential Screening

Checking a credential pair against known-compromised data at login, signup, or password reset, and acting on the result before access is granted.

Read more →
Email Reputation

Assessing the risk attached to an email address itself — whether criminals already control the mailbox, and whether the address has any legitimate history.

Read more →
BIN Monitoring

Watching your card ranges for active testing so you can raise scrutiny, lock cards, and reissue before fraudulent transactions land.

Read more →
ATO Threat Monitoring

Continuous surveillance of your domains, BINs, and users, with alerts naming what is being attacked, how often, and how successfully.

Read more →
Multi-Factor Authentication (MFA / 2FA)

Requiring a second proof of identity beyond the password. Effective against some attacks, and routed around entirely by others — particularly when the second factor lands in a compromised inbox.

Read more →
One-Time Passcode (OTP)

A short-lived code sent to a user to confirm identity. Its security rests entirely on the channel it is sent through — an OTP to a compromised mailbox protects nobody.

Read more →
Step-Up Authentication

Adding a verification challenge only when a specific signal warrants it, so friction lands on risky sessions instead of every user.

Read more →
Passkey

A phishing-resistant credential bound to a device, replacing the password. Strong against credential theft, but account recovery still routes through the email address.

Read more →
False Positive

A legitimate user flagged as risky. The cost is real: abandoned sessions, support load, and users who do not come back.

Read more →

See these signals on live data.

30 minutes, real attack traffic, no pitch deck.

Request Free Demo