Cybersecurity glossary
What is Shoulder Surfing?
Learn what shoulder surfing is, how attackers observe screens and keypads in public and offices, how cameras change the threat, and which privacy habits and workspace controls reduce visual credential theft.
Definition
Shoulder surfing is a social-engineering and physical-observation attack in which an adversary watches, films, or otherwise captures a person’s screen, keypad, or gestures to obtain passwords, PINs, MFA codes, or sensitive data without touching the victim’s device.
Why the oldest credential-theft technique still works
People lock laptops and then type a PIN with a train window as a mirror. Shoulder surfing needs no malware, no lookalike domain, and no exploit. It needs a line of sight at the moment a secret is visible. Airports, cafés, open-plan offices, ATMs, and conference hallways concentrate that moment: people authenticate under time pressure, hold phones at readable angles, and treat nearby strangers as background.
The social-engineering layer is permission to stand close. A queue, a shared table, a “is this seat taken,” or a colleague who is actually a visitor can put eyes on a keyboard without looking like an attack. Cameras removed the need to stand close at all.
Unlike phishing, the victim is using the real site. Antivirus will not fire. The password was entered correctly—just not privately.
How a shoulder-surf is actually performed
Choose a high-yield place
Transit, hotel lobbies, ATMs, badge readers, and open offices where secrets must be typed in public.
Close the distance or the lens
Stand in a queue, sit in the next row, use a phone camera, or watch reflections in glass and polished screens.
Wait for a secret to appear
Password fields, PIN pads, MFA codes, recovery screens, or an unlocked session showing customer data.
Capture, don’t interrupt
Memorize, film, or photograph. Challenging the victim would end the opportunity.
Replay immediately or later
A six-digit TOTP is useful for about thirty seconds. A PIN or password may be useful for months.
Combine with other access
Pair the observed secret with a stolen laptop, a known email from a breach, or a login started on another device.
What observers are actually after
PINs and lock screens
Phone, laptop, badge, and ATM PINs are short, numeric, and often typed slowly enough to count.
Passwords and patterns
Even a partial view of length, character classes, or gesture shape shrinks brute-force and confirms reuse.
MFA codes in the other hand
The laptop asks for a code that the phone displays in large type—an ideal two-screen surf.
The session already open
Watching a CRM, mailbox, or admin console can leak data without ever capturing the password.
Shoulder surfing versus nearby user threats
| Threat | How the secret is captured | Typical place |
|---|---|---|
| Shoulder surfing | Eyes, cameras, or reflections | Transit, ATM, open office |
| Session replay recording | Software that stores DOM and keystrokes | The victim’s own browser |
| Phishing | Victim types into a fake destination | Inbox or message app |
| Evil twin portal | Victim types into a fake network login | Public Wi-Fi |
Habits and workspace controls that shrink the viewing angle
- Use a privacy filter on laptops that leave the office, and sit with your back to a wall when you must authenticate in public.
- Cup the hand over PIN pads and phone lock screens; body-block ATMs and badge readers.
- Do not display SMS or TOTP codes at a café table next to an unlocked laptop; unlock the authenticator only when the field is ready, then lock the phone.
- Prefer passkeys or hardware keys in public so there is no password to watch, and avoid recovery-code screens on planes.
- In offices, place screens away from corridors and visitor seating; treat tailgating and lingering near desks as reportable.
- Auto-lock aggressively. An unattended unlocked session is shoulder surfing without the typing.
- Be wary of phone cameras in queues and of video calls that show a badge board or password sticky behind you.
- If you must share a screen, share a window, not the desktop, and never the authenticator app.
Open offices are not a café, but the geometry is similar
Internal threat and careless visitors matter as much as strangers on a train. Cleaning staff, contractors, and other teams walking a floor can see compensation spreadsheets and MFA prompts that email DLP will never see. Privacy is a facilities control: monitor angles, badge-separated areas for privileged work, and a culture that challenges people standing behind a screen without a reason.
The practical takeaway
Shoulder surfing steals secrets from the real keyboard and the real screen. It is physical phishing: the lure is ordinary public life, and the payload is whatever you had to type or display.
Hide the angle, shorten the time a secret is visible, and prefer authenticators that do not produce a number a camera can read. If someone could film your login from the next seat, treat that login as already shared.
Related security terms
Social Engineering
Shoulder surfing is low-tech social engineering: proximity plus a moment when the victim must type a secret.
Phishing
Phishing steals secrets through a fake destination; shoulder surfing steals them from the real one by watching.
Session Hijacking
A watched session cookie or already-open admin console can be as useful as a stolen password.
Multi-Factor Authentication (MFA)
SMS and TOTP codes displayed on a phone are high-value shoulder-surf targets sitting next to the laptop.
Pretexting
A pretext such as ‘I need to wait for my colleague’ is often how the observer stays close without drawing challenge.
Frequently asked questions
What is shoulder surfing in simple terms?
Someone watches you type or looks at your screen—on a train, at an ATM, in an open office, or via a camera—to copy a password, PIN, or one-time code.
Is shoulder surfing only a person standing behind you?
No. Phone cameras, reflections in windows, telephoto lenses, and overhead security cameras can capture the same secrets from farther away.
Does a password manager stop shoulder surfing?
It reduces visible typing of the password itself. It does not hide an unlocked laptop, an MFA code on a phone, or a document already on screen.
Are privacy screen filters worth it?
They help on planes and trains by narrowing the viewing angle. They are not enough in a quiet office where someone can stand directly behind you, and they do not hide a phone keypad held in the open.
Can shoulder surfing beat MFA?
If the second factor is a visible TOTP or SMS code, an observer who also saw the password—or who already has it from a breach—can complete the login in real time.
What should I do if I think I was watched?
Change the exposed secret from a private place, review recent logins, and treat any MFA code that was on screen as burned. For bank PINs, contact the issuer if you suspect capture at a terminal.
Is this still relevant with passkeys?
Passkeys remove the typed password, which shrinks the classic attack. Unlock gestures, recovery codes, and on-screen data remain observable. Physical privacy still matters.
References
Explore authoritative guidance and frameworks related to shoulder surfing.
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.