Cybersecurity glossary

What is Shoulder Surfing?

Learn what shoulder surfing is, how attackers observe screens and keypads in public and offices, how cameras change the threat, and which privacy habits and workspace controls reduce visual credential theft.

Social engineering and user threatsUpdated August 13, 2026
Also known asVisual observation attackScreen peekingKeypad observation

Definition

Shoulder surfing is a social-engineering and physical-observation attack in which an adversary watches, films, or otherwise captures a person’s screen, keypad, or gestures to obtain passwords, PINs, MFA codes, or sensitive data without touching the victim’s device.

Why the oldest credential-theft technique still works

People lock laptops and then type a PIN with a train window as a mirror. Shoulder surfing needs no malware, no lookalike domain, and no exploit. It needs a line of sight at the moment a secret is visible. Airports, cafés, open-plan offices, ATMs, and conference hallways concentrate that moment: people authenticate under time pressure, hold phones at readable angles, and treat nearby strangers as background.

The social-engineering layer is permission to stand close. A queue, a shared table, a “is this seat taken,” or a colleague who is actually a visitor can put eyes on a keyboard without looking like an attack. Cameras removed the need to stand close at all.

Unlike phishing, the victim is using the real site. Antivirus will not fire. The password was entered correctly—just not privately.

How a shoulder-surf is actually performed

1

Choose a high-yield place

Transit, hotel lobbies, ATMs, badge readers, and open offices where secrets must be typed in public.

2

Close the distance or the lens

Stand in a queue, sit in the next row, use a phone camera, or watch reflections in glass and polished screens.

3

Wait for a secret to appear

Password fields, PIN pads, MFA codes, recovery screens, or an unlocked session showing customer data.

4

Capture, don’t interrupt

Memorize, film, or photograph. Challenging the victim would end the opportunity.

5

Replay immediately or later

A six-digit TOTP is useful for about thirty seconds. A PIN or password may be useful for months.

6

Combine with other access

Pair the observed secret with a stolen laptop, a known email from a breach, or a login started on another device.

What observers are actually after

PINs and lock screens

Phone, laptop, badge, and ATM PINs are short, numeric, and often typed slowly enough to count.

Passwords and patterns

Even a partial view of length, character classes, or gesture shape shrinks brute-force and confirms reuse.

MFA codes in the other hand

The laptop asks for a code that the phone displays in large type—an ideal two-screen surf.

The session already open

Watching a CRM, mailbox, or admin console can leak data without ever capturing the password.

Shoulder surfing versus nearby user threats

ThreatHow the secret is capturedTypical place
Shoulder surfingEyes, cameras, or reflectionsTransit, ATM, open office
Session replay recordingSoftware that stores DOM and keystrokesThe victim’s own browser
PhishingVictim types into a fake destinationInbox or message app
Evil twin portalVictim types into a fake network loginPublic Wi-Fi

Habits and workspace controls that shrink the viewing angle

  • Use a privacy filter on laptops that leave the office, and sit with your back to a wall when you must authenticate in public.
  • Cup the hand over PIN pads and phone lock screens; body-block ATMs and badge readers.
  • Do not display SMS or TOTP codes at a café table next to an unlocked laptop; unlock the authenticator only when the field is ready, then lock the phone.
  • Prefer passkeys or hardware keys in public so there is no password to watch, and avoid recovery-code screens on planes.
  • In offices, place screens away from corridors and visitor seating; treat tailgating and lingering near desks as reportable.
  • Auto-lock aggressively. An unattended unlocked session is shoulder surfing without the typing.
  • Be wary of phone cameras in queues and of video calls that show a badge board or password sticky behind you.
  • If you must share a screen, share a window, not the desktop, and never the authenticator app.

Open offices are not a café, but the geometry is similar

Internal threat and careless visitors matter as much as strangers on a train. Cleaning staff, contractors, and other teams walking a floor can see compensation spreadsheets and MFA prompts that email DLP will never see. Privacy is a facilities control: monitor angles, badge-separated areas for privileged work, and a culture that challenges people standing behind a screen without a reason.

The practical takeaway

Shoulder surfing steals secrets from the real keyboard and the real screen. It is physical phishing: the lure is ordinary public life, and the payload is whatever you had to type or display.

Hide the angle, shorten the time a secret is visible, and prefer authenticators that do not produce a number a camera can read. If someone could film your login from the next seat, treat that login as already shared.

Related security terms

Frequently asked questions

What is shoulder surfing in simple terms?

Someone watches you type or looks at your screen—on a train, at an ATM, in an open office, or via a camera—to copy a password, PIN, or one-time code.

Is shoulder surfing only a person standing behind you?

No. Phone cameras, reflections in windows, telephoto lenses, and overhead security cameras can capture the same secrets from farther away.

Does a password manager stop shoulder surfing?

It reduces visible typing of the password itself. It does not hide an unlocked laptop, an MFA code on a phone, or a document already on screen.

Are privacy screen filters worth it?

They help on planes and trains by narrowing the viewing angle. They are not enough in a quiet office where someone can stand directly behind you, and they do not hide a phone keypad held in the open.

Can shoulder surfing beat MFA?

If the second factor is a visible TOTP or SMS code, an observer who also saw the password—or who already has it from a breach—can complete the login in real time.

What should I do if I think I was watched?

Change the exposed secret from a private place, review recent logins, and treat any MFA code that was on screen as burned. For bank PINs, contact the issuer if you suspect capture at a terminal.

Is this still relevant with passkeys?

Passkeys remove the typed password, which shrinks the classic attack. Unlock gestures, recovery codes, and on-screen data remain observable. Physical privacy still matters.

References

Explore authoritative guidance and frameworks related to shoulder surfing.

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary