Shoulder Surfing - Preventing Visual Password Theft
About 2 min read
Shoulder surfing is a technique of stealing confidential information such as passwords or PIN codes by peering over someone's shoulder at their screen or keyboard. The risk is especially high in public places such as cafes, trains, and airports. It is a low-tech attack that requires no advanced skills, yet the damage can be serious. With the spread of remote work, reports of incidents at cafes and coworking spaces increased throughout 2024-2025. It is classified as a form of social engineering.
What Follows From Peeking Leaving No Record
Peeking leaves no trace, either on the device or in communication records. Even when a screen has been photographed, the activity log on that device shows nothing but ordinary use, and looking back later reveals no gap. The occasion for noticing is more or less limited to the point at which the stolen information is actually used, and even then no material remains that would distinguish peeking from the reuse of credentials leaked elsewhere, or from a compromise of the device itself. Two things follow from this. The first is that a risk of this kind cannot be managed by counting incidents. A low count is not evidence of safety, because what is visible is only the portion that could be detected. The object of management therefore has to be the practice side, where and what is typed, rather than the outcome. The second is the order of response once the possibility of having been watched is noticed. Because no material remains to confirm it, proceeding by establishing the facts first leaves the decision suspended indefinitely. Invalidating and replacing the credentials in question as soon as the suspicion arises settles the matter sooner than waiting for confirmation. In addition, what the other party obtains is not only the string that was typed. Whatever was displayed at that moment was visible as well, so it is worth reviewing what was on screen during the work, on the assumption that part of the exposure cannot be undone by replacing credentials.
Shoulder Surfing Tactics
Beyond direct peeking, tactics include photographing with a smartphone camera, observing from a distance with binoculars, and abusing surveillance camera footage. The main targets are PIN entry at ATMs, unlocking smartphones, and password entry on laptops.
Real Damage Scenarios
There are cases where, while working at a cafe and logging into online banking, the screen is photographed with a smartphone from a seat behind, leaking the ID and password. There are also reported cases where accessing a corporate system in an airport lounge allowed a person in the adjacent seat to spy out the VPN credentials, leading to unauthorized intrusion into the corporate network. Working at business-trip destinations and coworking spaces carries especially high risk, so countermeasures are needed as part of security for remote work.
Countermeasures
Using a privacy filter (an anti-peeping film) is the easiest and most effective measure. Habitually checking your surroundings when entering a password and making use of biometric authentication are also effective. If you use randomly generated passwords through a password manager's autofill, you can minimize keyboard input and greatly reduce the risk of being watched. Put this into practice together with security measures in public places.
Was this article helpful?