Shoulder surfing is the act of observing someone enter credentials by watching over their shoulder or through another direct line of sight. It is a low-tech but effective attack because it bypasses encryption and focuses on the user’s behaviour. Screens, privacy, and input discipline reduce the risk.
Expanded Definition
Shoulder surfing is a direct observation attack: the attacker does not need to defeat the authentication system itself, only to see sensitive input or information as it is entered or displayed. It most often targets passwords, PINs, one-time codes, recovery answers, account numbers, or unlocked screens in public or shared spaces. The term covers both deliberate watching and opportunistic glances, including cases where a nearby person, camera, or reflected surface captures the data.
The key boundary is that shoulder surfing is about human visibility, not software compromise. It is not phishing, malware, or credential interception in transit. That distinction matters because the control problem is physical and behavioural as much as technical. A common misunderstanding is to treat it as a minor nuisance, when in practice it can defeat strong authentication if the attacker captures a usable secret or observes a verification step. Privacy filters, seating position, and screen discipline are therefore part of the defensive model, not just convenience measures.
For a broader glossary of security terms, the OWASP Non-Human Identity Top 10 is not directly about shoulder surfing, but it illustrates how visibility and secret handling become security issues when credentials are exposed to observation.
Examples and Use Cases
Shoulder surfing appears in everyday workflows wherever users enter or view sensitive information in exposed environments. The risk is not limited to classic “over the shoulder” observation; angle, reflection, and proximity all create opportunities for a casual observer to collect reusable data.
- Someone watches a user type a PIN at an ATM or payment terminal and then attempts a follow-on theft or account access.
- A coworker glances at a laptop screen in a meeting room and captures a password, recovery code, or visible customer record.
- A passenger on public transport observes a phone unlock pattern or authentication prompt and later reuses that information.
- A shop or reception area allows sensitive forms to be entered on a screen that is readable from a queue or adjacent desk.
- A camera positioned in a public space records a screen, keypad, or reflection that reveals credentials or confidential data.
One practical trade-off is usability: hiding the screen or shielding input can slow users down, especially at kiosks, help desks, or shared terminals. The defence has to fit the setting, because a control that people routinely ignore will fail in practice.
Security Implications
Shoulder surfing matters because it can convert a brief moment of exposure into immediate unauthorized access. When the observed secret is a password, PIN, or one-time code, the attacker may not need malware, a phishing page, or network interception; the human entry event itself becomes the compromise point. The result can be account takeover, unauthorized transactions, session hijacking, or exposure of regulated or personal data.
The failure mode is often simple: a secret is entered where others can see it, and the organisation assumes the surrounding environment is trustworthy when it is not. This becomes more serious when the observed information is reused, weak, or part of a recovery flow, because one successful observation can open multiple paths to the same account or service. Observable symptoms include frequent verification prompts in public areas, users turning screens away from others, and shared workspaces where sensitive information is entered without any privacy controls.
For NHIMG’s identity-security readers, the important point is that shoulder surfing can undermine even otherwise strong authentication if the exposed factor is human-readable and immediately usable. The control gap is rarely cryptographic; it is usually visibility, placement, and user behaviour.
Domain and Governance Relevance
Shoulder surfing sits at the intersection of physical security, user behaviour, and access assurance. In general cybersecurity terms, it is a low-tech observation threat that belongs in awareness, workspace design, and endpoint usage policy. The issue is not only whether a password is strong, but whether the environment lets someone see it being entered or displayed.
In identity-heavy environments, the relevance increases when the observed data is an authentication factor or recovery artifact. A seen PIN, temporary code, or unlock gesture can become the weakest link in a stronger access model, especially where users share desks, travel with devices, or authenticate in public. That means the governance question is not just “is the credential protected?” but also “who can observe the act of using it?”
For practitioners, this is a reminder that access assurance includes the conditions of use. If sensitive input is routinely visible to bystanders, the organisation has a control gap even if the underlying authentication system is well designed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT — Awareness and Training | Shoulder surfing is often enabled by poor user awareness in shared or public spaces. |
| Recommendation — Train users to shield sensitive input and to treat visible authentication as a security event. | ||
| CIS Controls v8 | 14 — Security Awareness and Skills Training | User behaviour and screen discipline directly affect exposure to visual credential capture. |
| Recommendation — Include shoulder-surfing avoidance in user security training and workspace handling guidance. | ||
| PCI DSS v4.0 | 3 — Protect Stored Account Data | Observed payment entry can expose account data or authentication factors in cardholder environments. |
| Recommendation — Limit visible account and authentication data during payment and customer-facing entry flows. | ||
| NIST SP 800-63 | 5.1.7 — Authenticator Protection | Visual capture of authenticators weakens the assurance of the factor being used. |
| Recommendation — Protect authenticators so they cannot be readily observed during enrollment and use. | ||
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org