Under construction The ClearSight Center is coming soon. These tools are being built in the open — what you see here is a preview, results are indicative, and everything on these pages may change before launch.
Exposure Center · Glossary
Every term we use, defined and sourced
If a result uses a word, it is explained here in a sentence you can act on — with the source behind it, like everything else in the Exposure Center.
- SIM swap
- Moving your phone number onto an attacker's SIM.An attacker convinces (or bribes) a carrier to port your number. Every SMS code then arrives on their device. This is why SMS is the weakest second factor.Source: FCC · SIM swap and port-out fraud rules (2024) ↗
- Credential stuffing
- Replaying leaked passwords across other sites.Automated tools try known email/password pairs against hundreds of services. It works only because passwords get reused.Source: Verizon · Data Breach Investigations Report (2024) ↗
- Data broker
- A company that buys and resells personal records.Brokers merge purchase, location and property data into per-person profiles sold to advertisers, insurers and anyone else who pays.Source: FTC · Data brokers and location data enforcement (2024) ↗
- k-anonymity
- Checking a secret without revealing it.Your password is hashed in the browser and only the first five hash characters are sent. The service returns every matching suffix; the comparison happens locally.Source: Have I Been Pwned · Pwned Passwords (k-anonymity) ↗
- Business email compromise
- Impersonating a trusted party to redirect money.No malware required. The attacker studies a reporting line, then sends an invoice or payroll change that fits the routine.Source: FBI IC3 · Internet Crime Report (2024) ↗
- Fourth-party risk
- Your vendor's vendors.You assessed your SaaS provider. You did not assess the analytics, support and hosting suppliers sitting behind it — and a breach there reaches your data all the same.Source: Verizon · Data Breach Investigations Report (2024) ↗
- Attack surface
- Everything of yours reachable from the internet.Subdomains, login portals, file shares, forgotten staging hosts. Attackers enumerate it from public sources before they touch anything.Source: OWASP · Top 10 ↗
- Phishing-resistant MFA
- Factors that cannot be relayed.Passkeys and hardware keys bind the login to the real domain, so a proxy phishing page cannot reuse the response.Source: CISA · Implementing phishing-resistant MFA ↗
- Automatic content recognition
- Your TV identifying what is on screen.Sampling frames or audio to identify content, then linking that viewing profile to the household's advertising identity.Source: FTC · Data brokers and location data enforcement (2024) ↗
- Whaling
- Targeted fraud aimed at an executive.The same techniques as ordinary phishing, researched against one high-authority person whose approval moves money.Source: FBI IC3 · Internet Crime Report (2024) ↗
Every number on this page is produced by the rules on our Methodology & Trust page: cited claims only, no biometrics, no third-party scraping, no storage of pasted content. Unfamiliar term? The cited glossary explains each one.