A few years ago, a journalist for the BBC demonstrated how easy it was to steal PINs and passwords simply by watching people type on their phones in a London coffee shop. He captured over 20 credentials in a single afternoon. No malware. No exploit kit. Just a pair of eyes and a good angle. That's a shoulder surfing attack in its purest form — and it remains one of the most underestimated threats in cybersecurity.

This post breaks down exactly how shoulder surfing works, why it's more dangerous than most organizations realize, and what you can do right now to defend against it. If you think this threat is too simple to worry about, I'd argue that's precisely why it works so well.

What Is a Shoulder Surfing Attack?

A shoulder surfing attack is a form of social engineering where a threat actor directly observes someone entering sensitive information — passwords, PINs, credit card numbers, or confidential documents. It can happen in person or remotely using binoculars, cameras, or even phone recordings from a distance.

Unlike phishing or ransomware, shoulder surfing requires zero technical skill. The attacker doesn't need to bypass your firewall or trick your email filters. They just need proximity and patience.

The 2024 Verizon Data Breach Investigations Report confirmed that the human element was involved in 68% of breaches. Shoulder surfing is one of the simplest ways threat actors exploit that human element — and it almost never gets reported because the victim doesn't even know it happened.

Where Shoulder Surfing Actually Happens

Airports, Coffee Shops, and Coworking Spaces

I've watched people enter banking credentials on their laptops in airport terminals without a shred of concern. Open floor plans and shared workspaces make this trivially easy. ATMs in busy areas are classic targets too — the FBI has long warned about PIN theft through direct observation at cash machines.

Inside Your Own Office

This is the one organizations don't want to hear. Shoulder surfing doesn't just happen in public. Disgruntled employees, contractors, and visitors can observe login screens, sticky notes with passwords, and unlocked workstations. The insider threat is real, and physical security is part of it.

Over Video Calls

Here's a scenario I've seen more than once since remote work exploded: an employee shares their screen during a video meeting and accidentally reveals a browser tab with saved passwords, an open email with sensitive data, or a document they didn't mean to expose. That's digital shoulder surfing, and it's increasingly common.

The $4.88M Lesson Most Organizations Learn Too Late

According to IBM's 2024 Cost of a Data Breach Report, the global average cost of a data breach reached $4.88 million. Not every breach starts with a sophisticated zero-day exploit. Some start with someone watching you type your password at the gate in Terminal B.

Credential theft is often the first step in a larger attack chain. A threat actor who captures your corporate email password through shoulder surfing can use it to launch phishing attacks against your colleagues, access sensitive files, or escalate privileges inside your network. One observed password can become a full-blown data breach.

This is why security awareness programs need to cover physical threats alongside digital ones. If your training only covers phishing simulations and ignores the person sitting three feet away, you've got a gap.

How to Prevent a Shoulder Surfing Attack

Use Privacy Screens on All Devices

Privacy screen filters narrow the viewing angle on your laptop and phone displays. Anyone not directly in front of the screen sees a darkened or blank display. They cost under $40 and are one of the most effective physical controls you can deploy. I recommend them as standard issue for any employee who works outside the office.

Enable Multi-Factor Authentication Everywhere

Even if an attacker captures your password through shoulder surfing, multi-factor authentication (MFA) adds a second barrier. A stolen password alone won't get them in. CISA has consistently recommended MFA as a baseline security measure across all critical accounts — see their guidance at cisa.gov/MFA.

Adopt Biometric and Passwordless Authentication

If there's no password to type, there's nothing to observe. Biometric logins — fingerprint, facial recognition — and passkeys eliminate the shoulder surfing risk for authentication entirely. This aligns with zero trust principles: verify identity through something you are, not just something you know.

Be Physically Aware of Your Surroundings

This sounds obvious, but I've conducted security assessments where employees entered credentials with their screens facing a lobby full of visitors. Sit with your back to the wall. Angle your screen away from foot traffic. Shield your hand when entering PINs. These habits matter.

Lock Your Screen. Every Single Time.

Windows key + L. Command + Control + Q on Mac. Make it muscle memory. An unlocked workstation is an open invitation — not just for shoulder surfing, but for direct access. Your organization's security policy should mandate auto-lock after 60 seconds of inactivity at most.

Training Your Team to Recognize the Threat

Most employees have never heard the term "shoulder surfing attack." They don't think of someone watching them type as a security incident. That's a training failure.

Effective security awareness programs cover the full threat spectrum — not just the digital attacks. Your people need to understand that social engineering includes physical observation, pretexting, tailgating, and dumpster diving alongside email-based phishing.

If you're building or improving your organization's training program, our cybersecurity awareness training course covers social engineering tactics including shoulder surfing, pretexting, and physical security fundamentals. For organizations focused specifically on email-based threats, our phishing awareness training for organizations pairs well as a complement — because in the real world, a shoulder surfing attack and a phishing simulation failure often happen to the same untrained employee.

Shoulder Surfing and the Bigger Social Engineering Picture

Shoulder surfing rarely happens in isolation. It's usually one tactic in a broader social engineering campaign. A threat actor might shoulder-surf an employee badge number, then use it to social-engineer the help desk into a password reset. Or they observe a login credential and combine it with information gathered from LinkedIn to craft a convincing spear-phishing email.

The NIST Cybersecurity Framework emphasizes the importance of protecting against unauthorized access through both technical and physical controls. You can review their full framework at nist.gov/cyberframework. Shoulder surfing falls squarely under the "Protect" function — and it's one of the cheapest threats to mitigate if you actually address it.

Does Shoulder Surfing Count as a Data Breach?

This is a question I get asked surprisingly often. The answer depends on what was observed and your jurisdiction's breach notification laws. If a threat actor visually captures protected health information (PHI), payment card data, or personally identifiable information (PII), it can absolutely trigger regulatory obligations under HIPAA, PCI DSS, or state breach notification statutes.

The FTC has taken action against companies for failing to implement reasonable physical safeguards for consumer data. You can review their enforcement actions at ftc.gov/enforcement. "Reasonable safeguards" includes preventing unauthorized visual access to sensitive information — which is exactly what shoulder surfing exploits.

A Five-Minute Checklist to Harden Against Shoulder Surfing

  • Deploy privacy screen filters on all laptops, tablets, and phones used outside secure areas.
  • Enforce MFA on every account that supports it — no exceptions.
  • Train employees on physical security awareness, not just digital threats.
  • Implement auto-lock policies: 60 seconds maximum on all workstations.
  • Position monitors and workstations away from public-facing windows and walkways.
  • Prohibit writing passwords on sticky notes, whiteboards, or visible surfaces.
  • Conduct periodic physical security assessments — walk your own office like an attacker would.

The Threat That Hides in Plain Sight

A shoulder surfing attack won't make headlines. There's no dramatic ransomware countdown timer. No encrypted files. No panicked all-staff email. That's exactly what makes it dangerous — it's invisible until the damage is already done.

Your organization's security posture is only as strong as its weakest layer. If you've invested heavily in endpoint detection, email filtering, and network segmentation but your employees are typing passwords in full view of strangers, you've left the front door open while fortifying the back wall.

Start with awareness. Train your people through programs like our cybersecurity awareness training. Deploy basic physical controls. And remember: sometimes the most effective attack doesn't require a single line of code.