Glossary of Terms
A
AI-Generated Scam
An AI-generated scam is fraudulent content, communication, or digital infrastructure created or enhanced using generative artificial intelligence. Attackers can use AI to produce convincing phishing messages, fake websites, advertisements, social media profiles, product images, customer-support conversations, and other deceptive content at greater speed and scale.
BrandShield helps identify external digital assets associated with AI-enabled scams across domains, websites, social media, advertisements, and other relevant channels. Suspicious assets can be analyzed for impersonation, phishing, fraud, and connections to wider threat campaigns before eligible cases are prioritized for enforcement.
AI Platform Abuse
AI platform abuse occurs when fraudulent, misleading, infringing, or malicious sources appear within or influence answers generated by AI assistants and AI-powered search platforms. Users may be directed toward fake websites, counterfeit sellers, fraudulent services, impersonating businesses, or other harmful sources while relying on AI-generated recommendations.
BrandShield monitors leading AI platforms for harmful or misleading references connected to protected brands. It can identify the external sources influencing these answers, investigate potentially fraudulent or infringing content, and help organizations take action against malicious websites, sellers, profiles, and other digital assets associated with the underlying threat.
B
Brand Impersonation
Brand impersonation is the unauthorized imitation of a company’s name, logo, website, visual identity, products, or communications. It can appear across websites, domains, social media, marketplaces, paid advertisements, mobile applications, and other digital channels. The objective is usually to exploit the trust associated with the brand to deceive customers, employees, or business partners.
BrandShield monitors external digital channels for unauthorized use of brand assets and suspicious activity connected to a protected organization. Detected cases are reviewed, prioritized, connected to related infrastructure, and submitted for enforcement.
Business Email Compromise (BEC)
Business email compromise, or BEC, is a form of social engineering in which attackers impersonate executives, employees, vendors, or other trusted contacts to manipulate victims into transferring money, sharing sensitive information, or changing payment details. Attacks may involve spoofed email addresses, lookalike domains, compromised accounts, or executive impersonation.
BrandShield helps identify external infrastructure that can support BEC attacks, including lookalike domains, impersonating websites, fake executive profiles, and related malicious assets. BrandShield’s external monitoring complements internal email security and payment-verification controls by helping organizations detect and disrupt impersonation activity before or during an attack.
C
Counterfeiting
Counterfeiting is the unauthorized production, promotion, or sale of goods that imitate a legitimate brand’s products, trademarks, packaging, or designs. Counterfeit products may be sold through marketplaces, standalone websites, social media accounts, paid advertisements, or messaging platforms.
BrandShield helps identify suspected counterfeit listings, sellers, storefronts, advertisements, and related digital assets. Its monitoring and enforcement workflows can support brands in documenting infringements and requesting removal through platforms, hosts, registrars, or other relevant providers.
Cybersquatting
Cybersquatting is the registration or use of a domain name containing, closely resembling, or referencing a trademark or brand name without authorization. It may be used for resale, traffic diversion, advertising revenue, impersonation, phishing, or counterfeit sales.
BrandShield monitors domain ecosystems for registrations that may infringe protected trademarks or create customer risk. Cases can be assessed according to their similarity, content, intent, technical activity, and potential legal or platform-policy basis for enforcement.
D
Digital Risk Protection (DRP)
Digital risk protection is the process of identifying, investigating, prioritizing, and addressing threats that exist outside an organization’s network and endpoints. These risks may affect a company’s brand, executives, employees, customers, digital assets, intellectual property, or revenue.
BrandShield provides external monitoring across channels such as domains, websites, social media, marketplaces, paid advertisements, mobile applications, the dark web, and emerging AI platforms. Its role is to help organizations understand which external threats are active, how they may be connected, and which cases may require action.
Domain Shadowing
Domain shadowing occurs when attackers compromise access to a legitimate domain account and create unauthorized subdomains beneath it. These subdomains may be used for phishing, malware distribution, redirects, or fraudulent campaigns while benefiting from the reputation of the legitimate parent domain.
BrandShield can identify suspicious subdomains, malicious content, redirects, and infrastructure associated with protected brands or active threat campaigns. Remediation may involve notifying the domain owner, hosting provider, registrar, platform, or other responsible service.
Deepfake Impersonation
Deepfake impersonation is the use of AI-generated or manipulated audio, video, or imagery to imitate a real person. Attackers may impersonate executives, employees, celebrities, or other trusted individuals to conduct financial fraud, promote scams, manipulate employees or customers, or damage an individual’s reputation.
BrandShield monitors external digital channels for unauthorized use of protected executives and other high-profile individuals. Suspected deepfake content can be investigated alongside associated profiles, advertisements, websites, domains, and campaign infrastructure to identify broader impersonation activity and support removal through relevant platforms and service providers.
Domain Spoofing
Domain spoofing is the use of a deceptive domain name, URL, or related digital identifier designed to appear associated with a legitimate organization. Attackers may use misspellings, added words, substituted characters, misleading subdomains, or similar domain structures to conduct phishing, payment fraud, impersonation, or other scams.
BrandShield continuously monitors domain ecosystems for suspicious variations connected to protected brands, executives, and trademarks. Potential threats can be evaluated based on registration data, website content, technical infrastructure, redirects, visual similarity, and connections to other malicious assets before enforcement action is considered.
E
Executive Impersonation
Executive impersonation is the unauthorized use of a senior leader’s name, image, voice, title, or identity. It is commonly used in payment fraud, investment scams, fake interviews, social engineering, recruitment scams, and misleading advertisements.
BrandShield monitors external channels for fake executive profiles, deceptive websites, fraudulent advertisements, and other unauthorized uses of protected identities. Cases can be investigated and submitted to relevant platforms or service providers when there is a valid basis for removal.
External Attack Surface Management (EASM)
External attack surface management is the continuous discovery and assessment of endpoint, assets, such as cloud services, mobile phones, browsers, certificates, and exposed applications. The objective is to identify unknown assets, vulnerabilities, misconfigurations, and other exposures that attackers could exploit.
H
Help Desk / Customer Support Scam
A fake customer support scam occurs when attackers impersonate a company’s service or technical-support team. They may create fake social profiles, support pages, phone numbers, advertisements, or websites designed to collect passwords, payment details, remote access, or personal information.
BrandShield helps identify fake support accounts, pages, domains, advertisements, and related infrastructure. Confirmed cases can be documented, prioritized, connected to wider campaigns, and submitted for removal through the appropriate channel.
Homoglyph Attack
An (IDN) homoglyph attack uses characters that look similar but come from different alphabets or character sets. For example, an attacker may replace a Latin letter with a visually similar Cyrillic character. This technique can be used in deceptive domains, usernames, email addresses, and social media profiles.
BrandShield can detect visually similar brand references and domain variations that may not be obvious through exact-text matching. Suspicious assets are evaluated together with their content, behavior, infrastructure, and intended use.
L
Lookalike Domain
A lookalike domain is designed to resemble a legitimate company’s domain through misspellings, added words, substituted characters, alternative extensions, or misleading URL structures. It may be used for phishing, fake stores, malware distribution, payment fraud, or brand impersonation.
BrandShield monitors domain registrations and active websites for variations associated with protected brands. It can help determine whether a domain is inactive, defensive, legitimate, suspicious, or actively harmful before further action is taken.
M
Malvertising
Malvertising is the use of digital advertising to promote malicious or deceptive content. Attackers may purchase search, display, or social advertisements that redirect users to phishing pages, fake stores, malware downloads, counterfeit products, or impersonating websites.
BrandShield monitors paid-ad environments for unauthorized brand use and advertisements connected to scams or impersonation. It can support evidence collection and reporting to advertising platforms, landing-page providers, hosting companies, and other relevant services.
Marketplace Abuse
Marketplace abuse includes counterfeit listings, trademark misuse, fake storefronts, unauthorized sellers, manipulated reviews, misleading product claims, and other violations occurring on ecommerce platforms. The activity may harm customers, reduce legitimate sales, and weaken control over distribution.
BrandShield monitors marketplaces for potentially infringing listings, sellers, images, product descriptions, and storefronts. Cases can be reviewed and submitted through marketplace enforcement processes based on the available evidence and the brand’s rights.
Mobile App Impersonation
Mobile app impersonation involves the creation or distribution of an unauthorized application that copies a legitimate brand’s name, logo, interface, product, or service. Fake apps may collect credentials, distribute malware, generate fraudulent payments, or mislead users.
BrandShield monitors relevant app stores and external sources for applications that may misuse protected brand assets. Suspected cases can be documented and submitted to app stores or hosting services for review.
P
Phishing
Phishing is a fraudulent attempt to trick users into revealing passwords, payment information, personal data, or other sensitive information. Phishing campaigns may use email, SMS, messaging applications, social media, search ads, fake websites, or compromised accounts.
BrandShield focuses on the external infrastructure used in phishing, including deceptive domains, websites, social profiles, advertisements, and connected malicious assets. It helps identify and investigate these threats and supports removal where a valid enforcement path exists.
R
Reverse Proxy Phishing
Reverse proxy phishing places attacker-controlled infrastructure between a victim and a legitimate service. The fake page forwards information to the real website in real time, allowing the attacker to capture credentials, MFA responses, and authenticated session cookies.
BrandShield helps identify and investigate domains and websites used to host or distribute these phishing campaigns. It can support disruption of the external infrastructure, but it does not replace phishing-resistant MFA, endpoint protection, or session-security controls.
Rogue Website
A rogue or fake website is an unauthorized website created to imitate, misuse, or exploit a legitimate company, brand, product, service, or individual. These sites may be used for phishing, counterfeit sales, fake customer support, investment fraud, credential theft, payment scams, or other deceptive activity.
BrandShield monitors the open web and domain ecosystem for websites that misuse protected brand names, trademarks, visual assets, executive identities, or other indicators. Suspicious sites can be analyzed and prioritized according to their level of risk, linked to related infrastructure, and submitted to registrars, hosting providers, platforms, or other responsible parties for enforcement.
S
Search Engine Poisoning
Search engine poisoning is the manipulation of search results to increase the visibility of malicious, counterfeit, or impersonating websites. Attackers may use search engine optimization, compromised sites, paid advertisements, or misleading content to rank for branded and high-intent searches.
BrandShield can monitor search results and related digital channels for deceptive use of a protected brand. Identified threats may be investigated and reported to search engines, advertising platforms, website hosts, or other responsible providers.
Social Media Impersonation
Social media impersonation is the creation or use of fake profiles, pages, groups, or advertisements that falsely represent a brand, executive, employee, or customer-support team. These accounts may distribute scams, collect payments, promote counterfeit products, or direct users to malicious websites.
BrandShield monitors social platforms for unauthorized brand and identity use. It can help analyze related accounts, content, links, and campaign patterns before submitting eligible cases for platform review and removal.
Subdomain Impersonation
Subdomain impersonation uses a misleading URL structure to make a malicious website appear associated with a trusted brand. The brand name may appear in the subdomain while the actual registered domain belongs to the attacker, such as brand.secure-login-example.com.
BrandShield analyzes full domain and URL structures rather than relying only on visible brand terms. Suspicious subdomains can be evaluated based on ownership, content, redirects, technical infrastructure, and connections to other malicious assets.
Smishing
Smishing is a form of phishing conducted through SMS or mobile messaging services. Attackers typically impersonate trusted companies, financial institutions, delivery providers, executives, or customer-support teams and direct victims toward malicious links, fraudulent websites, or requests for sensitive information.
BrandShield helps identify external assets associated with smishing campaigns, including phishing websites, lookalike domains, fraudulent support pages, and impersonating digital identities. These assets can be analyzed, connected to related threat infrastructure, and submitted for enforcement when an appropriate removal path exists.
T
Threat Actor
A threat actor is an individual, group, or organization responsible for malicious or potentially harmful cyber activity. Threat actors may include financially motivated criminals, organized fraud networks, malicious insiders, state-sponsored groups, counterfeiters, scammers, or other entities seeking to exploit organizations, employees, customers, or digital assets.
BrandShield helps organizations identify patterns across external threats that may indicate coordinated activity by the same threat actor or network. By analyzing domains, websites, social accounts, advertisements, infrastructure, and other digital signals, BrandShield can connect related incidents into broader threat clusters and help security teams prioritize the most significant risks.
Threat Intelligence
Threat intelligence is the collection, analysis, and interpretation of information about cyber threats, threat actors, malicious infrastructure, tactics, and campaigns. It helps security teams understand how threats operate, assess their relevance to the organization, prioritize risk, and make more informed decisions about detection and response.
BrandShield provides external threat intelligence by continuously monitoring domains, websites, social media, advertisements, mobile applications, dark web sources, and other digital channels. Detected threats can be analyzed for relationships, infrastructure, behavior, and risk so organizations can identify coordinated campaigns, prioritize critical cases, and take targeted enforcement or remediation action.
Typosquatting
Typosquatting is the registration of domains containing common misspellings, missing letters, added characters, transposed letters, or alternative spellings of a legitimate domain. Attackers rely on typing errors or visual similarity to redirect users to fraudulent content.
BrandShield monitors domain variations associated with protected brands and identifies those that may create customer or security risk. Active threats can be investigated and, where justified, submitted for takedown or other enforcement action.
V
Vendor Impersonation
Vendor impersonation occurs when an attacker pretends to be a trusted supplier, service provider, distributor, or business partner. The attacker may use a deceptive domain, fake website, spoofed email address, or compromised account to redirect payments or obtain sensitive information.
BrandShield helps identify lookalike domains, fake websites, impersonating accounts, and other external assets used to imitate business partners. It supports external detection and disruption but should be combined with internal payment verification and supplier-management controls.