Clickjacking is a malicious technique for tricking a user into clicking on something other than what the user believes they are clicking, typically by layering an invisible or disguised clickable element over legitimate-looking content. A victim who believes they are pressing a visible button, such as a video's play control, can instead unknowingly trigger a hidden action, like a purchase, because the click is captured by the concealed element beneath it. Because the victim is usually already logged into the targeted service, the resulting action carries the victim's own authentication, making the attack hard to trace back to its perpetrator. The technique was named by researchers Jeremiah Grossman and Robert Hansen in 2008 and has since developed into variants targeting browsers, mobile apps and other platforms. This description is adapted from Wikipedia contributors under CC BY-SA 4.0; changes were made. https://creativecommons.org/licenses/by-sa/4.0/
Facts
Classification
Offense GradeMinor or Summary Offense 1 Connections
Has Offense Grade
Entity-backed identity for the offense-grade enum value this offense already carries, resolved to a crime concept by an explicit value-to-entity map (phase 3 bucket conversion, docs\design_entity_backed_browse_buckets_20260928.md). The offense-grade fact itself stays on the offense unchanged.
Sources
1. Clickjacking (Wikipedia)
Reader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.