Skip to content

7 min read

American Corners

Who the attackers are

It is rarely personal

Most people imagine a single hooded figure targeting them by name. The reality is more ordinary and, oddly, more reassuring: the great majority of attacks are not aimed at you in particular. They are wide nets, cast to catch whoever is careless that day.

Knowing who casts those nets, and why, helps you judge what is actually likely, which is the first step in the Impact × Likelihood thinking from the previous lesson.

The main groups

  • Cybercriminals. By far the most common. Their motive is money, through ransomware, phishing, and fraud. They favour easy, repeatable targets, which is exactly why everyday habits stop most of them.
  • Nation-state actors. Well resourced groups working for a government, after intelligence or disruption. They are patient and targeted, but most people and small organisations are simply not their focus.
  • Hacktivists. Driven by a cause rather than profit. They want attention, often through defacing a site or leaking data to make a point.
  • Insiders. Someone with legitimate access: an employee, a contractor, a partner. Most insider incidents are not malicious at all, just a mistake, a missent file, or a reused password.
  • Cyberterrorists. Rare, aiming to cause fear or damage to critical services. Important to name, but not the everyday threat.

What this means for you

Two things follow from the list.

First, because ordinary cybercrime is the common case, ordinary defences matter most. The habits that frustrate a mass phishing campaign, checking the sender and never rushing, are the same ones this course keeps returning to.

Tip

The most common "attacker" is not a stranger at all. It is an honest colleague in a hurry. Building calm, simple habits protects against mistakes just as much as against malice.

Second, verifying anything unusual through a separate, trusted channel works no matter who is behind it. You do not need to identify the attacker to shut the door.

Try this now

Open the spam or junk folder of your own inbox and pick one message. Using the groups above, decide which kind of attacker most likely sent it and what they were after. Almost every time it will be an ordinary cybercriminal casting a wide net for money, which is exactly the pattern this lesson describes.

Where this lesson comes from

Built from

  • Workshop 1: Cybersecurity Essentials (participant guide V3.0): threat actors

alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement