Skip to content

6 min read

American Corners

How an attack unfolds

An attack is a journey, not a single leap

It is tempting to picture a break-in as one dramatic moment. In reality most attacks unfold in stages, one step leading to the next. That is actually good news: a journey with several steps gives you several chances to notice something is wrong and stop it before real harm is done. We will walk through three simple stages: getting in, moving, and acting.

Stage one: getting in

First the attacker needs a way through the door. The most common way is not clever code but a message that fools a person. Phishing is a fake message, usually an email, built to look trustworthy so you click a link, open an attachment or type your password on a fake page. One careless click can hand over a password or quietly install malicious software.

Other entry points exist, like an unpatched weakness or a stolen password, but a person tricked by a convincing message is the classic front door.

Stage two: moving

Getting in rarely lands the attacker exactly where the valuable things are, so they move. From one mailbox they read messages and reset other passwords. From one laptop they look for shared drives, saved logins and other machines on the same network. Often they take their time and try to blend in with normal activity, so nothing obvious stands out.

This quiet middle stage is easy to miss, but it is also full of chances to catch it: a login from a strange place, an account doing something it never does, a file being opened at 3am.

Stage three: acting

Finally the attacker does what they came for. That might be stealing data, sending fake payment requests from a trusted mailbox, or launching ransomware to lock everything and demand money. By this stage the damage is visible, which is exactly why stopping the earlier stages matters so much.

Every stage is a place to stop

The useful lesson is that you do not need to be perfect at every step. Break the chain at any stage and the attack fails.

  • At "getting in": pausing on one suspicious message stops the whole thing before it starts.
  • At "moving": strong, unique passwords and multi-factor authentication (MFA) make it far harder to jump from one account to the next.
  • At "acting": a tested backup means even ransomware does not have to be a disaster.

Think of it as several locked doors rather than one. An attacker has to beat all of them; you only have to hold one.

Before you move on, try putting the three stages back in the order an attack actually moves through:

Order the attack chain

Drag a step by its handle, use its ▲ / ▼ buttons, or focus it and press Enter to pick it up then use the arrow keys. Then check your order.

Where this lesson comes from

Built from

  • Workshop 1: Cybersecurity Essentials (participant guide V3.0): attack stages

alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement