Who is attacking - and why?
Every cyberattack has a person or group behind it. In cybersecurity, you call them threat actors - individuals or organizations that intentionally exploit vulnerabilities in systems, networks, or people to cause harm or gain an advantage. Understanding threat actors is one of the first things a security professional learns because who is attacking tells you how they will attack, what they are after, and how much effort they will invest.A threat actor is any person, group, or entity responsible for a cyber event that impacts - or has the potential to impact - an organization’s security.

Threat actors come in many forms
The six types of threat actors

Cyber threats by the numbers - why every business needs security
1. Cybercriminals
Motivation: Money - always money.
Cybercriminals are motivated by financial gain
2. Hacktivists
Motivation: Ideology, politics, or social causes. Hacktivists use hacking as a form of protest. They deface websites, leak confidential documents, and launch denial-of-service attacks to draw attention to causes they believe in. Their targets are usually governments, corporations, or organizations they view as unethical.3. Nation-state actors
Motivation: Strategic national interests - espionage, disruption, or warfare. These are government-sponsored hackers. They have enormous budgets, advanced tools, and time on their side. Their goals include stealing military secrets, disrupting foreign infrastructure, influencing elections, and gaining economic advantages through intellectual property theft.4. Advanced persistent threats (APTs)
Motivation: Long-term strategic access. APTs are not a separate motivation category - they are a method. APT groups (often nation-state backed) gain access to a network and remain hidden for months or even years. They move slowly, avoid detection, and extract data over time. The term “advanced” refers to their sophisticated techniques. “Persistent” means they maintain access continuously. “Threat” means they cause real damage.APT groups are often given numbers by security researchers. APT29 (also called “Cozy Bear”) is linked to Russian intelligence. APT41 is associated with China and conducts both espionage and financially motivated attacks.
5. Script kiddies
Motivation: Curiosity, bragging rights, or boredom. Script kiddies use pre-built hacking tools and scripts without understanding how they work. They download attack software, watch YouTube tutorials, and target easy victims. While individually less dangerous, they can still cause real harm - especially when powerful tools are freely available online.Don’t underestimate script kiddies. A teenager with a freely available exploit kit can still breach a company that hasn’t patched its systems. The tools do the hard work - the attacker just points and clicks.
6. Insider threats
Motivation: Varies - revenge, financial gain, negligence, or coercion.
Insider threats hide among trusted users - the red face in a sea of friendly ones
- Malicious insiders - Intentionally steal data, sabotage systems, or sell access to outsiders
- Negligent insiders - Accidentally cause breaches through carelessness (clicking phishing links, misconfiguring systems, losing devices)
Hacker hat classification
The security industry also classifies hackers by their intent, using a color-coded “hat” system.Black hat hackers
Black hat hackers
Black hats are the villains. They hack without authorization and with malicious intent - to steal, destroy, or profit. Everything they do is illegal.
- Break into systems without permission
- Steal data, deploy ransomware, or sell exploits
- Motivated by money, revenge, or power
White hat hackers
White hat hackers
White hats are the heroes. They hack with authorization to find and fix vulnerabilities before the bad guys do. They are also called ethical hackers or penetration testers.
- Hired by organizations to test security
- Follow strict rules of engagement
- Report everything they find
- Careers: penetration tester, security consultant, red team operator
Gray hat hackers
Gray hat hackers
Gray hats operate in a legally ambiguous zone. They find vulnerabilities without authorization but typically report them to the owner rather than exploiting them. Their intentions may be good, but their methods are technically illegal.
- Find bugs without permission
- Usually report findings to the organization
- May demand payment (bug bounty) or publicly disclose if ignored
- Legally risky - even helpful hacking without authorization can lead to prosecution
Threat actor attributes
When analyzing a threat actor, security professionals evaluate three key attributes.- Internal vs. external
- Funding level
- Sophistication level
- External threat actors operate from outside the organization. They must breach perimeter defenses first.
- Internal threat actors already have some level of authorized access. They are harder to detect because their activity may look normal.
Shadow IT
Shadow IT refers to technology used within an organization without the knowledge or approval of the IT department. It creates hidden attack surfaces that security teams cannot monitor or protect.Intellectual Point example: Imagine an employee stores client project files on their personal Google Drive instead of the company’s approved SharePoint. If that personal account is compromised, the company’s data is exposed - and the security team never even knew the data was there.
- Using personal cloud storage (Dropbox, Google Drive) for work files
- Installing unapproved apps on work computers
- Using personal email for business communication
- Setting up unauthorized Wi-Fi access points
- Using consumer messaging apps (WhatsApp, Telegram) for work discussions
Key vocabulary
Master these terms - you will see them throughout the rest of the week.Exercise: identify the threat actor
Read each scenario and identify the threat actor type and their likely motivation.Scenario 1
Scenario 1
A group encrypts a hospital’s patient records and demands $500,000 in Bitcoin to restore access.Answer: Cybercriminal. Motivation: financial gain. This is a classic ransomware attack targeting critical infrastructure because hospitals are more likely to pay quickly.
Scenario 2
Scenario 2
A teenager downloads a tool from a hacking forum and uses it to deface their school’s website with a meme.Answer: Script kiddie. Motivation: curiosity and bragging rights. They used a pre-built tool and targeted an easy victim with poor security.
Scenario 3
Scenario 3
A foreign intelligence agency spends six months quietly collecting emails from a defense contractor’s executives.Answer: Nation-state actor / APT. Motivation: espionage. The long duration, stealth, and strategic target all point to a state-sponsored operation.
Scenario 4
Scenario 4
An employee who was just told they are being laid off downloads the entire customer database to a USB drive on their last day.Answer: Insider threat (malicious). Motivation: revenge or personal gain. They used their legitimate access to steal data before losing it.
Scenario 5
Scenario 5
A collective leaks thousands of internal emails from a large oil company to protest their environmental record.Answer: Hacktivists. Motivation: ideological - environmental activism. The leak is designed to embarrass and pressure the company, not to profit financially.
Scenario 6
Scenario 6
An accounting employee clicks a phishing link and accidentally gives attackers access to the payroll system.Answer: Insider threat (negligent). The employee didn’t act maliciously - they made a mistake. But the result is the same: the attacker now has access.

