Threat Actors: Who Is Actually Attacking, and Why
Not every attacker wants the same thing. Knowing the type of adversary helps you guess what they will do next.
2 min readBeginner Sep 15, 2026
Explain Like I'm Not a Hacker
Different burglars want different things: cash, secrets, or to make a point. Knowing which type you face tells you which door to lock first.
The 30-second explanation
Some attackers want money, some want secrets, some want attention, some are angry insiders. What they want decides how patient they are and what they go after.
How it works
- 1
1. Motivation
Money, secrets, cause or grievance.
- 2
2. Capability
From opportunistic to highly resourced.
- 3
3. Behaviour
How they get in and what they do next.
- 4
4. Priority
Defend against what fits your risk.
Criminals mainly seek money, using ransomware, fraud and stolen data. State-linked groups seek intelligence or strategic advantage, and are usually patient and well-resourced. Hacktivists want publicity for a cause and often use defacement, leaks or floods of traffic. Insiders already have access and may be careless or aggrieved. Because a group can fit several categories, defenders focus on behaviour and evidence rather than labels, and are careful about attribution.
Real-world example
A small online business is far more likely to face opportunistic criminals looking for easy money than a state-backed group, so it prioritises backups, MFA and patching over exotic defences.
How to spot it
Fast, noisy activity
Often opportunistic or financially motivated.
Slow, careful access
Often long-term intelligence gathering.
Public claims and messages
A sign of publicity-seeking activity.
Access from trusted accounts
May indicate an insider or stolen credentials.
What to do
- 1List who is most likely to target you and why, then match your defences to that list.
- 2Be cautious with attribution: treat labels as hypotheses until evidence supports them.
- 3Revisit the list when your business, data or public profile changes.
Stay curious. Stay safer.
This is one piece of a bigger picture. Explore more real-world examples, concepts and tips to build your cybersecurity awareness.
Keep reading
- Threat Intelligence
Threat Intelligence: How Defenders Learn to Think Like Attackers
2 min read - Advanced Persistent Threats
APT: The Attackers Who Are Willing to Wait
2 min read - Hacktivism
Hacktivism: When Cyber Attacks Carry a Message
2 min read - Security Basics
MFA: The Second Lock That Hackers Can Still Pick
3 min read