Skip to content
Cyber Unboxed
Threat Intelligence

Threat Actors: Who Is Actually Attacking, and Why

Not every attacker wants the same thing. Knowing the type of adversary helps you guess what they will do next.

2 min readBeginner Sep 15, 2026

Explain Like I'm Not a Hacker

Different burglars want different things: cash, secrets, or to make a point. Knowing which type you face tells you which door to lock first.

The 30-second explanation

Some attackers want money, some want secrets, some want attention, some are angry insiders. What they want decides how patient they are and what they go after.

How it works

  1. 1

    1. Motivation

    Money, secrets, cause or grievance.

  2. 2

    2. Capability

    From opportunistic to highly resourced.

  3. 3

    3. Behaviour

    How they get in and what they do next.

  4. 4

    4. Priority

    Defend against what fits your risk.

Criminals mainly seek money, using ransomware, fraud and stolen data. State-linked groups seek intelligence or strategic advantage, and are usually patient and well-resourced. Hacktivists want publicity for a cause and often use defacement, leaks or floods of traffic. Insiders already have access and may be careless or aggrieved. Because a group can fit several categories, defenders focus on behaviour and evidence rather than labels, and are careful about attribution.

Real-world example

A small online business is far more likely to face opportunistic criminals looking for easy money than a state-backed group, so it prioritises backups, MFA and patching over exotic defences.

How to spot it

  • Fast, noisy activity

    Often opportunistic or financially motivated.

  • Slow, careful access

    Often long-term intelligence gathering.

  • Public claims and messages

    A sign of publicity-seeking activity.

  • Access from trusted accounts

    May indicate an insider or stolen credentials.

What to do

  1. 1List who is most likely to target you and why, then match your defences to that list.
  2. 2Be cautious with attribution: treat labels as hypotheses until evidence supports them.
  3. 3Revisit the list when your business, data or public profile changes.

Stay curious. Stay safer.

This is one piece of a bigger picture. Explore more real-world examples, concepts and tips to build your cybersecurity awareness.

Explore More

Keep reading