Cybersecurity 101: Types of Cyber Attacker October 24, 2023 – Posted in: Cyber Security, IT Support – Tags: , ,

The motivations of a malicious actor are important – who is targeting you will make a significant difference to the type of hack and the type of risks to your business. There are many subcategories and further distinctions, but here we cover the most relevant categories for your average small to medium business.

Some options on the list may seem outlandish for a smaller business, but the threat that you might be compromised by a scatter gun approach aimed at someone else is very real. Whilst 73% of breaches in a 2022 report1 were caused by direct external threats, 39% came through partners. That means clients or suppliers unintentionally passing threats on.

THE HAT WEARERS

There is a simple definition between black hat hackers who hack to do damage or steal and white hat hackers who are hired by companies to test systems and find weaknesses. So called grey hat hackers break things just to see if they can, they aren’t entirely benign but do not exploit networks for criminal purposes. A grey hat hacker may turn in information to companies about weaknesses in their systems in return for rewards. Then there is the red hat hacker, the vigilante. These hackers are essentially hacktivists who target black hat hackers with aggressive or even illegal methods.

SCRIPT KIDDIES OR ELITE HACKERS

The sophistication of the hacker will directly impact how large the potential for damage is for your business. A script kiddie is someone who has simply copied or bought some existing malware and thrown it into the world, often targeting large numbers of people with a less sophisticated hook – the likelihood of attack is high, but the potential for damage is lower. An elite hacker will write custom malware to target a specific piece of software or company, they are often determined, clever and creative in their activity. The likelihood that the average SME business will be directly targeted by an elite hacker is low, but the potential for damage could be catastrophic.

That is not to say that the less sophisticated attacks can’t cause significant issues – 48% of small businesses reported a negative outcome from a cyberattack and the average direct cost of a breach with a negative outcome to UK based small businesses in 2022 was £3,0802. That doesn’t include the cost of time spent fixing or investigating the breach, time when staff couldn’t do their jobs or the cost of devices or equipment that needed replacing.

NATION STATES & INDUSTRIAL ESPIONAGE

Some malicious actors are paid by Nations or by big businesses to target enemies, allies or competitors. The primary aim of an attack is likely to be a data theft or systemic damage to major infrastructure. It is unlikely that a SME business will be targeted directly by a Nation State or large business – so why are we mentioning them here?

Firstly, it is the exploits and malware that these well-funded organisations create that is often sold on to other, smaller organisations who will have a less narrow focus.

Secondly, malware is rarely a targeted snipe. Some of the most effective sabotaging malware is effective because it can spread – with or even without the help of unwitting users. If a massive infrastructure related firm was targeted, say a large building company or a water company, they would likely have the turnover to employ sophisticated protections to stop the virus before they lost too much and repair any damage done. But, it is likely that by the time they realised they had a problem they may have passed the virus on to some of their suppliers or clients, who may then pass it on to their suppliers or clients. Before you know it a thousand small businesses are at risk.

It’s also important to bear in mind that whilst an SME business is unlikely to be the direct target of cyberterrorism or international espionage, some Nation States have been known use cybercrime as a revenue stream – and you are as valid a target as anyone else for ransomware or theft of data to sell on the black market.

CRIMINAL ORGANISATIONS

There are a multitude of criminal organisations, ranging from the classic lone hacker to sophisticated enterprises employing hundreds of staff. The aim of these criminal organisations is generally profit. They are looking to extort, con or steal money directly or saleable information.

Historically the delivery of malware was a significant challenge so a targeted approach to high value victims was the most lucrative option. In today’s connected world delivery of malware is easier than it has ever been so more organisations take a stack them high and sell them cheap approach to cybercrime. Send out 2 million emails, get a 0.5% uptake rate and get £200 out of each victim and make a couple of million pounds.

You will likely have seen it yourself – emails trying to persuade your staff that you want them to buy vouchers from a specific website, screaming red overdue bills from companies you have never heard of, or requests to put in your email address and password to download an important document. 36% of small businesses in the UK fell for one of these scams in 2022.

HACKTIVISTS

There are those who consider themselves on the side of good who will hack to get information they feel should be in the public domain, or make a statement against policies or organisations they feel are damaging society. Whatever intentions are, by finding exploits and not reporting them to the relevant authorities, and creating malware to attack those that they feel deserve it, they are creating tools that can be used against anyone.

Most SME businesses are unlikely to be targeted directly by hacktivists, but as always a hack rarely stays confined. Malware spreads, tools are stolen or sold and in the cloud servers carry more than one business’s data.

INSIDER THREATS

The highest risk of damage for most organisations come from the insider threat. Verizon reported that in 2022 whilst only 18% of breaches were directly created by an internal threat, the average number of data records compromised was 375,000 for insider threats, compared to 30,000 for external threats. A disgruntled employee or ex-employee could be seeking revenge, or someone could be blackmailed, tricked or bribed into walking out with a memory stick full of proprietary information.

No-one wants to think that a colleague might turn on them or their business but every business is at risk from insider threats, and they are the hardest to guard against.