Who attacks and why

40 min 4 outcomes ENISA and DBIR 2025 cited

Here is the short answer this module defends: most people who attack organisations are not lone geniuses. They are running a business. Ransomware in particular is now a supply chain of specialists who each take a cut, and the four broad kinds of attacker (financially motivated criminals, state actors, hacktivists and insiders) behave in predictable ways that a defender can plan against. If you can read a threat report without being fooled by a scary headline, you can spend a security budget where the evidence says the danger actually is.

By the end of this module you will be able to:

  • Describe the ransomware-as-a-service value chain and say who profits at each link
  • Tell financially motivated crime, state actors, hacktivists and insiders apart by motivation and typical tradecraft
  • Read headline threat statistics critically by checking what population they are drawn from
  • Explain why assuming a sophisticated attacker is usually the wrong first move

Police seized the servers. The business carried on.

In February 2024, a task force led by the UK National Crime Agency and the United States FBI, working across ten countries under the name Operation Cronos, seized the infrastructure of LockBit, at the time the most prolific ransomware brand in the world. The police took over LockBit's own leak site and, in a neat piece of theatre, used it to publish details of the group instead of its victims.

The disruption was real, but it did not end the threat. The criminal ecosystem fragmented rather than shrank. By the third quarter of 2025 researchers were counting around 85 active ransomware groups, more brands than before the takedown, as displaced operators moved to rival services or started their own. What did change was the money: the share of victims choosing to pay fell to roughly 23 percent in the same quarter, a record low, as more organisations recovered without paying and as paying became legally and reputationally riskier.

The lesson runs through the whole module. Enforcement disrupts brands, but it does not change the economics underneath them. To understand why, you have to look at attack as an industry rather than as a series of individual villains.

If an international police operation can seize a criminal group's own website, why did ransomware not fall afterwards?

1. The attacker is running a business

The single most useful shift in how you think about attackers is to stop imagining one person at a keyboard and start imagining a market. The clearest example is , usually shortened to RaaS. Instead of one gang doing everything, the work is split between specialists who buy and sell from each other, exactly like any other industry.

At one end, developers write the malware and license it out, running it like a software company with updates, dashboards and support. They typically keep a fixed share of any ransom, in the region of 20 to 30 percent. Separately, an sells a ready-made foothold: stolen remote-access credentials or a live session into a target network, priced per victim. An affiliate then rents the malware, buys the access, and actually runs the intrusion, keeping the largest share of the proceeds, often 70 to 80 percent. When the victim pays, a launderer moves the cryptocurrency through mixers and exchanges and takes a cut to convert it into usable funds.

The reason this matters for defence is structural. Once attacking is a business with specialists and margins, it scales. Brokers sell the same kind of foothold to many affiliates, affiliates run the same playbook against many victims, and the tooling is bought rather than invented. So a defender should plan for commodity techniques arriving in volume, not for a bespoke, one-off masterpiece aimed personally at them. The figure below traces a single intrusion down through the chain and marks the cut each link takes.

Common misconception

We were breached, so it must have been a sophisticated nation-state attacker.

This is usually the wrong first assumption, and reaching for it can be a way to avoid an awkward truth. The evidence base is consistent: most intrusions begin with commodity routes such as phishing, stolen or reused credentials, and unpatched internet-facing devices, run by financially motivated affiliates using bought tooling. Sophisticated actors exist, but attributing a breach to one before the evidence supports it tends to excuse the basic control that actually failed. Start from the likely, not the flattering.

2. Four motivations, four behaviours

Attackers are easiest to reason about through their motivation, because motivation predicts behaviour: how persistent they will be, which targets they choose, and what counts as success for them. Four broad classes cover most of what a typical organisation faces.

Financially motivated criminals are behind most incidents. They want profit at scale, they get in through phishing and stolen credentials, and they persist only for as long as it keeps paying. Success for them is a ransom paid or data resold. State actors are after espionage and quiet prepositioning inside systems they may want to disrupt later. They can afford zero-day exploits and supply-chain routes, they stay patient and hidden, and success is access that is never noticed. A wants publicity for a cause, favours noisy techniques such as distributed denial of service and website defacement, runs in short campaigns, and counts visible disruption as a win. ENISA found that hacktivist activity, dominated by denial-of-service attacks, made up roughly 77 percent of the incidents it counted between July 2024 and June 2025, a reminder that loud and frequent is not the same as damaging.

The fourth class is different in kind. An is someone who already has legitimate access, so there is no intrusion to detect at all. Their motive may be grievance, greed or coercion, they are already inside the perimeter, and success is data taken before anyone notices. No firewall sits between an insider and the data they are trusted with, which is why this class needs a different set of controls built around monitoring and separation of duties rather than keeping attackers out.

3. Reading the evidence base

Threat statistics are quoted in board papers all the time, and they are often mishandled. The two most cited annual sources are the ENISA Threat Landscape and the Verizon Data Breach Investigations Report, and they do not measure the same thing. Knowing the difference is what lets you use a number honestly.

The 2025 ENISA Threat Landscape looked at roughly 4,875 incidents recorded across Europe. It found ransomware to be the most impactful threat, that accounted for about 60 percent of initial access, and that vulnerability exploitation featured in about 21 percent of cases. The Verizon 2025 report, by contrast, studies confirmed breaches: it found ransomware present in 44 percent of them, that third-party involvement had doubled to around 30 percent, and that exploitation of edge and virtual private network devices had risen roughly eightfold. Both are credible, but the first counts incidents and the second counts breaches, and an incident is not the same as a breach.

That distinction is the whole point. A population of all recorded incidents is swollen by high-volume, low-impact events such as denial-of-service floods, so hacktivism looks enormous in it. A population of confirmed breaches strips those out and shows what actually caused damage, so ransomware and stolen credentials rise to the top. Before you quote a percentage, ask what the denominator is: percentage of what, counted by whom, over what period. A number without its denominator is a decoration, not evidence.

Common misconception

Ransom payment rates are falling, so ransomware is going away.

Falling payment rates are good news, but they do not mean the threat is shrinking. After the LockBit takedown the number of active groups rose while the share of victims who paid fell to around 23 percent. Attackers responded to fewer payments by demanding more from those who do pay and by leaning harder on data theft and leak threats, so that even a victim with good backups faces pressure. Fewer payments changes the shape of the threat, not its presence. This is the double-extortion pattern, and it gets its full treatment in the practice and strategy stage.

4. What this means for the rest of the course

If you take the evidence seriously, it tells you where to spend attention. Most breaches still begin in a small number of ordinary ways: someone is phished, a credential is stolen or reused, or an internet-facing device is left unpatched. Exotic techniques exist, but they are not where the volume is. A course that matched effort to risk would therefore spend most of its depth on identity, on reducing exposure, and on detecting intrusions early, because that is where commodity attacks land.

That is exactly how the rest of this course is weighted. The idea that attackers behave in patterns you can plan against, which is the payoff of forward-defining and the actor classes here, feeds directly into how you reason about likelihood in the next module on risk and outcomes. You now have the vocabulary for who is on the other side; risk turns that into a judgement about what to protect first.

Check your understanding

A mid-sized firm is hit by ransomware. Investigators find the intruders bought working VPN credentials from a third party and rented the encryptor from another group. Which actor class and structure does this fit?

A colleague quotes 'hacktivists cause 77 percent of attacks' from a threat report to argue for spending on denial-of-service defence. What is the most useful challenge?

Core distinctions

  • Modern attack is an industry. Ransomware-as-a-service splits the work between developers who license the malware, access brokers who sell footholds, affiliates who run intrusions and keep the largest cut, and launderers who cash out.
  • Because attack is a supply chain, plan for commodity tooling arriving in volume, not for a bespoke attack aimed personally at you.
  • Four actor classes cover most of what an organisation faces: financially motivated crime (profit, most incidents), state actors (quiet espionage and prepositioning), hacktivists (noisy publicity, most counted incidents), and insiders (legitimate access, no intrusion to detect).
  • ENISA counts incidents and Verizon counts breaches, so their headline numbers differ by design. Before quoting a statistic, ask what population it is drawn from.
  • Most breaches still start with phishing, stolen credentials or unpatched edge devices, which is why the course spends its depth on identity, exposure and detection rather than on exotic threats.

Standards and sources cited in this module

  1. ENISA Threat Landscape 2025

    Prime threats, ransomware and hacktivism, reporting period July 2024 to June 2025

    Source for the incident-population figures: roughly 4,875 incidents, ransomware as the most impactful threat, phishing about 60 percent of initial access, vulnerability exploitation about 21 percent, and hacktivist denial-of-service activity around 77 percent of counted incidents.

  2. Verizon 2025 Data Breach Investigations Report

    Summary of findings; ransomware, third-party and edge-device exploitation

    Source for the breach-population figures: ransomware present in 44 percent of breaches, third-party involvement doubled to around 30 percent, and exploitation of edge and VPN devices up roughly eightfold. Used to contrast a breach population with ENISA's incident population.

  3. Security Affairs, 'Ransomware payments hit record low, only 23% pay in Q3 2025' (2025)

    Quarterly payment-rate reporting

    Source for the Q3 2025 payment rate of about 23 percent used in the opening case and the third misconception card.

  4. Morphisec, 'The evolving economics of ransomware: fewer payments, bigger payouts' (2025)

    Post-LockBit ecosystem analysis

    Source for the fragmentation of the ecosystem after Operation Cronos, including the count of around 85 active groups by Q3 2025 and the shift toward larger demands on the victims who do pay.

Module 2 of 41 · Foundations