Cybercrime has grown into a complex, organized ecosystem that threatens individuals, businesses, and even nations. To build resilient defenses in smart cities and connected environments, security professionals must understand who commits these crimes, who they target, why they do it, and how they carry out attacks. This understanding forms the foundation of any effective cybersecurity strategy.

Table of Contents

Identifying targets in cybercrime: individuals, organizations, and nations

Cybercriminals cast a wide net when selecting their targets, but their choices are far from random. The healthcare sector bears the brunt of cybercrime activity, accounting for 14.2% of all attacks targeting critical infrastructure. Financial organizations follow closely, making up 8.3% of attacks, with telecommunications, transport, and energy sectors also facing regular targeting.

Individuals as targets

Everyday people remain prime targets for cybercriminals. Attackers seek personal information such as credit card data, login credentials, and social security numbers to commit identity theft, financial fraud, or sell the information on the dark web. One study from the University of Maryland estimates a cyberattack occurs every 39 seconds, demonstrating just how frequently individuals face digital threats.

Organizations as targets

Businesses of all sizes face cybercrime risks, though small and medium enterprises often underestimate their vulnerability. Many small organizations think they’re too small to be targeted by cybercriminals, but this is simply not true. In reality, smaller businesses possess valuable information that criminals seek while often having fewer resources dedicated to cybersecurity.

Organizations are targeted for multiple reasons: to steal intellectual property, disrupt operations through ransomware, commit corporate espionage, or gain competitive advantage. The healthcare, technology, and education sectors were top targets in 2024, with sophisticated techniques once reserved for large enterprises now becoming commonplace against organizations of every size.

Nations as targets

Nation-states have become significant targets in cyberspace. Between January 2023 and January 2024, global critical infrastructure faced over 420 million cyberattacks, averaging approximately 13 attacks per second. While the United States was the primary target, 163 other countries also experienced attacks on critical infrastructure, often attributed to state-sponsored hackers.

Nation-states are targeting critical infrastructure to collect information and gain access to industrial control systems in the energy, nuclear, water, aviation, and critical manufacturing sectors. These attacks can threaten national security, economic prosperity, and public health and safety.

Who are the threat actors? Hackers, insiders, and nation-states

A threat actor is anyone who is either a key driver of or participates in a malicious action that targets an organization’s IT security. These actors range from lone individuals to sophisticated state-sponsored groups, each with distinct motivations and capabilities.

Cybercriminals

Professional cybercriminals represent the most common type of threat actor. These threat actors focus on stealing sensitive financial data from corporations, money from financial systems, or personal information from customer records. They operate using well-structured methods and sophisticated tools, often working through organized criminal networks rather than as lone hackers.

Ransomware-as-a-Service (RaaS) groups have industrialized cybercrime, with groups like LockBit, PLAY, and RansomHub giving affiliates higher percentage payouts-often reaching 80-90% of the ransom-and collectively accounting for 54% of all ransomware incidents in 2024.

Insider threats

Insider threats are difficult to identify and prevent because they originate inside the targeted network. An insider doesn’t have to break down defenses to steal data or commit other cybercrimes. They may be an employee, consultant, board member, or any other individual with privileged access to the system. Motivations for insider threats include personal grievances, financial gain, or coercion by external actors.

Nation-state actors

Nation-state actors and nation-state-sponsored entities pose an elevated threat to national security. These adversaries are known for their advanced persistent threat (APT) activity. The Chinese government engages in malicious cyber activities including infiltrating critical infrastructure networks. The Iranian government has exercised increasingly sophisticated cyber capabilities to suppress social and political activity. The North Korean government employs malicious cyber activity to collect intelligence, conduct attacks, and generate revenue.

Nation-state threat actors work at a national level and generally target intelligence in the nuclear, financial, or technology sectors. They are highly trained, extremely stealthy, and protected by their nation’s legal system.

Hacktivists

Hacktivists are individuals or groups driven by political or social motivations. They often use denial of service attacks and other disruptive tactics to promote their beliefs or make a statement. Unlike financially motivated criminals, hacktivists are driven by ideological causes and aim to publicize an organization’s perceived wrongdoing.

Motives behind cyberattacks: financial gain, espionage, and disruption

Understanding why threat actors attack is essential for predicting and preventing cyber incidents. Motives vary widely and often overlap.

Financial gain

Many cybercriminals are primarily motivated by financial gain. They seek to steal sensitive information such as credit card data, personal information, or login credentials, which they can sell on the black market or use for fraudulent activities. Hackers can break into a bank account to take funds directly or use social engineering scams to mislead individuals into transferring money.

Financially motivated attacks typically involve ransomware. Cybercriminals encrypt data and demand ransom payments to unlock infected systems. The attackers often target sectors where downtime can have severe consequences, such as healthcare and utilities, to increase the likelihood of receiving payments.

Espionage and strategic advantage

Nation-states, corporate competitors, or other entities may engage in cyber espionage to gather sensitive information, trade secrets, intellectual property, or government secrets for political, economic, or strategic advantage. Governments or state-sponsored entities may also conduct cyber operations to advance their national interests, engage in geopolitical maneuvering, or gather intelligence.

State-sponsored attackers target critical infrastructure to cause widespread disruptions, safety risks, and economic damage. Since these attackers need long-term access to IT infrastructure, their preferred approach is known as the advanced persistent threat (APT).

Disruption and sabotage

Geopolitically motivated cyberattacks aim to disrupt critical infrastructure to assert dominance or influence over a region. Nation-states engage in cyber espionage and warfare, seeking strategic, political, or military advantages.

In late 2022, Russia-linked threat actor Sandworm targeted Ukrainian critical infrastructure, deploying techniques to trip substation circuit breakers. This attack led to an unplanned power outage that coincided with widespread missile strikes, causing civilian casualties and leaving regions temporarily without electricity.

Political and ideological causes

Pro-Russia hacktivist groups have been conducting cyber operations against numerous organizations and critical infrastructure sectors worldwide. Consisting of individuals who support Russia’s agenda but lack direct governmental ties, most of these groups target Ukrainian and allied infrastructure. These groups are primarily seeking notoriety with their actions, though they have caused actual damage in some instances.

Common vectors and techniques: social engineering, malware, and botnets

Attack vectors are points of vulnerability that unauthorized users can exploit to enter IT systems. Understanding these methods helps organizations implement targeted defenses.

Social engineering and phishing

Social engineering is when an adversary targets a human and uses the power of emotion-such as love, fear, or greed-to manipulate the person into taking a desired action. This technique exploits human psychology rather than technical vulnerabilities.

Phishing attacks use email, social media, or other digital communications to deliver social engineering attacks that deceive users into executing malicious code or sharing confidential information. Attacks may seek to gain credentials, steal financial data, or introduce malware.

Malware types

Malware is a term that describes various strands of malicious software, which include ransomware, spyware, Trojans, and viruses. Cybercriminals use malware as a threat vector to help them gain access to corporate networks and devices, then steal data or damage systems.

Trojans disguise malware as legitimate applications to deceive users into downloading it. Once installed, trojans may contact botnet servers, spy on data, change data, delete data, or perform other malicious actions. They may enter systems through email attachments, websites, file-sharing sites, or spoofed chat messages.

Botnets

Botnets are networks of hijacked computer devices used to carry out various scams and cyberattacks. Assembly of a botnet is usually the infiltration stage of a multi-layer scheme. The bots serve as a tool to automate mass attacks, such as data theft, server crashing, and malware distribution.

The Mirai Botnet infected IoT devices like cameras and routers using default credentials. It has been used for DDoS attacks, overwhelming targets with traffic exceeding 1 Tbps. Modern botnets can also be used to send phishing emails, launch other cyberattacks, steal sensitive data, or mine cryptocurrency.

Exploiting vulnerabilities

New security vulnerabilities are added to the CVE database every day and zero-day vulnerabilities are found just as often. If a developer has not released a patch for a zero-day vulnerability before attackers can exploit it, prevention becomes extremely difficult. This highlights the importance of regular software updates and vulnerability management programs.

Building defenses through understanding

The cybercrime landscape continues to evolve as threat actors develop new techniques and identify new targets. Smart cities and connected environments face unique challenges because of their interconnected nature-a breach in one system can cascade across multiple services. By understanding who the threat actors are, what motivates them, who they target, and how they attack, organizations can develop more effective defense strategies.

What do you think? Given the industrialization of cybercrime and the growing sophistication of threat actors, how should smart cities balance the benefits of connectivity with the need for security? What role should public-private partnerships play in defending critical infrastructure?

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://www.weforum.org/stories/2024/04/cybercrime-target-sectors-cybersecurity-news/
  2. https://www.crowdstrike.com/cybersecurity-101/threat-actor/
  3. https://www.cisa.gov/news-events/news/target-rich-cyber-poor-strengthening-our-nations-critical-infrastructure-sectors
  4. https://cybermagazine.com/articles/how-threat-actors-industrialised-cybercrime-in-2024
  5. https://www.anapaya.net/blog/top-5-critical-infrastructure-cyberattacks
  6. https://www.dhs.gov/archive/secure-cyberspace-and-critical-infrastructure
  7. https://www.sophos.com/en-us/cybersecurity-explained/threat-actors
  8. https://www.redlegg.com/blog/cyber-threat-actor-types
  9. https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors
  10. https://www.recordedfuture.com/threat-intelligence-101/threat-actors/threat-actor-types
  11. https://aimultiple.com/most-common-cyber-attack-vectors
  12. https://industrialcyber.co/analysis/targeting-critical-infrastructure-recent-incidents-analyzed/
  13. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a
  14. https://www.cobalt.io/blog/defending-against-23-common-attack-vectors
  15. https://www.crowdstrike.com/en-us/cybersecurity-101/threat-intelligence/attack-vector/
  16. https://www.fortinet.com/resources/cyberglossary/attack-vector
  17. https://usa.kaspersky.com/resource-center/threats/botnet-attacks
  18. https://www.vectra.ai/topics/cyberattack-techniques
  19. https://www.upguard.com/blog/attack-vector

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Smart Cities – Health, Education, Governance & Cyber Security

1 Digitization of Cities

  1. Urban Planning and Infrastructure Management
  2. Basics of Smart Cities and some of the related applications
  3. Initiatives taken by the Government of India

2 Digitization and Smart Buildings

  1. Introduction: Defining Smart Buildings
  2. Traditional Vs Smart Building
  3. Smart Building Services
  4. Security Camera
  5. Video Intelligence Data
  6. Building Intelligence Data

3 Digital Command and Control Centers

  1. City Command and Control centers
  2. A Peek in Future: Robotics for Digital Transformation in Urban Existence and Related Concerns

4 Basics of Digital Health

  1. Healthcare Systems: Challenges and Solution
  2. Digital Health- Part-I ( Basics of e-Health, e-RM, m-Health, Telemedicine)
  3. Digital Health โ€“ Part-II ( Basics of Smart Health)
  4. Precision Health
  5. Health Stack

5 Smart Health- Specific Application of Emerging Technologies in the Health Domain

  1. An Overview of Emerging Technologies in Healthcare
  2. Application of AI/NLP in SmartHealth : Some Examples
  3. Application of Iots/ Wearable Technologies in Smarthealth: Some Examples
  4. Application of Internet in Healthcare: Various Types

6 Smart Health Management and Networks

  1. What is Electronic Records Management?
  2. Body Area Networks (BANs)/Body Sensor Networks (BSNs)
  3. Home Health Platforms And Smart Home Services
  4. Inclusive Cities For Ambient And Assisted Living

7 Digital Health in India & Concerns

  1. Digital Health Initiatives by Government of India
  2. Challenges, Issues & Related Concerns of Digital/Smart Health

8 Basics of Smart Education

  1. The Need for Smart Education Systems: Contextualized and Personalized Learning Experience for the Learners
  2. Smart Computing Platforms: Role of Emerging Technologies and Digital Platforms in Education Domains

9 Types of Smart Education

  1. Types of Smart Education: Digital and Blended
  2. Possible Smart Education Scenarios
  3. Class Based Differentiated Instruction
  4. Group Based Collaborative Learning
  5. Individual-based Personalized Learning
  6. Mass-based Generative Learning

10 Global and National Best Practices in Smart Education

  1. Global Best Practices
  2. National Advents
  3. Challenges to Smart Education

11 Basics of Smart Governance

  1. Understanding E-government & E-governance
  2. Digital Transformation of Governance to Smart Governance: Role of Emerging Technologies in Governance

12 Industry 4.0 and Smart Governance Practices

  1. Impact of Industry 4.0 on Public Service Delivery
  2. Global UNDESA Rankings
  3. Global Best Practices of SMART Governance in Estonia

13 Evolution and Challenges of Smart Governance

  1. Evolution of e-Governance in India from Past till Now: NeGP, Digital India, IndEA, DSS, Digital Health Mission
  2. Challenges to SMART Governance: Cyber Security, Privacy, Digital Divide, Capacity Building etc

14 Basics of Cyber Security, Types of Cyber Crimes and Safety

  1. Introduction: Defining Cyber Space, Digital Footprints, Cyber Security and Digital Safety
  2. Mapping the Cyber Crime Landscape: Threat Actors, Targets, Motives and Vectors
  3. Introduction to Cyber Crimes
  4. Popular Types of Cyber Crimes
  5. Some Interesting Case-Stories
  6. Ensuring Digital Safety by Practicising CyberHygiene

15 Legal & Regulatory Provisions

  1. Introduction
  2. Legal & Regulatory Provisions in IPC & IT Act by Government of India
  3. Role & Responsibilities of various kinds of Government Organisations
  4. Cyber Security Policy 2013: A Critique and its Way forward
  5. Global Cyber Security Index

16 New and Emerging Technologies

  1. 7 Important Cybersecurity Trends
  2. The Need to adopt the latest Cyber Security Technologies
  3. The Latest Cyber Security Technologies