Cybercrime has grown into a complex, organized ecosystem that threatens individuals, businesses, and even nations. To build resilient defenses in smart cities and connected environments, security professionals must understand who commits these crimes, who they target, why they do it, and how they carry out attacks. This understanding forms the foundation of any effective cybersecurity strategy.
Table of Contents
- Identifying targets in cybercrime: individuals, organizations, and nations
- Individuals as targets
- Organizations as targets
- Nations as targets
- Who are the threat actors? Hackers, insiders, and nation-states
- Cybercriminals
- Insider threats
- Nation-state actors
- Hacktivists
- Motives behind cyberattacks: financial gain, espionage, and disruption
- Financial gain
- Espionage and strategic advantage
- Disruption and sabotage
- Political and ideological causes
- Common vectors and techniques: social engineering, malware, and botnets
- Social engineering and phishing
- Malware types
- Botnets
- Exploiting vulnerabilities
- Building defenses through understanding
Identifying targets in cybercrime: individuals, organizations, and nations
Cybercriminals cast a wide net when selecting their targets, but their choices are far from random. The healthcare sector bears the brunt of cybercrime activity, accounting for 14.2% of all attacks targeting critical infrastructure. Financial organizations follow closely, making up 8.3% of attacks, with telecommunications, transport, and energy sectors also facing regular targeting.
Individuals as targets
Everyday people remain prime targets for cybercriminals. Attackers seek personal information such as credit card data, login credentials, and social security numbers to commit identity theft, financial fraud, or sell the information on the dark web. One study from the University of Maryland estimates a cyberattack occurs every 39 seconds, demonstrating just how frequently individuals face digital threats.
Organizations as targets
Businesses of all sizes face cybercrime risks, though small and medium enterprises often underestimate their vulnerability. Many small organizations think they’re too small to be targeted by cybercriminals, but this is simply not true. In reality, smaller businesses possess valuable information that criminals seek while often having fewer resources dedicated to cybersecurity.
Organizations are targeted for multiple reasons: to steal intellectual property, disrupt operations through ransomware, commit corporate espionage, or gain competitive advantage. The healthcare, technology, and education sectors were top targets in 2024, with sophisticated techniques once reserved for large enterprises now becoming commonplace against organizations of every size.
Nations as targets
Nation-states have become significant targets in cyberspace. Between January 2023 and January 2024, global critical infrastructure faced over 420 million cyberattacks, averaging approximately 13 attacks per second. While the United States was the primary target, 163 other countries also experienced attacks on critical infrastructure, often attributed to state-sponsored hackers.
Nation-states are targeting critical infrastructure to collect information and gain access to industrial control systems in the energy, nuclear, water, aviation, and critical manufacturing sectors. These attacks can threaten national security, economic prosperity, and public health and safety.
Who are the threat actors? Hackers, insiders, and nation-states
A threat actor is anyone who is either a key driver of or participates in a malicious action that targets an organization’s IT security. These actors range from lone individuals to sophisticated state-sponsored groups, each with distinct motivations and capabilities.
Cybercriminals
Professional cybercriminals represent the most common type of threat actor. These threat actors focus on stealing sensitive financial data from corporations, money from financial systems, or personal information from customer records. They operate using well-structured methods and sophisticated tools, often working through organized criminal networks rather than as lone hackers.
Ransomware-as-a-Service (RaaS) groups have industrialized cybercrime, with groups like LockBit, PLAY, and RansomHub giving affiliates higher percentage payouts-often reaching 80-90% of the ransom-and collectively accounting for 54% of all ransomware incidents in 2024.
Insider threats
Insider threats are difficult to identify and prevent because they originate inside the targeted network. An insider doesn’t have to break down defenses to steal data or commit other cybercrimes. They may be an employee, consultant, board member, or any other individual with privileged access to the system. Motivations for insider threats include personal grievances, financial gain, or coercion by external actors.
Nation-state actors
Nation-state actors and nation-state-sponsored entities pose an elevated threat to national security. These adversaries are known for their advanced persistent threat (APT) activity. The Chinese government engages in malicious cyber activities including infiltrating critical infrastructure networks. The Iranian government has exercised increasingly sophisticated cyber capabilities to suppress social and political activity. The North Korean government employs malicious cyber activity to collect intelligence, conduct attacks, and generate revenue.
Nation-state threat actors work at a national level and generally target intelligence in the nuclear, financial, or technology sectors. They are highly trained, extremely stealthy, and protected by their nation’s legal system.
Hacktivists
Hacktivists are individuals or groups driven by political or social motivations. They often use denial of service attacks and other disruptive tactics to promote their beliefs or make a statement. Unlike financially motivated criminals, hacktivists are driven by ideological causes and aim to publicize an organization’s perceived wrongdoing.
Motives behind cyberattacks: financial gain, espionage, and disruption
Understanding why threat actors attack is essential for predicting and preventing cyber incidents. Motives vary widely and often overlap.
Financial gain
Many cybercriminals are primarily motivated by financial gain. They seek to steal sensitive information such as credit card data, personal information, or login credentials, which they can sell on the black market or use for fraudulent activities. Hackers can break into a bank account to take funds directly or use social engineering scams to mislead individuals into transferring money.
Financially motivated attacks typically involve ransomware. Cybercriminals encrypt data and demand ransom payments to unlock infected systems. The attackers often target sectors where downtime can have severe consequences, such as healthcare and utilities, to increase the likelihood of receiving payments.
Espionage and strategic advantage
Nation-states, corporate competitors, or other entities may engage in cyber espionage to gather sensitive information, trade secrets, intellectual property, or government secrets for political, economic, or strategic advantage. Governments or state-sponsored entities may also conduct cyber operations to advance their national interests, engage in geopolitical maneuvering, or gather intelligence.
State-sponsored attackers target critical infrastructure to cause widespread disruptions, safety risks, and economic damage. Since these attackers need long-term access to IT infrastructure, their preferred approach is known as the advanced persistent threat (APT).
Disruption and sabotage
Geopolitically motivated cyberattacks aim to disrupt critical infrastructure to assert dominance or influence over a region. Nation-states engage in cyber espionage and warfare, seeking strategic, political, or military advantages.
In late 2022, Russia-linked threat actor Sandworm targeted Ukrainian critical infrastructure, deploying techniques to trip substation circuit breakers. This attack led to an unplanned power outage that coincided with widespread missile strikes, causing civilian casualties and leaving regions temporarily without electricity.
Political and ideological causes
Pro-Russia hacktivist groups have been conducting cyber operations against numerous organizations and critical infrastructure sectors worldwide. Consisting of individuals who support Russia’s agenda but lack direct governmental ties, most of these groups target Ukrainian and allied infrastructure. These groups are primarily seeking notoriety with their actions, though they have caused actual damage in some instances.
Common vectors and techniques: social engineering, malware, and botnets
Attack vectors are points of vulnerability that unauthorized users can exploit to enter IT systems. Understanding these methods helps organizations implement targeted defenses.
Social engineering and phishing
Social engineering is when an adversary targets a human and uses the power of emotion-such as love, fear, or greed-to manipulate the person into taking a desired action. This technique exploits human psychology rather than technical vulnerabilities.
Phishing attacks use email, social media, or other digital communications to deliver social engineering attacks that deceive users into executing malicious code or sharing confidential information. Attacks may seek to gain credentials, steal financial data, or introduce malware.
Malware types
Malware is a term that describes various strands of malicious software, which include ransomware, spyware, Trojans, and viruses. Cybercriminals use malware as a threat vector to help them gain access to corporate networks and devices, then steal data or damage systems.
Trojans disguise malware as legitimate applications to deceive users into downloading it. Once installed, trojans may contact botnet servers, spy on data, change data, delete data, or perform other malicious actions. They may enter systems through email attachments, websites, file-sharing sites, or spoofed chat messages.
Botnets
Botnets are networks of hijacked computer devices used to carry out various scams and cyberattacks. Assembly of a botnet is usually the infiltration stage of a multi-layer scheme. The bots serve as a tool to automate mass attacks, such as data theft, server crashing, and malware distribution.
The Mirai Botnet infected IoT devices like cameras and routers using default credentials. It has been used for DDoS attacks, overwhelming targets with traffic exceeding 1 Tbps. Modern botnets can also be used to send phishing emails, launch other cyberattacks, steal sensitive data, or mine cryptocurrency.
Exploiting vulnerabilities
New security vulnerabilities are added to the CVE database every day and zero-day vulnerabilities are found just as often. If a developer has not released a patch for a zero-day vulnerability before attackers can exploit it, prevention becomes extremely difficult. This highlights the importance of regular software updates and vulnerability management programs.
Building defenses through understanding
The cybercrime landscape continues to evolve as threat actors develop new techniques and identify new targets. Smart cities and connected environments face unique challenges because of their interconnected nature-a breach in one system can cascade across multiple services. By understanding who the threat actors are, what motivates them, who they target, and how they attack, organizations can develop more effective defense strategies.
What do you think? Given the industrialization of cybercrime and the growing sophistication of threat actors, how should smart cities balance the benefits of connectivity with the need for security? What role should public-private partnerships play in defending critical infrastructure?
References
- https://www.weforum.org/stories/2024/04/cybercrime-target-sectors-cybersecurity-news/
- https://www.crowdstrike.com/cybersecurity-101/threat-actor/
- https://www.cisa.gov/news-events/news/target-rich-cyber-poor-strengthening-our-nations-critical-infrastructure-sectors
- https://cybermagazine.com/articles/how-threat-actors-industrialised-cybercrime-in-2024
- https://www.anapaya.net/blog/top-5-critical-infrastructure-cyberattacks
- https://www.dhs.gov/archive/secure-cyberspace-and-critical-infrastructure
- https://www.sophos.com/en-us/cybersecurity-explained/threat-actors
- https://www.redlegg.com/blog/cyber-threat-actor-types
- https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors
- https://www.recordedfuture.com/threat-intelligence-101/threat-actors/threat-actor-types
- https://aimultiple.com/most-common-cyber-attack-vectors
- https://industrialcyber.co/analysis/targeting-critical-infrastructure-recent-incidents-analyzed/
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a
- https://www.cobalt.io/blog/defending-against-23-common-attack-vectors
- https://www.crowdstrike.com/en-us/cybersecurity-101/threat-intelligence/attack-vector/
- https://www.fortinet.com/resources/cyberglossary/attack-vector
- https://usa.kaspersky.com/resource-center/threats/botnet-attacks
- https://www.vectra.ai/topics/cyberattack-techniques
- https://www.upguard.com/blog/attack-vector
Leave a Reply