Skip to contentExploitQuest

Lesson 1 of 1 in Who Is Actually Attacking You

Not One Enemy

The word "hacker" hides a spectrum that runs from a bored script against a million random addresses to a government team with a budget and a year. Your defences only make sense once you know which end of that spectrum is realistic for you.

4 min read

Not yet reviewed

Wrenlearner

I keep seeing "you will be hacked". But who would even bother with me? I am not a bank.

Magpieadversary

Most of us never chose you. A machine found you — an address that answered, a login that took a common password. You were not a target. You were a match.

Rookmentor

Which is the first useful thing to learn. "Who is attacking you" has very different answers, and each answer wants a different defence.

A spectrum, not a type

Picture the range as a line. At one end is the fully automated and impersonal: scanners that knock on every door on the internet, malware that spreads to whatever it can reach, credential-stuffing bots trying leaked passwords against every site. Cheap, tireless, and aimed at no one in particular. At the other end is the deliberate and expensive: a skilled team that picked *you*, will spend months, and will not trip the alarms the cheap end trips. Almost everyone lives much closer to the automated end than they fear.

Opportunistic

Picks a weakness, then finds who has it.
You were a match, not a target.

Targeted

Picks a victim, then finds their weakness.
You were chosen, and they will adapt.

The single most useful question about any attacker: did they pick the hole first, or the victim first? It decides whether being unremarkable is a defence — against the opportunistic it is a very good one, and against the targeted it is worth nothing.

The cast of who

Opportunistic scanners   automated, impersonal, relentless
Ransomware crews          professional, financial, patient enough to be paid
Fraudsters & scammers     after your money or your account directly
Insiders                  already inside; access is not their problem
Hacktivists               after attention, for a cause
Competitors               after what you know
Nation-states             after influence or secrets, with real budgets
  1. Line 1The overwhelming majority of what hits an ordinary person or small business. Boring, and stopped by boring things — a unique password, an update, a second factor.
  2. Line 2A business, not a genius. They buy access from the opportunistic end, then run a playbook. Most of this course is their playbook.
  3. Line 7Real, rare, and almost certainly not your problem. Defending an ordinary life against a government is how people waste effort they needed elsewhere.

A friend insists on an elaborate, expensive setup because "the government could be watching". What is the question that either justifies it or deflates it?

Why this is the front door

Every later stage of this course — the reconnaissance, the way in, the spread — reads differently depending on who is doing it. A scanner's reconnaissance is a port scan; a targeted attacker's is reading your team's social media for a month. Naming your realistic attacker first is what turns the rest of the story from a list of scary words into a set of decisions you can actually make.

One thing you can do this week: decide, in a sentence, who your realistic attacker is. "Automated attacks and scams aimed at anyone" is the honest answer for most people, and it is a good one — because everything that stops that attacker is cheap, and the next chapters are about exactly those cheap things.