Lesson 1 of 1 in Who Is Actually Attacking You
Not One Enemy
The word "hacker" hides a spectrum that runs from a bored script against a million random addresses to a government team with a budget and a year. Your defences only make sense once you know which end of that spectrum is realistic for you.
4 min read
Not yet reviewed
I keep seeing "you will be hacked". But who would even bother with me? I am not a bank.
Most of us never chose you. A machine found you — an address that answered, a login that took a common password. You were not a target. You were a match.
Which is the first useful thing to learn. "Who is attacking you" has very different answers, and each answer wants a different defence.
Legal
This course teaches how attackers think so that you can defend against them. Studying their methods is legal and necessary. Using them against any system you do not own or do not have written permission to test is a serious criminal offence — and understanding the mind of an attacker is precisely what should make that line obvious rather than tempting.
A spectrum, not a type
Picture the range as a line. At one end is the fully automated and impersonal: scanners that knock on every door on the internet, malware that spreads to whatever it can reach, credential-stuffing bots trying leaked passwords against every site. Cheap, tireless, and aimed at no one in particular. At the other end is the deliberate and expensive: a skilled team that picked *you*, will spend months, and will not trip the alarms the cheap end trips. Almost everyone lives much closer to the automated end than they fear.
Opportunistic
Picks a weakness, then finds who has it.
You were a match, not a target.Targeted
Picks a victim, then finds their weakness.
You were chosen, and they will adapt.The single most useful question about any attacker: did they pick the hole first, or the victim first? It decides whether being unremarkable is a defence — against the opportunistic it is a very good one, and against the targeted it is worth nothing.
The cast of who
Opportunistic scanners automated, impersonal, relentless
Ransomware crews professional, financial, patient enough to be paid
Fraudsters & scammers after your money or your account directly
Insiders already inside; access is not their problem
Hacktivists after attention, for a cause
Competitors after what you know
Nation-states after influence or secrets, with real budgets
- Line 1The overwhelming majority of what hits an ordinary person or small business. Boring, and stopped by boring things — a unique password, an update, a second factor.
- Line 2A business, not a genius. They buy access from the opportunistic end, then run a playbook. Most of this course is their playbook.
- Line 7Real, rare, and almost certainly not your problem. Defending an ordinary life against a government is how people waste effort they needed elsewhere.
A friend insists on an elaborate, expensive setup because "the government could be watching". What is the question that either justifies it or deflates it?
Why this is the front door
Every later stage of this course — the reconnaissance, the way in, the spread — reads differently depending on who is doing it. A scanner's reconnaissance is a port scan; a targeted attacker's is reading your team's social media for a month. Naming your realistic attacker first is what turns the rest of the story from a list of scary words into a set of decisions you can actually make.
One thing you can do this week: decide, in a sentence, who your realistic attacker is. "Automated attacks and scams aimed at anyone" is the honest answer for most people, and it is a good one — because everything that stops that attacker is cheap, and the next chapters are about exactly those cheap things.