A cyber attack is any malicious attempt to gain unauthorized access to a computer, computing system or computer network with the intent to cause damage. Cyber attacks aim to disable, disrupt, destroy or control computer systems or to alter, block, delete, manipulate or steal the data held within these systems.
Any individual or group can launch a cyber attack from anywhere using one or more attack strategies.
Cybercriminals who carry out cyber attacks are often referred to as bad actors, threat actors and hackers. They include individuals who act alone, drawing on their computer skills to design and execute malicious attacks, as well as criminal syndicates. These groups work with other threat actors to find weaknesses or vulnerabilities in the computer systems that they can exploit for gain.
Government-sponsored groups of computer experts also launch cyber attacks. They're identified as nation-state attackers, and they've been accused of attacking the IT infrastructure of other governments, as well as nongovernment entities, such as businesses, nonprofits and utilities.
Cyber attacks are designed to cause damage. They can have various objectives, including the following:
Financial gain. Cybercriminals launch most cyber attacks, especially those against commercial entities, for financial gain. These attacks often aim to steal sensitive data, such as customer credit card numbers or employee personal information, which the cybercriminals then use to access money or goods using the victims' identities.
Other financially motivated attacks are designed to disable computer systems, with cybercriminals locking computers so owners and authorized users can't access the applications or data they need; attackers then demand that the targeted organizations pay them a ransom to unlock the computer systems.
Still, other attacks aim to gain valuable corporate data, such as proprietary information; these types of cyber attacks are a modern, computerized form of corporate espionage.
Disruption and revenge. Bad actors also launch attacks specifically to sow chaos, confusion, discontent, frustration or mistrust. They could be taking such actions to get revenge for acts taken against them. They could be aiming to publicly embarrass the attacked entities or to damage an organization's reputation. These attacks are often directed at government entities but can also hit commercial or nonprofit organizations.
Nation-state attackers are behind some of these types of attacks. Others, called hacktivists, might launch these types of attacks as a form of protest against the targeted entity; a secretive decentralized group of internationalist activists known as Anonymous is the most well-known of these groups.
Insider threats are attacks that come from employees with malicious intent.
Cyberwarfare. Governments around the world are also involved in cyber attacks, with many national governments acknowledging or being suspected of designing and executing attacks against other countries as part of ongoing political, economic or social disputes. These types of attacks are classified as cyberwarfare.
Threat actors use various techniques to launch cyber attacks, depending in large part on whether they're attacking a targeted or an untargeted entity.
In an untargeted attack, where the bad actors are trying to break into as many devices or systems as possible, they generally look for vulnerabilities in software code that enable them to gain access without being detected or blocked. Or, they might employ a phishing attack, emailing large numbers of people with socially engineered messages crafted to entice recipients to click a link that downloads malicious code.
In a targeted attack, the threat actors are going after a specific organization and the methods used vary depending on the attack's objectives. The hacktivist group Anonymous, for example, was suspected in a 2020 distributed denial-of-service attack (DDoS) on the Minneapolis Police Department website after a man died while being arrested by Minneapolis officers. Hackers also use spear-phishing campaigns in a targeted attack, crafting emails to specific individuals who, if they click included links, would download malicious software designed to subvert the organization's technology or the sensitive data it holds.
Cybercriminals often create the software tools to use in their attacks, and they frequently share those on the dark web.
Cyber attacks often happen in stages, starting with hackers surveying or scanning for vulnerabilities or access points, initiating the initial compromise and then executing the full attack -- whether it's stealing valuable data, disabling the computer systems or both.
In fact, most organizations take months to identify an attack underway and then contain it. According to the "Cost of a Data Breach Report 2023" from IBM, the breach lifecycle -- or the time it takes organizations to identify and contain breaches -- averaged 204 days in 2023, down from 207 days in 2022. However, organizations required an average of 73 days to contain breaches in 2023, which is up from their average of 70 days in 2022.
Cyber attacks most commonly involve the following:
There's no guaranteed way for any organization to prevent a cyber attack, but there are several cybersecurity best practices they can follow to reduce the risk. Reducing the risk of a cyber attack relies on using a combination of skilled security professionals, processes and technology.
Reducing risk also involves the following three broad categories of defensive action:
Best practices include the following:
Cyber attacks continue to increase in sophistication and have had significant impacts beyond just the companies involved.
For example, JBS S.A., a Brazil-based meat processing company, suffered a successful ransomware attack on May 30, 2021. The attack shut down facilities in the U.S. as well as Australia and Canada, forcing the company to pay an $11 million ransom.
This came just weeks after hackers hit Colonial Pipeline in May 2021 with a ransomware attack. The attack shut down the largest fuel pipeline in the U.S., leading to fuel shortages along the East Coast.
Several months before that, the massive SolarWinds attack breached U.S. federal agencies, infrastructure and private corporations in what is believed to be among the worst cyberespionage attacks inflicted on the U.S. On Dec. 13, 2020, Austin-based IT management software company SolarWinds was hit by a supply chain attack that compromised updates for its Orion software platform. As part of this attack, threat actors inserted their own malware, now known as Sunburst or Solorigate, into the updates, which were distributed to many SolarWinds customers.
The first confirmed victim of this backdoor was cybersecurity firm FireEye, which disclosed on Dec. 8 that it was breached by suspected nation-state hackers. It was soon revealed that SolarWinds attacks affected other organizations, including tech giants Microsoft and VMware, as well as many U.S. government agencies. Investigations showed that the hackers -- believed to be sponsored by the Russian government -- had been infiltrating targeted systems undetected since March 2020.
Other notorious breaches include the following:
The volume, cost and impact of cyber threats continue to grow each year, according to multiple reports. Consider the figures from one 2022 report. The "Cybersecurity Solutions for a Riskier World" report from ThoughtLab noted that the number of material breaches suffered by surveyed organizations jumped 20.5% from 2020 to 2021. Yet, despite executives and board members paying more attention -- and spending more on cybersecurity than ever before, 29% of chief executive officers (CEOs) and chief information security officers and 40% of chief security officers said their organization is unprepared for the ever-evolving threat landscape.
The report further notes that security experts expect the volume of attacks to continue their climb.
The types of cyber attacks, as well as their sophistication, also grew during the first two decades of the 21st century -- particularly during the COVID pandemic when, starting in early 2020, organizations enabled remote work en masse and exposed a host of potential attack vectors in the process.
The first computer virus was invented in 1986, although it wasn't intended to corrupt data in the infected systems. Cornell University graduate student Robert Tappan Morris created in 1988 the first worm distributed through the internet, called the Morris worm.
Then came Trojan horse, ransomware and DDoS attacks, which became more destructive and notorious with names such as WannaCry, Petya and NotPetya -- all ransomware attack vectors.
The 2010s then saw the emergence of cryptomining malware -- also called cryptocurrency mining malware or cryptojacking -- where hackers use malware to illegally take over a computer's processing power to use it to solve complex mathematical problems to earn cryptocurrency, a process called mining. Cryptomining malware dramatically slows down computers and disrupts their normal operations.
With the increased popularity of machine learning and AI, hackers have been adopting more sophisticated technologies, as well as bots and other robotic tools, to increase the velocity and volume of their attacks.
They also developed more sophisticated phishing and spear-phishing campaigns, even as they continued to go after unpatched vulnerabilities; compromised credentials, including passwords; and misconfigurations to gain unauthorized access to computer systems.
As cyber attacks grow in frequency and sophistication, several trends have started to appear. For example, three currently appearing trends in cyber attacks include the following:
With these evolving threats, it's important to stay on top of these potential cyber threats. Learn more about cybersecurity trends and statistics to keep an eye on.
12 Dec 2023