What are the most common ways cybercriminals target everyday users?
According to the report, cybercriminals primarily target everyday users through Social Engineering tactics, with Phishing and Pretexting representing the most prominent threats . Attackers frequently use deceptive emails and malicious websites to manipulate human behavior, altering the target’s actions to compromise confidential information .
The primary objective of these campaigns is often to steal Credentials, which the report describes as the “glazed donut of data types” because they are so highly coveted by attackers . Once acquired, these stolen credentials are put to use in hacking attacks to gain unauthorized access to cloud-based email systems, mail servers, and corporate web applications .
Another widespread social engineering threat is the Business Email Compromise (BEC) . In these attacks, cybercriminals rely heavily on Pretexting—crafting elaborate, invented scenarios—to dupe employees into initiating fraudulent financial transactions or wire transfers .
Finally, users are also targeted through email-delivered Malware (such as Trojans or backdoors) , while simple, non-malicious human mistakes—like Misdelivery (sending sensitive data to the wrong recipient) or Misconfigurations—frequently expose sensitive personal or credential information without any direct attacker interaction .
What do hackers actually want when they attack an organization?
At its core, the overwhelming majority of threat actors are driven by a single, straightforward desire: financial gain . Financially motivated attacks continue to be the most common motive behind data breaches, and organized crime remains the leading type of threat actor .
To achieve this financial goal, cybercriminals target specific types of valuable assets and data:
Credentials: Credentials are the most highly sought-after data variety in breaches . Attackers covet credentials because they grant easy access to an organization’s network, cloud mail servers, and web applications . Once acquired, credentials are used to pivot internally and escalate the attacker’s presence in the victim’s systems .
Personal and Bank Data: Personal data (including Social Security numbers, addresses, names, and insurance details) is the second most targeted data type . Attackers favor this information because of its high resale value on criminal forums and its utility in committing downstream financial fraud .
Operational Control and Leverage (Ransomware): Rather than purely targeting payment card data, attackers increasingly focus on stealing any sensitive organizational data that will impact the victim’s operations . Under the growing “name and shame” tactic, attackers exfiltrate copies of this sensitive data before encrypting the systems, threatening to publish it on the internet to force organizations into paying a ransom .
Repurposing Infrastructure (Secondary Motives): In other instances, attackers are driven by a secondary motive, where their ultimate goal is to leverage the victim’s access, infrastructure, or web applications . They target these systems to distribute malware, host defaced pages, or establish command-and-control access for future campaigns .
While other motives like espionage, personal grudges, ideology, or convenience occasionally appear, they are vastly outnumbered by the pursuit of financial profit .
Does falling victim to a cyberattack always mean losing money?
No, falling victim to a cyberattack does not always mean losing money. According to data from the FBI’s Internet Crime Complaint Center (IC3), a large percentage of security incidents do not actually result in any direct financial loss . Specifically, 42% of Business Email Compromise (BEC) incidents, 76% of Computer Data Breaches (CDB), and 90% of ransomware attacks resulted in zero financial loss .
Furthermore, when the report’s authors simulated overall breach costs using 1,000 Monte Carlo simulations, 14% of the simulated breaches had no financial or operational impact at all . Even when looking at associated post-breach expenses like forensic investigations and legal guidance, many organizations escape without incurring these bills: 50% of analyzed incidents had no digital forensics costs, and 36% had no associated legal costs . However, when losses do occur, they are not of a “one-size-fits-all” variety, and the actual financial impact depends heavily on factors such as organizational size, the nature of the attack, and whether victims can quickly partner with law enforcement to freeze stolen funds .
Why is the human element still the weakest link in digital security?
The human element is involved in 85% of confirmed security breaches , making it a primary focus for attackers and defenders alike.
According to the report, this vulnerability persists because of several key factors:
Deceptive Scams and Manipulative Stories: Attackers extensively leverage Social Engineering actions like Phishing and Pretexting, which psychologically compromise individuals and alter their behavior to hand over sensitive access . Rather than targeting system vulnerabilities, adversaries frequently trick employees into yielding highly coveted credentials or initiating fraudulent wire transfers .
Constant Presence of Errors: Unintentional human actions remain a persistent security “frenemy” . Employees make mistakes—often at scale—such as misconfiguring databases, making publishing errors, or sending emails and physical documents to the wrong recipients .
Traditional Security Education Limits: Traditional security awareness training often fails because it does not mimic real-life situations or match the behaviors that actually lead to breaches . Effective security requires moving toward behavioral science and shaping a culture that addresses the organizational values, attitudes, and beliefs driving individual habits .
Delayed Detection and Awareness: A major challenge with human-targeted attacks is that when employees fall for scams, they rarely realize they have been hooked . The vast majority of these incidents are discovered by external entities, signaling that organizations lack the easy, well-publicized internal channels necessary for employees to act as an early warning system .
Ultimately, while technology can block many threats, managing modern “cognitive hazards” continues to depend on an organization’s ability to systematically adapt human behaviors .
Should security teams focus on daily normal threats or rare catastrophic exceptions?
According to the report, an ideally optimized security strategy is to engineer solutions for the norm and train your security operations teams to handle the exceptions .
The data analyzed in the report demonstrates that the threat landscape is highly unequal, characterized by a few common threat varieties up top (the “norm”) and a “long tail” of rare, extraordinary, and uncommon attacks (the “exceptions”) . Security teams do not need next-gen AI or predictive neural networks to identify the norm; they can easily identify it and plan accordingly . In contrast, attempting to build engineered solutions for every single possible exception in the long tail is not a wise or cost-effective use of an organization’s resources .
Instead, organizations should rely on the natural flexibility of human security teams to act as adaptive problem solvers for rare exceptions when they occasionally arise . Rather than panicking over rare, paradigm-shifting threat vectors, security teams should focus on “doing the basics”—such as robust patch management and access control—which will successfully defend against the vast majority of the problem space most likely to affect the organization .
How did exfiltrating data replace encryption as the ultimate ransomware tactic?
The transition from simple encryption to data exfiltration as the primary ransomware tactic was driven by a major obstacle for cybercriminals: organizations were increasingly refusing to pay ransoms, often because they possessed adequate data backup solutions to restore their systems . This trend is highlighted by the fact that 90% of analyzed ransomware incidents resulted in zero financial loss, meaning victims were successfully bypassing the threat of locked files .
To regain their leverage, threat actors shifted from simply locking systems to a “name and shame” strategy, which began in late 2019 with the Maze Group and has since become commonplace . Under this approach, attackers perform what the report calls a “breach double-dip” . Before triggering any encryption, they first exfiltrate (steal) a copy of the organization’s sensitive operational data .
If the victim refuses to pay for a decryption key, the attackers threaten to expose the stolen files publicly, often utilizing specialized infrastructure they have developed to host these corporate data dumps . Consequently, cybercriminals have shifted away from purely targeting payment card data toward broadly targeting any sensitive data that will severely impact an organization’s operations, using the threat of public disclosure to force organizations into paying . This tactical evolution explains why ransomware frequency more than doubled, appearing in 10% of all confirmed breaches .
Source institutions:Verizon
This content is for reading and understanding research reports. It does not constitute investment advice or trading signals.
Read in App
Read global research reports on mobile.
This content is for research reading and does not constitute investment advice.