TechKnowSurge
VideoSecurityFree

An Adversary’s Motivations

Understanding attacker motivation reveals their likely targets, methods, and level of effort — making it a foundational concept in threat analysis and defense strategy. From curiosity and revenge to financial gain and hacktivism, different motivations produce fundamentally different attack profiles.

Complete this video to capture a CTF flag worth 1 point.

About this video

Understanding why an attacker acts is just as important as understanding how they act. Motivation shapes every dimension of a threat — the target chosen, the methods employed, and the time and resources an adversary is willing to invest. Without this context, defensive strategies lack the focus needed to address the most realistic and relevant risks an organization faces. Attacker motivations fall into several broad but meaningful categories. Some are emotionally driven — curiosity, the desire for challenge, a need for notoriety or recognition, a sense of power gained through disruption, or revenge against an employer or organization. These motivations share a common thread: the attacker is seeking an internal emotional payoff, whether that is pride, control, or retribution. A disgruntled former employee planting a logic bomb before departure is a classic example of vindictive motivation translating directly into a security incident. Financial motivation drives a significant portion of cybercrime, including extortion, ransomware, blackmail, and attacks aimed at gaining competitive advantage. Hacktivists represent a different profile entirely — adversaries acting on political, ideological, or social convictions, often targeting organizations they view as opponents of a cause. Their attacks may include data exposure, defacement, or service disruption carried out in the name of protest or geopolitical conflict. Ethical hackers and penetration testers operate with explicit authorization and professional purpose, working to expose vulnerabilities before malicious actors can exploit them. Finally, one of the most underestimated threat categories is the internal user who poses a risk not through hostile intent but through convenience — employees who circumvent security controls to accomplish legitimate business goals, a pattern commonly referred to as shadow IT. Mapping attacker motivation to the threat landscape allows security professionals to build more targeted, realistic defenses and prioritize the scenarios most likely to affect their environment.

What you'll learn

What's covered

Attacker Motivations

Key terms

Threat Actor
An individual or group responsible for a security incident or attack.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Insider Threat
A security risk that originates from individuals who have authorized access to an organization's systems — such as employees, contractors, or partners — and misuse that access either maliciously or through negligence.
Hacktivism
The use of hacking techniques to promote a political, social, or ideological agenda rather than for personal or financial gain.
Ransomware
A type of malware that encrypts a victim's files and demands payment in exchange for the decryption key.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.
Shadow IT
The use of unauthorized software, systems, or services within an organization without IT department knowledge or approval. Shadow IT creates security blind spots because unmanaged assets fall outside standard patching, monitoring, and access controls.

Topics

Threat Actor Motivations Threat Intelligence Insider Threats Hacktivism Cybersecurity

Transcript

To really get into the mind of an attacker and understand why and how they're going to attack our systems, we have to understand their motivations. What's motivating them to do this? By understanding the motivation of an attacker, we can much better understand how they're going to approach their attack.

One of the most critical parts to understanding our adversary is understanding their motivations. If they're an employee that's leaving the company and they're really angry at the company, they might not be as skilled. They might not have the same targets as somebody who is outside of the company and maybe is doing it just for financial gain. So really understanding the motivation gives us a key into everything else of what they're going to be doing and how they're going to be doing it.

Understanding the motivation of an adversary tells us what that target is going to be, the processes that they're going to use, and how much energy, time and resources they're going to put behind this to target you as an individual, to target your organization as an entity.

Examples of motivations

  • They might just want the challenge or the curiosity.
  • They might want notoriety.
  • They might want some sort of power.
  • They might be getting some sort of revenge or vindictiveness.
  • Maybe they have some sort of financial motivation.
  • Maybe they are trying to enact some sort of change.
  • Maybe they're doing some sort of testing and research and development. This would be more like a white hat hacker.
  • Or maybe they're just trying to get work done.

Challenge and curiosity

Back in high school, I took some computer classes, and the computer instructor put some barriers in place so we could only use the computers in certain ways. I took that as a bit of a challenge of how can I get past these measures that they're putting in place. I didn't want to cause any kind of harm — I maybe caused a little bit of frustration with them, but that wasn't my intent. It was more of just the challenge, more of the curiosity. There's some pride in knowing that I could get around the security systems. There is a little bit of thrill in that. And so it really just had to do with the challenge of it all.

So there are a lot of motivations behind just trying to get around the security systems in place, to see it from more of a curiosity standpoint and more of that challenge standpoint.

Notoriety and power

There are certain people for whom this becomes a little more of an ego thing. Not just can they get around it, but it's something that they get a lot of notoriety about. They get maybe some sort of fame and they can tell other people about it. Maybe there's some sort of recognition that they want. And so if they hack some sort of big customer, then they can put that on their resume or put that out there as being, hey, I did that.

Maybe their motivation is some sort of power game: by causing some sort of disruption or chaos, they get the sense of control. Maybe they're out of control in their personal life, and this is one way that they feel like they can gain control. So this is an emotional thing. I think of the bully back in maybe middle school or high school or elementary school or whatever. You see some of the bullies that would go around and push other kids around. Well, that is what some of the motivation is behind these adversaries.

Revenge and vindictiveness

Sometimes as humans we feel slighted against an organization or against another person, and we want to get even. We want to get revenge. We want to get some sort of retribution for this. We experience some pain, and so we want them to experience pain. So an example might be when a company fires an employee and they have this sense that they want to get even, so they launch something like a bomb that just goes off when they leave the company. So there's this vindictiveness attitude.

So the top part here — challenge, curiosity, notoriety, power, revenge, vindictiveness — the main motivator behind this, the common theme behind all of this, is the emotion: they're doing some sort of action just to get that emotional reaction within themselves.

Financial gain

One could argue that's the same thing for financial gain, but the primary focus that we really think of from a motivation standpoint is the money, going after some sort of money. This is where cyber crime comes into play. This is where maybe there's some sort of blackmail or extortion that's happening to get money out of the person. Maybe it's to get some sort of competitive advantage. So they're carrying out some sort of action in order for a financial gain.

Activism and something greater

But maybe an adversary is not doing it for themselves. Maybe they're doing it for something greater than them, for some sort of political change or philosophical change. We call this a hacktivist. A hacktivist is doing this for some sort of activism, to change something. Maybe it's because of political beliefs. Maybe they're doing it out of protest. Maybe it's part of cyber warfare. Maybe it's geopolitical. Maybe it's part of cyber terrorism. And so they're doing it to enact some sort of change, something that is altruistic, that they're doing it for the greater good, at least in their own mind.

Ethical hacking

Then there is ethical hacking. Maybe it's not for some sort of emotional gain or for some sort of financial gain, and maybe it's not because there's something altruistic or something that you're trying to fight for, some sort of activism — maybe it's just part of your job. Your job is to pentest, or research and development, or test out the network to make sure that it is secure. So you're going to go through the hacking process to be able to test this network and see how well it's designed and how well its security is set up for this network.

Just getting stuff done

More often than not, the thing that causes the most security risk to a company, I've found, is just the internal threat. It's something we call shadow IT, and really the motivation is just to get stuff done. That is, there are employees that have a goal, they have an objective. It's for the company, it's a business need. They're working towards making the business better, but in doing so they've done something to compromise the network. And so more often than not, this is an internal threat that happens that puts the company at risk.

Now, these are all broad categories, but what it does do is give you insight into what the motivation of the adversary is.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →