Understanding attacker motivation reveals their likely targets, methods, and level of effort — making it a foundational concept in threat analysis and defense strategy. From curiosity and revenge to financial gain and hacktivism, different motivations produce fundamentally different attack profiles.
Attacker Motivations
To really get into the mind of an attacker and understand why and how they're going to attack our systems, we have to understand their motivations. What's motivating them to do this? By understanding the motivation of an attacker, we can much better understand how they're going to approach their attack.
One of the most critical parts to understanding our adversary is understanding their motivations. If they're an employee that's leaving the company and they're really angry at the company, they might not be as skilled. They might not have the same targets as somebody who is outside of the company and maybe is doing it just for financial gain. So really understanding the motivation gives us a key into everything else of what they're going to be doing and how they're going to be doing it.
Understanding the motivation of an adversary tells us what that target is going to be, the processes that they're going to use, and how much energy, time and resources they're going to put behind this to target you as an individual, to target your organization as an entity.
Back in high school, I took some computer classes, and the computer instructor put some barriers in place so we could only use the computers in certain ways. I took that as a bit of a challenge of how can I get past these measures that they're putting in place. I didn't want to cause any kind of harm — I maybe caused a little bit of frustration with them, but that wasn't my intent. It was more of just the challenge, more of the curiosity. There's some pride in knowing that I could get around the security systems. There is a little bit of thrill in that. And so it really just had to do with the challenge of it all.
So there are a lot of motivations behind just trying to get around the security systems in place, to see it from more of a curiosity standpoint and more of that challenge standpoint.
There are certain people for whom this becomes a little more of an ego thing. Not just can they get around it, but it's something that they get a lot of notoriety about. They get maybe some sort of fame and they can tell other people about it. Maybe there's some sort of recognition that they want. And so if they hack some sort of big customer, then they can put that on their resume or put that out there as being, hey, I did that.
Maybe their motivation is some sort of power game: by causing some sort of disruption or chaos, they get the sense of control. Maybe they're out of control in their personal life, and this is one way that they feel like they can gain control. So this is an emotional thing. I think of the bully back in maybe middle school or high school or elementary school or whatever. You see some of the bullies that would go around and push other kids around. Well, that is what some of the motivation is behind these adversaries.
Sometimes as humans we feel slighted against an organization or against another person, and we want to get even. We want to get revenge. We want to get some sort of retribution for this. We experience some pain, and so we want them to experience pain. So an example might be when a company fires an employee and they have this sense that they want to get even, so they launch something like a bomb that just goes off when they leave the company. So there's this vindictiveness attitude.
So the top part here — challenge, curiosity, notoriety, power, revenge, vindictiveness — the main motivator behind this, the common theme behind all of this, is the emotion: they're doing some sort of action just to get that emotional reaction within themselves.
One could argue that's the same thing for financial gain, but the primary focus that we really think of from a motivation standpoint is the money, going after some sort of money. This is where cyber crime comes into play. This is where maybe there's some sort of blackmail or extortion that's happening to get money out of the person. Maybe it's to get some sort of competitive advantage. So they're carrying out some sort of action in order for a financial gain.
But maybe an adversary is not doing it for themselves. Maybe they're doing it for something greater than them, for some sort of political change or philosophical change. We call this a hacktivist. A hacktivist is doing this for some sort of activism, to change something. Maybe it's because of political beliefs. Maybe they're doing it out of protest. Maybe it's part of cyber warfare. Maybe it's geopolitical. Maybe it's part of cyber terrorism. And so they're doing it to enact some sort of change, something that is altruistic, that they're doing it for the greater good, at least in their own mind.
Then there is ethical hacking. Maybe it's not for some sort of emotional gain or for some sort of financial gain, and maybe it's not because there's something altruistic or something that you're trying to fight for, some sort of activism — maybe it's just part of your job. Your job is to pentest, or research and development, or test out the network to make sure that it is secure. So you're going to go through the hacking process to be able to test this network and see how well it's designed and how well its security is set up for this network.
More often than not, the thing that causes the most security risk to a company, I've found, is just the internal threat. It's something we call shadow IT, and really the motivation is just to get stuff done. That is, there are employees that have a goal, they have an objective. It's for the company, it's a business need. They're working towards making the business better, but in doing so they've done something to compromise the network. And so more often than not, this is an internal threat that happens that puts the company at risk.
Now, these are all broad categories, but what it does do is give you insight into what the motivation of the adversary is.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →