Skip to main content
Home > What Causes Cyber Attacks? The Groups Responsible and How They Operate

What Causes Cyber Attacks? The Groups Responsible and How They Operate

Understanding the threat landscape: from script kiddies to state-sponsored actors

▶ WATCH THE VIDEO

This blog post is a companion to our video “Challenges and Trends,” where Intercede’s security experts sit down to unpack the evolving threat landscape, who is behind today’s cyber attacks, what motivates them, and how their methods are changing. Watch the video for the full conversation.

Not All Attackers Are the Same

When we hear about a cyber attack in the news, it is tempting to imagine a lone hacker in a dark room. The reality, as we explore in our accompanying video, is far more complex. Today’s cyber threat landscape involves a range of actors with vastly different motivations, resources, and methods. Understanding who these groups are is the first step towards building effective defences.

Organised Cybercriminal Groups

Just over a quarter of organisations rate organised cybercriminal groups as the threat actor posing the greatest risk. These groups operate like businesses, with hierarchies, specialised roles, and even customer service for their ransomware victims. In the first half of 2025 alone, ransomware attacks surged 60% compared to the previous period, with groups like Akira responsible for 72 attacks in a single month. Cybercrime-as-a-service has become increasingly popular, lowering the barrier to entry for aspiring attackers.

State-Sponsored Actors

Nation-state actors represent the most sophisticated tier of the threat landscape. In 2024, threat intelligence teams detected 828 APT (Advanced Persistent Threat) cyberattacks, a 58% rise from 2023, driven largely by geopolitical conflicts. These actors target government (15.5%), manufacturing (4.8%), finance (3.8%), and IT (3.5%) sectors for strategic, economic, and technological advantages. They are well-funded, patient, and often willing to play the long game. In our video, we discuss why these state-sponsored campaigns are increasingly difficult to distinguish from financially motivated cybercrime.

Hacktivists

Hacktivism has surged alongside global political tensions. In 2025 alone, at least 45 new hacktivist groups became active, often aligned with geopolitical causes. The lines between hacktivism, cybercrime, and state-sponsored activity are increasingly blurred, with some groups receiving covert support from nation-states while maintaining a veneer of independence.
The Emerging Threat: AI-Enabled Attackers

Across all these categories, threat actors are rapidly integrating AI into their operations. From automated vulnerability scanning to AI-generated phishing campaigns, the tools available to attackers are becoming more powerful and more accessible. Throughout 2025, security researchers tracked 1,100 emerging threat actors across all vectors, a 23% increase on 2024. Our video discussion dives into how these AI-enabled attackers are changing the calculus for defenders.

Defending Against a Diverse Threat Landscape

With such a range of adversaries, there is no single silver bullet. Effective defence requires a layered approach: strong identity and access management, continuous monitoring, breach detection, and, critically, authentication that goes beyond passwords. Solutions like Intercede’s MyID suite help organisations implement phishing-resistant MFA, certificate-based authentication, and continuous password breach monitoring, providing protection against the full spectrum of threat actors.

▶ WATCH THE FULL DISCUSSION

To hear our experts discuss these threat actors in depth, including real-world examples and how the lines between groups are blurring, watch our video: “Challenges and Trends.”