Threat actors and their motivations, sorted by what they can afford
This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.
Listen to this lesson
Every episode of this course is also a podcast: listen on Spotify.
This episode is a study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.
Objective 2.2 asks you to describe who attacks organisations and why. The exam's actor list is longer than it used to be — terrorists, competitors and the accidental insider all appear by name — and so is its list of motives. This lesson covers both, plus the three attributes that actually separate one actor from another.
Why this matters
Domain 2 is 24% of SY0-801, and this objective is where its scenarios begin. The questions are almost always the same shape: a description of an attack, and a request to name the actor or the motive behind it. That is answerable, reliably, if you stop thinking about actors as personalities and start thinking about them as budgets.
It is practical rather than trivia: who you are up against changes what you defend and how much you spend.
The lesson
From state-sponsored groups and crime syndicates to competitors and the unskilled attacker
The actors, with the feature that distinguishes each:
- State-sponsored. Directed or funded by a government — the exam's current term for what older material called a nation-state actor. The defining features are time and funding: they can spend years on one target and develop their own tools, including exploits nobody else has. The goal is usually intelligence, influence or strategic advantage rather than money.
- Crime syndicate (organised crime). Professional, structured, and in it for money. They run like businesses — specialised roles, affiliates, even support desks for ransomware victims. Well resourced but cost-sensitive: if you are more expensive than the next target, they move on.
- Terrorist. Seeks to cause fear or harm in support of a political or ideological cause. In security terms the concern is attacks aimed at disruption and visible damage — especially against services people depend on — rather than quiet theft.
- Hacktivist. Motivated by a cause, with skill that varies enormously. Publicity is part of the objective: defacements, leaks timed to a news cycle, denial of service against a symbolic target. A hacktivist nobody notices has failed at their own goal.
- Insider. Someone with legitimate access — malicious or accidental. Covered in its own section below, because position changes everything.
- Competitor. Another organisation seeking commercial advantage: product plans, pricing, bids, customer lists, research. Often works through people — a recruited employee, a departing one — rather than through malware.
- Unskilled attacker. Uses tools others wrote, without deep understanding. Low resources, low sophistication, and high volume — which is why they still matter: they find the unpatched, the default-configured and the exposed.
Resources, funding and sophistication, and the persistent threat that has all three
Three attributes separate the actors, and scenario questions hinge on them:
- Internal or external — do they start with legitimate access?
- Resources and funding — can they buy or develop exploits, hire people and sustain an operation for a year?
- Sophistication and capability — off-the-shelf tools, or their own?
Put the actors on those axes and the scenarios sort themselves:
| Actor | Resources | Sophistication | Tell in a scenario |
|---|---|---|---|
| State-sponsored | Very high | Very high | Custom malware, zero-day, months undetected, intelligence target |
| Crime syndicate | High | High | Ransomware, extortion, payment fraud, clear money motive |
| Terrorist | Varies | Varies | Disruption aimed at public fear, critical services |
| Hacktivist | Low–medium | Varies | Public statement, defacement, leak, symbolic target |
| Competitor | Medium | Varies | Stolen designs, bids or customer data; often via people |
| Insider | Low | Varies | Valid credentials, unusual access, no intrusion at all |
| Unskilled | Very low | Low | Known tool, known CVE, noisy, opportunistic |
The most reliable single discriminator is use of a previously unknown vulnerability. Zero-days are expensive. An actor spending one is telling you they are well funded.
An advanced persistent threat (APT) is the actor that sits at the top of all three axes, and SY0-801 also lists it as a threat vector in its own right. Take the words literally. Advanced: capable of custom tooling, though happy to use a phishing email if it works. Persistent: the load-bearing word — they establish access, keep it quietly, and come back if evicted. Threat: an organisation with intent, not a piece of malware. The consequence to carry is that response against an APT cannot be "remove the malware and move on", because they will have more than one foothold. That is why incident response insists on scoping before eradication.
The insider, malicious or accidental, and why they start past most of your controls
An external attacker has to solve a problem the insider does not have: getting in. Every perimeter control and every authentication check is aimed at that problem. The insider begins on the other side of all of it, with credentials that are supposed to work, on a device that is supposed to be there, doing things that resemble their job.
Insiders come in two kinds, and the exam now names both:
- The malicious insider acts deliberately — stealing data before leaving for a competitor, sabotaging systems after a grievance, selling access.
- The accidental or unintentional insider causes harm without meaning to: emailing a spreadsheet to the wrong person, falling for a phishing email, sharing a file publicly, misconfiguring a storage bucket. By volume, this is the larger problem.
The consequences the exam tests:
- Preventive perimeter controls are largely irrelevant. You cannot prevent someone using access you gave them.
- Detection has to be behavioural. The signal is access that is authorised but unusual — volume, timing, breadth.
- The structural controls work: least privilege, separation of duties, mandatory vacations or job rotation, dual authorisation for high-value actions, and prompt offboarding — access removed when someone is told they are leaving, not at the end of their notice.
- For the accidental insider, add training, DLP that warns before a mistake leaves the building, and safe defaults that make the careless action harder than the correct one.
Motives from money and espionage to ideology, notoriety, extortion and plain curiosity
Motive is not colour; it changes the incident. The ones to recognise:
- Financial — theft, fraud, ransomware, cryptomining, business email compromise. The most common motive by a wide margin.
- Extortion — demanding payment under threat: encrypting data, or the now usual variant, threatening to publish data already stolen. Backups answer only half of that.
- Espionage — obtaining information quietly over a long time. Detection is the whole problem, because nothing visibly breaks.
- Intellectual property — designs, source code, formulas, research. The competitor's and the state's motive alike.
- Influence — shaping opinion or decisions: leaks timed to an election or a negotiation, planted stories, manipulated discussion.
- Political and ideological — the hacktivist's and the terrorist's motive. Targets are chosen for what they symbolise, so your risk rises when your organisation is in the news.
- Fear and chaos — damage for its own sake. It breaks the assumption that attackers are rational actors you can price out; recovery capability is the real answer.
- Revenge — usually a current or former insider, clustered around a grievance such as a dismissal or a passed-over promotion.
- Notoriety — wanting to be known for it. Typical of unskilled attackers and some hacktivists; the attack is often announced.
- General curiosity — probing to see what is possible, without a plan for what comes next. Often unskilled, sometimes still damaging.
- Ethical — the researcher who finds a flaw and reports it. "Was this malicious?" is a real triage question, and an organisation with no disclosure route turns a free private report into a public one.
Why it matters for response: two intrusions can begin identically, with a phishing email and a stolen credential. If the motive is financial, the attacker will cash out fast, so you contain immediately — revoke, reset, block the payment path. If the motive is espionage, the attacker intends to stay, and evicting one foothold loudly tells them to use the second one you have not found. There, you scope the full compromise first and remediate everything at once.
Matching an actor and a motive to a scenario, which is the shape the exam question takes
A short procedure answers most of these:
- What was the goal? Money points to a crime syndicate. Information points to a state or a competitor. A public point points to a hacktivist; public fear or disruption of a critical service, to a terrorist.
- How long were they there? Months undetected raises state-sponsored sharply.
- What did they use? A known CVE with a public exploit points down the scale; a zero-day or bespoke implant points up it.
- Did they announce themselves? Announcement suggests a hacktivist, an extortion demand or notoriety. Silence suggests espionage.
- Did they have to break in at all? If not, an insider — or an attacker holding stolen valid credentials. If nobody meant any harm, it is the accidental insider.
Two traps. A competitor and a state can both want intellectual property; the tell is resources and duration. And a terrorist and a hacktivist can both be ideological; the tell is whether the aim is to make a point or to cause fear and harm.
What to take into the exam
- Sort actors by resources and sophistication, not by how frightening they sound. Zero-day use is the strongest single sign of a well-funded actor.
- State-sponsored is the current term; APT is the persistent, well-resourced actor, and "persistent" is the word that makes eradication hard.
- Insiders may be malicious or accidental; both start past the perimeter, so the answers are behavioural detection and structural controls.
- Financial is the commonest motive; espionage is the one that changes the response from "contain now" to "scope first".
- Hacktivists and notoriety-seekers announce themselves; spies do not.
Practise what you just read
1. An intrusion used a previously unknown vulnerability and went undetected for eight months while quietly collecting data. Which actor does this most strongly indicate?
Select one
Show answer
D. Zero-days are expensive, and eight months of quiet presence shows both capability and patience. That combination points to a well-funded actor pursuing intelligence rather than money. A crime syndicate can afford a zero-day, but it cashes out quickly rather than sitting silently for months.
2. Which attributes most usefully separate one threat actor from another in an exam scenario?
Select one
Show answer
A. Sorting actors by how frightening they sound produces guesses. Sorting by what they can afford, how capable they are and whether they start inside produces answers, because the scenario usually tells you what was used and how long it lasted, and both are functions of resources.
3. What does the word 'persistent' contribute to the term advanced persistent threat?
Select one
Show answer
B. Persistent is the load-bearing word. An APT establishes access, keeps it quietly for months or years and comes back if evicted, usually through a second foothold. That is why response against one cannot be 'remove the malware and move on', and why scoping comes before eradication.
Hands-on labs
Part of the free CompTIA Security+ SY0-801 course — 47 lessons and 78 hands-on labs.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.