Technology

Types of Cybersecurity Attack Method

15rows
5columns
58views
0downloads
Source:Community curated
Updated:3/7/2026
15/15
Attack Method
Category
Typical Target
Primary Defense
Known For
Phishing
Social engineeringIndividuals via email or SMSSecurity awareness training, email filtering90% of breaches start with phishing, Nigerian prince emails evolved into sophisticated spear-phishing, cheapest attack to launch
Ransomware
MalwareOrganizations, hospitals, citiesOffline backups, endpoint detection, patch managementWannaCry (2017) hit 200K+ computers, Colonial Pipeline paid $4.4M, billion-dollar criminal industry
DDoS (Distributed Denial of Service)
Availability attackWebsites, online services, DNS providersCDN protection (Cloudflare), traffic scrubbing, rate limitingMirai botnet took down half the internet (2016), GitHub 1.35 Tbps attack, botnets-for-hire cost $20/hour
SQL Injection
Code injectionWeb applications with database backendsParameterized queries, input validation, WAFOWASP Top 10 for 20+ years, Heartland Payment breach (130M cards), Bobby Tables XKCD comic, still shockingly common
Zero-Day Exploit
Vulnerability exploitationAny software with unknown vulnerabilitiesDefense-in-depth, bug bounties, rapid patchingStuxnet used 4 zero-days to destroy Iranian centrifuges, zero-days sell for $500K-$2.5M on black market
Man-in-the-Middle (MITM)
InterceptionUnencrypted communications, public WiFi usersHTTPS/TLS, certificate pinning, VPNEvil twin WiFi hotspots, SSL stripping attacks, why 'free airport WiFi' is dangerous, banking session hijacking
Cross-Site Scripting (XSS)
Code injectionWeb application users via malicious scriptsContent Security Policy, output encoding, sanitizationSamy worm hit 1M MySpace profiles in 20 hours (2005), stored vs reflected vs DOM-based, cookie stealing
Credential Stuffing
Brute force / automationAny login portal using reused passwordsMFA, rate limiting, password managers, breach monitoringBillions of leaked credentials on dark web, automated login attempts at scale, why password reuse is deadly
Supply Chain Attack
Trust exploitationSoftware dependencies, update mechanismsSoftware bill of materials (SBOM), code signing, vendor auditsSolarWinds Orion hack (2020) compromised 18K organizations including US government, NotPetya via Ukrainian tax software
Brute Force Attack
Password crackingLogin systems, encrypted files, hashed passwordsAccount lockout, CAPTCHAs, long complex passwords, bcrypt hashingHashcat cracks billions of hashes per second on GPUs, dictionary attacks, rainbow tables, why 'password123' fails
DNS Spoofing / Cache Poisoning
RedirectionDNS resolvers, end users seeking legitimate sitesDNSSEC, DNS-over-HTTPS, trusted resolversKaminsky bug (2008) threatened entire internet DNS, redirects users to fake banking sites, hard to detect
Insider Threat
Internal / humanOrganization's own systems and dataLeast privilege, monitoring, DLP, background checksEdward Snowden, Tesla saboteur, costs companies $15.4M/year average, hardest threat to defend against
Cryptojacking
Resource theftWeb browsers, servers, cloud instancesAd blockers, endpoint monitoring, cloud cost alertsCoinhive script mined Monero in visitors' browsers, Tesla cloud account hijacked for mining, silent CPU drain
Buffer Overflow
Memory exploitationC/C++ programs without bounds checkingASLR, stack canaries, safe languages (Rust), code reviewMorris Worm (1988) used buffer overflow, Code Red, Blaster, foundation of most classic exploits, unsafe memory access
Social Engineering (Pretexting)
Human manipulationEmployees, help desks, executivesVerification procedures, security culture, callback protocolsKevin Mitnick's legendary hacking career, CEO fraud/BEC costs $26B, 'I'm from IT, I need your password', MGM hack (2023) via help desk call

Free to explore · No signup needed

Loading community rankings...