We still see plenty of conventional conflicts and wars, but there is much more happening behind the veil of the internet, hacking for causes, countries, religion and many more reasons.
It makes sense to cripple a country's or region's infrastructure if you want to invade or just destabilize that area.
This could be for war, trade, influence or many other reasons, everything is so interconnected we can shut down water, electricity or power from across the world.
The targets are not always the obvious targets, hospitals, air travel, shipping, production, ... are potential targets.
Common, we often see the attacks happening 9-5 in that time zone, this is a day job.
Approximate 120 countries have been developing ways to use the internet as a weapon to target financial markets, government computer systems and utilities.
Famous attacks: US elections (Russia), Sony websites (N. Korea), Stuxnet (US/Israel), US Office of Personnel Management (China) …
We are seeing more and more financially motivated attacks, they can be both highly skilled or not.
The lower skilled ones could be normal phishing attacks, social engineering or vishing, these are often a numbers game, but only a very small percentage needs to pay to make it worth the attack.
The ones requiring more skills could be stealing cardholder data, identity theft, fake anti-malware tools, or corporate espionage, ...
Ransomware is a subtype of financially motivated attacks, it will encrypt a system until a ransom is paid, if not paid the system is unusable, if paid the attacker may send instructions on how to recover the system.
Attackers just want the payday, they don’t really care from whom.