Cyber attacks do not all look the same. Some begin with a convincing email, some exploit a vulnerable application, and others abuse valid credentials without installing any malware. This complete guide explains 25 common attack types in plain language—along with warning signs, useful evidence and practical security controls.
A cyber attack is a deliberate attempt to gain unauthorised access, steal information, disrupt services, manipulate systems or damage digital assets. Effective defence requires more than memorising attack names. Security teams need to understand how an attacker enters, what evidence the activity creates, what business impact may follow and which control can interrupt the attack path.
MITRE ATT&CK describes adversary behaviour using objectives such as Initial Access, Credential Access, Lateral Movement, Exfiltration and Impact. This is useful because a real incident is usually a sequence of connected behaviours rather than one isolated action. If you are preparing for a SOC role, also read our MITRE ATT&CK Framework guide for beginners.
What Is a Cyber Attack?
A cyber attack is an intentional action against a computer, account, application, network, cloud service or data set. The attacker may want to steal credentials, commit fraud, spy on an organisation, interrupt operations, encrypt files, manipulate information or gain long-term access.
Confidentiality
Attackers access information that should remain private, such as passwords, customer records or intellectual property.
Integrity
Attackers alter data, transactions, configurations or software so that information and systems can no longer be trusted.
Availability
Attackers make systems, files or services unavailable through disruption, encryption, deletion or resource exhaustion.
Identity
Attackers misuse accounts, tokens or sessions to impersonate trusted users and bypass normal security controls.
Threat vs Vulnerability vs Exploit vs Cyber Attack
| Term | Simple meaning | Example |
|---|---|---|
| Threat | Anything capable of causing harm to a system, person or organisation. | A criminal group targeting financial companies. |
| Vulnerability | A weakness that could be abused. | An unpatched internet-facing application. |
| Exploit | A method or code that takes advantage of a vulnerability. | A crafted request that triggers unintended application behaviour. |
| Cyber attack | The intentional attempt to compromise, disrupt, misuse or damage a target. | An attacker exploits the application, steals credentials and accesses sensitive data. |
| Security incident | An event that actually or potentially threatens security and requires investigation or response. | The SOC confirms unauthorised access and begins containment. |
How a Cyber Attack Commonly Progresses
Attacks are not always linear, and attackers do not need to complete every phase. However, this simplified flow helps beginners understand how separate techniques can form one incident.
25 Types of Cyber Attacks at a Glance
| # | Attack type | Primary target or vector | Common impact | Useful defensive evidence |
|---|---|---|---|---|
| 1 | Phishing | Email and messaging | Credential theft or malware delivery | Email headers, URLs, message trace |
| 2 | Spear phishing and whaling | Selected employees or executives | Targeted compromise or fraud | Sender history, identity and endpoint events |
| 3 | Business email compromise | Trusted business communication | Payment fraud or sensitive-data disclosure | Mailbox rules, sign-ins and payment changes |
| 4 | Vishing, smishing and quishing | Calls, SMS and QR codes | Credential, OTP or payment theft | User reports, mobile and identity logs |
| 5 | MFA fatigue | Authentication prompts | Account takeover | Repeated denials followed by approval |
| 6 | Ransomware | Endpoints, servers and backups | Encryption, extortion and disruption | Mass file changes, EDR and backup events |
| 7 | Trojan and remote-access malware | Files, installers and software | Persistent unauthorised control | Process, persistence and network telemetry |
| 8 | Spyware and keylogging | User activity and credentials | Surveillance and data theft | Input capture, suspicious hooks and outbound traffic |
| 9 | Worms | Networked systems | Rapid self-propagation | Repeated connections and identical infections |
| 10 | Botnets and cryptojacking | Compromised devices and resources | Abused computing power and external attacks | Beaconing, CPU usage and unusual destinations |
| 11 | Brute force and password spraying | Login portals and remote services | Account compromise | Failed sign-ins across accounts or passwords |
| 12 | Credential stuffing | Reused credentials | Account takeover | High-volume logins and leaked-credential matches |
| 13 | Credential dumping and pass-the-hash | Endpoint credential material | Privilege and lateral movement | Credential-store access and remote authentication |
| 14 | DDoS | Public services and bandwidth | Service unavailability | Traffic volume, source distribution and errors |
| 15 | Man-in-the-middle | Network communication | Interception or manipulation | Certificate, ARP, DNS and session anomalies |
| 16 | DNS spoofing and poisoning | Name resolution | Malicious redirection | Unexpected answers and resolver changes |
| 17 | Session hijacking | Cookies and access tokens | Account access without a password | Token reuse and location/device changes |
| 18 | SQL injection | Web inputs and databases | Data theft or modification | WAF, application and database logs |
| 19 | Cross-site scripting | Web content and browsers | Session theft or malicious actions | Application output and browser-security reports |
| 20 | Broken access control and IDOR | Authorisation logic | Unauthorised data or function access | Object access and role-policy violations |
| 21 | SSRF | Server-side URL fetching | Internal-service or metadata access | Unexpected outbound server requests |
| 22 | Zero-day and vulnerability exploitation | Software weaknesses | Execution, access or disruption | Exploit patterns, crashes and unusual child processes |
| 23 | Supply-chain compromise | Vendors, updates and dependencies | Trusted-path compromise at scale | Build, signing, dependency and update telemetry |
| 24 | Cloud account takeover | Cloud identities, keys and configurations | Data exposure or resource misuse | Cloud audit, role and API activity |
| 25 | Insider attack and data exfiltration | Trusted access | Data theft, fraud or sabotage | DLP, access patterns and unusual transfers |
Phishing
Phishing uses deceptive email, chat or online messages to persuade a user to open a file, visit a fake website, reveal information or approve an unsafe action.
Learn the complete defensive workflow in our phishing email investigation guide for SOC analysts.
Spear Phishing and Whaling
Spear phishing is tailored to a selected individual, team or company. Whaling is a targeted form aimed at executives or other high-value decision makers.
Business Email Compromise (BEC)
BEC abuses a compromised or impersonated business identity to manipulate payments, payroll, vendor details or confidential information. It may use no malware at all.
Vishing, Smishing and Quishing
Vishing uses voice calls, smishing uses SMS or mobile messages, and quishing uses QR codes to direct victims toward a fraudulent action.
MFA Fatigue and Push Bombing
An attacker who already knows a password repeatedly triggers MFA requests, hoping the user will approve one through confusion, frustration or social engineering.
Malware-Based Attacks
Malware is software or code designed to perform unauthorised, harmful or deceptive activity.
Ransomware
Ransomware denies access to data or systems, commonly through encryption. Modern extortion incidents may also involve data theft, public-leak threats and disruption before or alongside encryption.
Trojan and Remote-Access Malware
A Trojan appears legitimate or is bundled with something the user expects, but performs hidden malicious activity. Remote-access malware can provide an attacker with unauthorised control of a compromised device.
Spyware and Keylogging
Spyware monitors activity or collects information without proper authorisation. Keyloggers specifically capture keyboard input and may expose passwords, messages or sensitive business information.
Computer Worm
A worm is malware that can spread from one system to another, often by exploiting a weakness or abusing accessible network services without requiring every victim to open a separate file.
Botnets and Cryptojacking
A botnet is a group of compromised systems controlled as a network. Cryptojacking secretly uses computing resources to mine cryptocurrency. A compromised device may participate in DDoS, spam, credential attacks or resource theft.
Password and Identity Attacks
Identity attacks aim to obtain or misuse passwords, hashes, tokens, tickets, keys or trusted sessions.
Brute Force and Password Spraying
Brute force tries many password possibilities against an account. Password spraying attempts a small number of common passwords across many accounts to reduce the chance of immediate lockout.
Credential Stuffing
Credential stuffing uses username-and-password combinations stolen from another service. It succeeds when people reuse passwords across different websites or applications.
Credential Dumping and Pass-the-Hash
Credential dumping attempts to obtain passwords, hashes, tokens or tickets from operating-system and application stores. Pass-the-hash uses a captured password hash for authentication without needing the original plaintext password.
For identity-focused attack paths, read 10 Active Directory attacks every SOC analyst should know.
Want to Learn How SOC Analysts Investigate These Attacks?
Build practical skills in SIEM, endpoint detection, phishing analysis, Windows logs, incident triage, MITRE ATT&CK and security investigation with mentor-led training.
Network Attacks
Network attacks target communication, availability, routing, name resolution or the trust placed in a connection.
Distributed Denial of Service (DDoS)
A DDoS attack uses many systems or traffic sources to overwhelm a service, connection or application so legitimate users cannot access it.
Man-in-the-Middle (MITM)
A MITM attack places an unauthorised party between two communicating systems to observe, redirect or modify information.
DNS Spoofing and Cache Poisoning
DNS attacks manipulate name-resolution information so users or systems are directed to the wrong destination even when they enter the expected domain name.
Session Hijacking and Token Theft
Session hijacking steals or abuses a valid session cookie or token. Because the session may already be authenticated, an attacker can sometimes access an account without submitting the password again.
Build the networking foundation required to understand these threats with our Networking Fundamentals for Cybersecurity Beginners guide.
Web and Application Attacks
Application attacks exploit weaknesses in input handling, authorisation, design, configuration, dependencies or server-side behaviour.
SQL Injection
SQL injection occurs when untrusted input changes the meaning of a database query. Depending on the application and permissions, it may expose, modify or delete information.
Cross-Site Scripting (XSS)
XSS allows untrusted content to execute in another user’s browser within the context of a trusted website. It can enable session theft, content manipulation or unauthorised actions.
Broken Access Control and IDOR
Broken access control allows a user to access data or functions outside their authorised permissions. Insecure Direct Object Reference (IDOR) occurs when an application exposes an object reference without enforcing proper server-side authorisation.
Server-Side Request Forgery (SSRF)
SSRF tricks a server into making a request chosen or influenced by the attacker. The server may be able to reach internal services, management interfaces or cloud metadata endpoints that external users cannot access directly.
Zero-Day and Vulnerability Exploitation
Vulnerability exploitation abuses a software or configuration weakness. A zero-day generally refers to a vulnerability for which defenders have little or no time to apply a complete vendor fix when exploitation becomes relevant.
Understand defensive and ethical testing concepts with our Vulnerability Assessment vs Penetration Testing guide.
Supply-Chain, Cloud and Insider Attacks
These attacks abuse trusted relationships, shared technology, cloud identities or legitimate access.
Software Supply-Chain Attack
A supply-chain attack compromises a vendor, dependency, build process, update mechanism or service provider to reach downstream users through an otherwise trusted path.
Cloud Account Takeover and Misconfiguration Exploitation
Cloud attacks may use stolen credentials, exposed access keys, excessive permissions, unsafe public access or vulnerable workloads to reach data and resources.
Insider Attack and Data Exfiltration
An insider incident involves a person with legitimate access who intentionally misuses it—or whose account and actions create harm through negligence or compromise. Investigation must be evidence-based and respect legal, privacy and HR processes.
How SOC Teams Detect Cyber Attacks
No single tool sees every attack. SOC analysts combine evidence across security layers and validate the context before escalating. A login failure may be a user mistake; thousands of failures across many accounts followed by a successful login could indicate password spraying.
Identity Evidence
Sign-ins, MFA results, password changes, role assignments, session issuance, device registration and risky-login alerts.
Endpoint Evidence
Processes, command lines, files, services, persistence, registry changes, user context and endpoint network connections.
Network Evidence
DNS, proxy, firewall, IDS/IPS, VPN, flow records, certificates, destination reputation and traffic behaviour.
Cloud and Application Evidence
Control-plane audit logs, API activity, storage access, application errors, WAF alerts, authorization decisions and data movement.
A Practical SOC Triage Sequence
- Validate the alert: Confirm the telemetry, time, asset, account and detection logic.
- Establish context: Determine what is normal for the user, system and business process.
- Build the timeline: Check activity before and after the alert across relevant data sources.
- Scope the incident: Identify affected accounts, endpoints, messages, applications and data.
- Assess impact: Determine whether access, execution, persistence, theft or disruption occurred.
- Contain safely: Follow the authorised playbook, preserve evidence and avoid unnecessary business interruption.
- Document clearly: Record evidence, conclusions, limitations, actions and remaining risks.
Cyber Attack Prevention Checklist
No control can guarantee that an organisation will never be attacked. A layered programme reduces both the probability of compromise and the impact when one control fails.
What Should You Do If a Cyber Attack Is Suspected?
- Report immediately: Notify the SOC, IT security team, service provider or authorised incident-response contact.
- Preserve evidence: Record time, affected system, user report, screenshots and available logs. Do not delete evidence simply to make the alert disappear.
- Contain according to authority: Isolate an endpoint, disable an account, revoke sessions or block indicators only under the approved response process.
- Determine scope: Search for related users, devices, messages, accounts, files and destinations.
- Remove the cause: Address malicious files, persistence, compromised credentials, vulnerabilities and unsafe configurations.
- Recover securely: Restore from trusted sources, validate systems, monitor for recurrence and document lessons learned.
Why Understanding Cyber Attacks Matters for Your Career
Attack knowledge is useful across SOC, incident response, threat intelligence, ethical hacking, cloud security, security architecture, GRC and leadership. A beginner does not need to memorise every tool. Start by learning:
- How networks, identity, endpoints, applications and cloud services generate evidence
- How to distinguish an indicator from confirmed impact
- How to build a timeline and ask investigation questions
- How preventive, detective and corrective controls work together
- How to document findings without exaggerating certainty
Turn Cyber Attack Knowledge into Practical Skills
Choose a structured learning path based on your goal: Cybersecurity Essentials for foundations, SOC Analyst training for blue-team investigation, or CEH training for ethical hacking and attack methodology.
Related Cybersecurity Guides
How to Investigate a Phishing Email
Learn sender validation, header analysis, URL and attachment checks, severity classification and SOC documentation.
MITRE ATT&CK Framework Explained
Understand attacker tactics, techniques, threat hunting, detection engineering and incident mapping.
Active Directory Attacks for SOC Analysts
Explore password spraying, Kerberoasting, Pass-the-Hash, DCSync and ticket-based identity attacks.
Microsoft Defender XDR Tutorial
Learn incident investigation, entity analysis, advanced hunting and automated response from a SOC perspective.
Frequently Asked Questions
What are the most common types of cyber attacks?
Common attack types include phishing, password attacks, credential stuffing, ransomware, malware, business email compromise, DDoS, web-application attacks, cloud account takeover and exploitation of vulnerable systems. Prevalence varies by industry, technology and attacker objective.
What is the difference between malware and a cyber attack?
Malware is malicious software or code. A cyber attack is the broader malicious operation. An attack may use malware, but it may also rely on stolen credentials, social engineering, insecure application logic or misuse of trusted access without installing malware.
Which cyber attack is the most dangerous?
There is no universal answer. Risk depends on the target, access obtained and potential business impact. Ransomware, supply-chain compromise, cloud account takeover, business email compromise and identity attacks can all become critical when they affect important systems or data.
Can antivirus stop every cyber attack?
No. Antivirus and endpoint protection are important, but they cannot by themselves stop stolen sessions, unsafe cloud permissions, business email fraud, DDoS or broken application authorisation. Effective defence uses layered identity, endpoint, network, cloud, application, backup and response controls.
How do SOC analysts identify a real attack?
SOC analysts validate the alert, establish normal context, correlate evidence from relevant systems, build a timeline, determine scope and assess impact. They distinguish suspicious activity from confirmed compromise and document both evidence and uncertainty.
What should I learn first as a cybersecurity beginner?
Begin with networking, operating systems, identity, common attack methods, logs and basic security controls. Then choose a path such as SOC, VAPT, cloud security, GRC or security architecture and build practical projects around that role.
How can individuals reduce cyber attack risk?
Use unique passwords with a password manager, enable MFA, keep devices updated, install software only from trusted sources, verify unexpected requests, back up important data and report suspicious activity quickly.
How often should this cyber attack guide be updated?
Review it at least annually and whenever major standards, attack patterns or defensive guidance change. Exact technique names and mappings should always be checked against current authoritative sources before being used in permanent detections or audit documentation.
Authoritative References
- CISA: Malware, Phishing and Ransomware
- MITRE ATT&CK: Adversary Tactics and Techniques
- MITRE ATT&CK: Enterprise Mitigations
- OWASP Top 10: 2025 Web Application Security Risks
- NIST Cybersecurity Framework
Social-Engineering Attacks
These attacks manipulate people, trust and business processes rather than relying only on technical vulnerabilities.