Good to see you again. Previously, you learned to separate an unsafe staff action from a weak organisational control. That explains how an incident may begin or spread. This lesson adds another essential question: why would an attacker choose to act?
Threat actors do not all want the same outcome. A criminal group may want money, a government may seek strategic advantage, a terrorist group may seek to intimidate or cause ideological violence, and an individual may be motivated by satisfaction, revenge, belief, or personal gain. For distinction-level answers, you need to identify the most likely motive from scenario evidence rather than simply naming a type of attacker.
By the end of this lesson, you should be able to distinguish the motives of commercial, government, terrorist, and individual threat actors, including cases where the categories overlap.
Motive is not the same as method, intent, or capability
A threat actor is the person, group, or organisation behind a malicious cyber action. The same attack method, such as phishing, ransomware, or a denial-of-service attack, can be used by very different actors for very different reasons.
For example, if a company is hit by ransomware:
- A commercial cybercriminal may be seeking a ransom payment.
- A government-backed actor might use ransomware as a distraction while stealing sensitive information.
- A terrorist group might use it to disrupt an important service and create fear.
- An individual might use it for personal profit, revenge, or simply to prove they can.
Therefore, do not identify the actor purely from the technology used. Look for evidence about the likely purpose.
The National Cyber Security Centre separates four useful ideas when assessing a threat:
| Term | Meaning | Example |
|---|---|---|
| Motivation | The underlying reason the actor acts. | Money, political influence, revenge. |
| Intent | The result the actor wants from this particular attack. | Steal a database, disrupt a service, demand a ransom. |
| Capability | The skills, tools, funding, and resources available. | Custom malware, a large team, or freely available tools. |
| Opportunity | The opening that makes an attack possible. | A vulnerable server, weak passwords, or insider access. |
Consider this short example:
A criminal group finds an organisation with an exposed remote-access service. It uses ransomware and demands payment.
- Motivation: Financial profit.
- Intent: Encrypt systems and obtain a ransom.
- Capability: Ability to obtain and operate ransomware tools.
- Opportunity: The exposed or weakly protected remote-access service.
A high-quality answer keeps these terms separate. Saying “the attacker had ransomware” describes capability or method; it does not by itself prove motive.
Risk management | The fundamentals and basics of cyber ...
Read this National Cyber Security Centre guidance to make the important distinction between a threat actor's motivation, intent, capability, and opportunity. These terms help prevent vague exam answers.
In the section “The components of cyber risk,” read the four components. Then continue into the “Capability,” “Intent,” “Motivation,” and “Opportunity” explanations. Focus particularly on why an actor's reason for acting is different from the harm they intend to cause in one specific incident.
The four broad threat-actor categories
The infographic below gives a useful starting map. It shows common motivations, not unbreakable rules. An individual can be financially motivated; a government can also use financially motivated activity; and a disgruntled insider may cooperate with a criminal group. In an exam, use the scenario evidence to decide which explanation is best supported.

An introduction to the cyber threat environment
This Canadian Centre for Cyber Security overview gives clear definitions and a practical classification of cyber threat actors. Read it to connect each actor type with its usual motivation, while recognising that capability varies between actors.
In the “Cyber threat actors” section, begin with the classification and motivation map. Then read the detailed paragraphs on state-sponsored actors, cybercriminals, hacktivists, and insider threats. Pay attention to the word “primarily”: it signals a common motive, not a guarantee. In the cybercriminal paragraph, use the financial-motive explanation to note that profit-driven actors can range from basic opportunists to organised groups.
1. Commercial threat actors: profit or commercial advantage
A commercial threat actor is motivated by economic benefit. This may mean direct criminal profit, but it can also mean gaining an advantage over a rival organisation.
There are two useful forms to distinguish.
Commercial cybercriminals seek illegal income. They may:
- demand ransom after encrypting data;
- steal bank details, payment-card information, or cryptocurrency;
- sell stolen personal data or login credentials;
- commit invoice fraud;
- run scams at scale;
- use stolen computing power for cryptocurrency mining.
Their success is usually measured in money. They may target many organisations opportunistically because any vulnerable victim could produce profit.
Commercial competitors or corporate spies seek business advantage. They may want:
- product designs and trade secrets;
- research and development data;
- tender or pricing information;
- customer lists;
- marketing plans;
- merger information;
- evidence that damages a competitor's reputation.
Their activity is more likely to be targeted. For example, stealing a prototype design shortly before a product launch suggests commercial advantage more strongly than a random ransomware attack would.
Exam-safe distinction: A competitor may want to become more successful than a rival. A cybercriminal may not care about the victim's market at all; they want illicit revenue from the victim.
Do not assume that every financially motivated attack is carried out by one highly organised criminal gang. Some profit-driven actors are sophisticated groups, while others use purchased or freely available tools. Their motive may be similar even when their capability is very different.
2. Government threat actors: strategic and geopolitical advantage
A government or nation-state threat actor operates on behalf of, or in support of, a state. Its primary motive is usually geopolitical or strategic advantage: improving its country's position, security, influence, or military readiness.
Possible aims include:
- espionage against another government;
- stealing defence, scientific, industrial, or diplomatic information;
- monitoring dissidents, journalists, or political opponents;
- influencing public opinion or elections;
- gaining access to critical national infrastructure;
- disrupting another country's public services, financial systems, communications, or defence systems;
- remaining hidden in a network so access can be used later during a political or military crisis.
Unlike a commercial criminal, a government actor may invest significant time and resources without expecting immediate financial return. The value may be intelligence, influence, or future strategic access.
For instance:
A group quietly remains inside an energy provider's network for months, maps industrial-control systems, and steals technical documents. There is no ransom demand and no obvious attempt to sell data.
A well-supported judgement is that this could indicate a government-backed actor, because the likely objective is strategic intelligence or the ability to disrupt critical infrastructure later. However, it is not proof. A distinction-level answer should use cautious wording such as “suggests,” “is consistent with,” or “is likely because.”
Government actors are often well funded and highly capable, but avoid writing that all advanced attacks must be government attacks. Capability is evidence to consider, not final proof of identity.
3. Terrorist threat actors: ideological violence, intimidation, and disruption
A terrorist threat actor is motivated by ideological violence. The objective is not simply to make money or express disagreement: it is to further an extremist cause through intimidation, fear, coercion, or serious disruption.
Possible cyber aims include:
- disrupting emergency, transport, health, energy, or communications services;
- spreading propaganda or threatening messages;
- publishing stolen information to intimidate a population;
- doxxing people, meaning exposing personal details, to encourage harassment;
- recruiting supporters;
- damaging systems in ways intended to create fear or instability.
The key idea is the intended psychological and ideological impact. A terrorist actor may want people, organisations, or governments to feel unsafe or change their behaviour.
It is important not to confuse a terrorist actor with a hacktivist:
| Actor | Typical motive | Typical desired effect |
|---|---|---|
| Hacktivist | Political or social ideology. | Publicity, protest, embarrassment, or promotion of a cause. |
| Terrorist group | Ideological violence and coercion. | Fear, intimidation, serious disruption, or support for violent extremism. |
Both could deface a website or launch a denial-of-service attack. The difference is the wider purpose and context. A website defaced with a protest slogan may indicate hacktivism. An attack intended to disrupt emergency communications and intimidate the public would be more consistent with terrorism.
Do not make assumptions about a group based on nationality, religion, or political view. Cybersecurity analysis should be based on actions, evidence, stated aims, target choice, and likely outcomes.
4. Individual threat actors: personal motives
An individual threat actor acts alone rather than as part of a government, terrorist organisation, or organised commercial group. “Individual” describes the actor's scale, not necessarily their skill level.
Individual motivations vary. Common examples include:
- Satisfaction or thrill-seeking: proving they can access a system, gaining status, curiosity, or enjoyment.
- Revenge or discontent: a former or current employee harms an organisation after a dispute, disciplinary action, or dismissal.
- Personal financial gain: stealing money, data, or accounts for themselves.
- Ideology: an individual acts because of a personal political or social belief.
- Personal grievance: targeting a person, school, employer, or local organisation due to a dispute.
An individual may be external, such as a person testing publicly available hacking tools against websites. Or they may be an insider, such as an employee who already has authorised access.
This distinction matters:
- Individual tells you whether the actor is acting alone.
- Insider tells you that they have an internal relationship or authorised access.
- Discontent or revenge may be their motive.
For example:
A dismissed employee still has access to a shared cloud folder. They delete project documents and send angry messages to managers.
This is best described as an individual insider threat motivated by discontent or revenge. The opportunity came from the organisation failing to remove access promptly.
How to infer motive from scenario evidence
In most exam scenarios, you will not be told with certainty who carried out an attack. You are expected to make a reasoned judgement from the evidence provided.
Use this pattern:
- Identify the likely actor category.
- Quote or describe relevant scenario evidence.
- Link that evidence to a likely motive.
- Acknowledge a realistic alternative if the evidence is incomplete.
Here are examples of the reasoning expected.
| Scenario evidence | Best-supported judgement | Why |
|---|---|---|
| A company is locked out of systems and receives a cryptocurrency demand. The same malware affects many unrelated organisations. | Commercial cybercriminals are likely. | The attack is scalable and the demand indicates direct financial gain. |
| A rival company obtains confidential designs shortly before a tender process. No ransom is demanded and the files are not published. | Commercial espionage is plausible. | The stolen information could create a competitive advantage. |
| Attackers secretly access a water supplier's systems and remain undetected while collecting technical information. | A government-backed actor may be likely. | Critical infrastructure and long-term covert access suggest strategic or geopolitical objectives. |
| An actor disrupts a public service, publishes extremist messages, and threatens further disruption to intimidate the public. | A terrorist threat actor is plausible. | The apparent aim is ideological intimidation and fear, not simply profit. |
| A student uses downloaded tools to take a school website offline, then boasts online about it. | An individual thrill-seeker is likely. | The visible reward is satisfaction, recognition, or proving ability. |
| An employee copies customer data shortly after being denied a promotion. | An individual insider motivated by discontent is plausible. | The timing and existing access point toward a personal grievance, although sale of the data for profit is also possible. |
Notice the language: likely, plausible, and suggests. Attribution can be difficult. Attackers may deliberately leave false clues, use another group's tools, or hide their location.
A weak answer would say:
It was definitely a government because the attack was advanced.
A stronger answer would say:
The long-term covert access to critical infrastructure suggests a possible government-backed actor because a state may seek strategic intelligence or future disruption capability. However, a well-funded criminal group could also have the technical capability, so further evidence would be needed to confirm attribution.
That second response identifies a justified conclusion and an alternative explanation. This is the sort of balanced judgement that improves an answer toward distinction level.
A compact exam-answer structure
When asked to explain a threat actor's motive, build a short chain of reasoning:
Actor category + scenario evidence + likely motive + how the attack helps achieve it.
For example:
The attacker is likely to be commercially motivated because they encrypted the organisation's files and demanded cryptocurrency. Their aim is financial profit: denying access to important systems creates pressure for the victim to pay a ransom.
For a government scenario:
The activity may be state-sponsored because the attackers targeted defence research and remained hidden rather than demanding payment. This suggests a geopolitical motive, as the stolen intelligence could provide strategic advantage to another country.
For an individual insider scenario:
This appears to be an individual insider threat motivated by discontent. The employee already had authorised access and deleted files immediately after disciplinary action, suggesting revenge rather than an attempt to gain commercial profit.
Use the word because. It forces you to explain the link rather than list disconnected facts.
Key takeaways
- A threat actor's motivation is the underlying reason for acting. It is different from their immediate intent, technical capability, and available opportunity.
- Commercial actors seek money or commercial advantage. Cybercriminals often seek direct profit; competitors may seek trade secrets or market advantage.
- Government actors are commonly motivated by geopolitical and strategic goals, including espionage, influence, disruption, and access to critical infrastructure.
- Terrorist actors seek to support ideological violence through intimidation, fear, coercion, or serious disruption. This differs from hacktivism, which is more often focused on protest or publicity.
- Individuals can be motivated by satisfaction, revenge, personal gain, ideology, or a personal grievance. An individual may also be an insider if they have authorised organisational access.
- In scenario answers, use evidence and cautious judgement. An advanced technique alone does not prove who the attacker is.
Next, you will analyse what a successful attack can cost an organisation beyond the initial technical problem: operational disruption, financial loss, reputational harm, and loss of intellectual property.
Can't find a good explanation? Sign up and we'll make it for you
Sign up