Attack Targets 🪓

Yes, admitted, they are probably protection goals in reverse, but I still want to quickly give an overview.

Data Abuse 📧

Misuse of data. A small example? A phishing email with the goal of luring an unsuspecting user to a fake website (preferably PayPal or their own bank). By the way, two violations of authenticity already occur here: a fake email and a fake website.

The abuse occurs when the data obtained is sold and traded further. Attackers often work quite division of labor here.

Data Manipulation 🪄📂

With data manipulation, the integrity of the entire data is lost, meaning one’s own data can no longer be trusted. It enables attackers to extort their victims. This can bring companies to the brink of ruin.

Data Theft 🔒🪓

A data leak can lead to a loss of reputation and consequently a loss of customers. Here, confidentiality is violated as a protection goal, as is the privacy of the users themselves.

Particularly explosive was the publication of stolen user data from Ashley Madison in 2015. The portal was an online dating portal specializing in affairs. With the publication of user data, some suicides occurred.

Denial-of-Service Attacks 🔫

An attack on a system or service such that the availability protection goal can no longer be achieved.

Websites are often bombarded with a flood of requests so that they can no longer handle them. Especially for online shops, this can lead to considerable revenue losses, up to reputational damage and customers switching to competitors.

Takeover 🤖

An attempt is made to gain access to the network or devices in order to misuse them for one’s own purposes.

Crypto miners are often installed, which bring money to the attacker; this is called cryptojacking. Another case is that the computers are available as bots for hire.