Inside the Mind of a Cybercriminal How Modern Attacks Really Happen
The Attack Begins Before You Know It
Most cyberattacks do not begin with a flashing warning on a
computer screen. They begin quietly.
A cybercriminal studies the target company’s website, wifi,
employees and social media accounts. An employee announces a new position on
LinkedIn. An executive posts photographs from an overseas conference. A
supplier’s contact details appear in a public document. Somewhere else, an
exposed system remains unpatched, or credentials compromised in an earlier
breach are still being used.
Individually, these pieces of information may appear
insignificant. To the attackers, they can form part of a much larger picture
and information that can be exploited.
Modern cybercriminals do not always need to defeat
sophisticated security systems. They look for opportunity: an exploitable
vulnerability, compromised credentials, a convincing phishing message, an
exposed third-party connection or a person who can be manipulated into
providing access.
The process can be remarkably patient. An attacker may
research an organisation, identify potential weaknesses and wait for the right
opportunity. A phishing email may be designed to capture credentials rather
than steal money immediately. Compromised access may provide a foothold from
which to explore systems, identify valuable information and move closer to the
ultimate objective. CISA describes phishing as a form of social engineering
that can be used to obtain credentials or deploy malware for further malicious
activity
This is what makes modern cybercrime difficult to defend
against. Attackers adapt. They exploit what they discover and combine technical
weaknesses with human behaviour .
Understanding that process changes the question
organisations should be asking.
Not simply:
“How do we stop hackers?”
But:
“What would an attacker see if they were looking at our
organisation right now?”
Every Attack Has a Path
Cyberattacks can appear sudden to the victim, but the
activity preceding them may be anything but spontaneous. Attackers frequently
move through a sequence of opportunities—gathering information, establishing
access, expanding that access and eventually pursuing an objective.
That objective varies. Some attackers want money. Others
seek confidential information, credentials or commercially valuable data.
Ransomware operators may seek both data and disruption, while fraudsters may
use compromised communications to manipulate payments or impersonate trusted
individuals.
The first opening may be surprisingly ordinary. A convincing
email. A reused password. An unpatched internet-facing system. An account with
excessive privileges. Access inherited through a third-party provider.
Once inside, the attacker’s priorities change. The question
is no longer “Can I get in?” but “What can I reach?””What data is
vulnerable to change and modify?” ”Is the email servers accessible and
sensitive information available?”
This is where seemingly separate weaknesses can become
dangerous when combined. One compromised account may expose internal
communications. Those communications may reveal suppliers, reporting structures
or financial processes. Additional credentials may provide access to other
systems. Information gathered from one part of the organisation can then be
used to make the next stage of the attack more convincing.
The lesson is important: organisations should not evaluate
cyber risk solely by looking for one catastrophic vulnerability. A modern
attack can succeed because several smaller weaknesses create a pathway towards
something valuable.
When a Weakness Becomes an Opportunity
South Africa has already seen how a security weakness can
escalate into a much broader organisational and regulatory issue.
In March 2022, credit bureau TransUnion South Africa
experienced a cyber incident in which a criminal third party gained access to
an isolated server. TransUnion subsequently reported that data relating to
approximately five million consumers was potentially affected, with a further 5.2
million consumers having ID numbers affected without personal
information linked to those numbers. Approximately 600,000 organisations
were also potentially affected
The incident also attracted the attention of South Africa’s
Information Regulator. Following its initial assessment, the Regulator
expressed concern about the adequacy of TransUnion’s response and the
safeguards protecting personal information and initiated an assessment into
the organisation’s security measures
The significance of the incident extends beyond the number
of records involved. It demonstrates how a cyberattack can quickly move beyond
information technology and become an issue of governance, regulatory
compliance, privacy, reputation and stakeholder confidence. It also illustrates
an uncomfortable reality: attackers do not need every control to fail. They
need an opportunity that allows them to progress.
South Africa is part of a much broader threat environment.
INTERPOL’s 2025 Africa Cyberthreat Assessment identified online scams,
particularly phishing, as the most frequently reported cybercrime across
Africa, while ransomware, Business Email Compromise and digital sextortion
remained widespread threats
The methods may differ, but the underlying principle remains
remarkably consistent: cybercriminals look for weaknesses that can be converted
into access, influence or financial gain.
Think Like an Attacker—Defend Like an Organisation
Understanding how attackers operate does not mean
organisations need to predict every possible cyberattack. It means recognising
that effective defence depends on making the attacker’s journey progressively
more difficult.
A vulnerability that is identified and patched removes one
opportunity. Multi-factor authentication can make stolen credentials
less useful. Appropriate access controls can limit what a compromised account
can reach. Effective monitoring can expose unusual behaviour. Employees who
recognise manipulation can interrupt a social-engineering attempt before access
is granted.
Individually, none of these measures provides absolute
protection. Together, they create layers of resistance.
This is where cyber resilience becomes a governance issue
rather than simply a technical one. Boards and executives do not need to
understand every line of malicious code, but they should understand where
critical information resides, who can access it, which third parties create
dependencies, whether significant vulnerabilities are being addressed and
whether the organisation is capable of detecting and responding when something
goes wrong.
The objective is not to build an organisation that can never
be attacked.
It is to build one in which an attacker encounters fewer
opportunities, stronger controls and a far greater chance of being detected
before reaching the intended target.
D-finitive Insight
Cybercriminals do not view an organisation through the
boundaries of departments, systems or policies. They look for opportunity. That
opportunity may be an unpatched vulnerability, compromised credentials, a
third-party connection or an employee who can be persuaded to take the wrong
action at the right moment.
At D-finitive Advisory, we believe effective cyber
resilience begins by understanding the organisation from the attacker’s
perspective. Strong governance, timely vulnerability management, effective
access controls, informed employees and tested incident-response procedures
should operate together—not as isolated safeguards.
The objective is not simply to stop the final attack. It is
to identify and disrupt the opportunities that allow an attacker to progress in
the first place.
Understand the attack. Strengthen the defence. Protect
what matters.
Delivering Clarity. Protecting
Integrity. Driving Accountability.
