Threat Atlas
Follow the path
of a cyber attack.
Explore how threat actors operate, the techniques they use and the real-world impact — in a simple, visual way.
Explore the Threat AtlasThreat ActorWho is behind it?
CampaignWhat are they targeting?
TechniqueHow do they do it?
AttackWhat happens?
ImpactWhat's the result?
DetectionHow to spot it?
Featured threat
Ransomware
Ransomware is a type of malware that locks your files or systems and demands payment to get them back.
Learn moreThe attack chain
The attack chain
Popular Threats
One row per threat: an overview first, then articles that go deeper. Scroll a row sideways, or choose View all.
In Ransomware5 reads
- Ransomware
Ransomware: the full picture
Ransomware operations are criminal businesses that break into organisations to lock or steal data and demand payment. Many work as an ecosystem where different people handle access, deployment and negotiation.
Threat overview - Ransomware
Ransomware: What Really Happens When Hackers Lock Your Files
The locked-screen moment is the loud part. Understanding what happens before it is where defenders find their advantage.
Intermediate · 2 min read - Ransomware
Double Extortion: When Locking Your Files Is Only Half the Threat
Modern ransomware often steals data first. Restoring from backup fixes the locked files, but not the threat to publish what was taken.
Intermediate · 2 min read - Ransomware
AI in Incident Response: How I Use It During Real Investigations
Where an AI assistant can genuinely save an analyst time during an incident, and where a human must stay in charge.
Intermediate · 2 min read - Ransomware
EDR: The Flight Recorder on Every Laptop
Antivirus asks 'have I seen this file before?'. EDR asks 'what is this machine doing right now, and does it look wrong?'.
Beginner · 2 min read
In Phishing5 reads
- Phishing
Phishing: the full picture
Phishing campaigns use convincing messages to trick people into giving up access, information or money. They range from mass emails to highly targeted messages written for one person.
Threat overview - Phishing
Phishing: How a Simple Email Can Lead to a Big Problem
It only takes one click. Here is how phishing works, why it is so effective, and how you can spot it.
Beginner · 2 min read - Phishing
Spear Phishing and BEC: The Email That Knows Your Name
Targeted email attacks skip the generic tricks. They use real names, real projects and real timing.
Intermediate · 2 min read - Phishing
Social Engineering: Hacking the Human Instead of the Computer
The easiest system to break into is often a person. Social engineering is the art of persuading someone to help an attacker.
Beginner · 2 min read - Phishing
Phishing + AI: Can an Assistant Spot a Fake Email?
AI can read a suspicious email quickly and point out the red flags. It can also be fooled, so treat it as a second opinion, not a verdict.
Beginner · 2 min read
In Credential Attacks5 reads
- Credential Attacks
Credential Attacks: the full picture
Credential attacks aim to get valid usernames and passwords, or sessions, by phishing, malware, guessing or reuse. Once they succeed, attackers can look like ordinary users.
Threat overview - Credential Attacks
Credential Theft: How One Stolen Password Opens Every Door
Stolen logins are behind a large share of intrusions. Here are the common routes and what they look like to a defender.
Intermediate · 2 min read - Credential Attacks
Password Spraying: How Attackers Try the Same Few Passwords Everywhere
Two automated attacks that make login pages the target: one tries common passwords on many accounts, the other reuses leaked ones.
Intermediate · 2 min read - Credential Attacks
MFA: The Second Lock That Hackers Can Still Pick
Multi-factor authentication blocks most stolen-password attacks — but not all of them. Here is how attackers get around it, and what actually holds up.
Beginner · 3 min read - Credential Attacks
Passwords: Why a Password Manager Beats Your Memory
Nobody can remember dozens of strong, unique passwords. A password manager does it for you, and does it more safely.
Beginner · 2 min read
In Insider Threats4 reads
- Insider Threats
Insider Threats: the full picture
An insider threat comes from someone with legitimate access. It can be deliberate, but is more often a mistake, such as sending data to the wrong person or falling for a scam.
Threat overview - Insider Threats
Insider Threats: When the Risk Is Already Inside the Building
Not every insider is malicious. Many incidents come from mistakes, and the signs to watch for are about behaviour, not suspicion.
Intermediate · 2 min read - Insider Threats
Data Exfiltration: How Data Quietly Walks Out the Door
Stealing data is often the real goal of an attack. Here are the common routes it takes on the way out.
Intermediate · 2 min read - Insider Threats
Least Privilege: Why Nobody Should Have More Access Than They Need
The simplest way to limit the damage of any mistake, theft or compromise is to give every account only the access it truly needs.
Beginner · 2 min read
In Advanced Persistent Threats5 reads
- Advanced Persistent Threats
Advanced Persistent Threats: the full picture
Advanced persistent threat (APT) describes well-resourced adversaries who aim to stay hidden in a network for a long time. This page describes the general pattern only, without attributing any incident to anyone.
Threat overview - Advanced Persistent Threats
APT: The Attackers Who Are Willing to Wait
Advanced persistent threats are patient, well-resourced intrusions. What sets them apart is not one trick, but persistence.
Intermediate · 2 min read - Advanced Persistent Threats
Living off the Land: Attacks That Use Your Own Tools Against You
Why bring your own malware when the target already has powerful, trusted tools installed?
Advanced · 2 min read - Advanced Persistent Threats
MITRE ATT&CK: The Attacker's Playbook, Published for Defenders
A shared, public catalogue of how attackers behave, used to talk about threats, plan defences and spot gaps.
Intermediate · 2 min read - Advanced Persistent Threats
Threat Hunting: Looking for Attackers Nobody Has Alerted On
Alerts catch what defenders already know to look for. Threat hunting goes looking for what they do not.
Intermediate · 2 min read
In Hacktivism5 reads
- Hacktivism
Hacktivism: the full picture
Hacktivists use attacks to make a statement. Activity often aims at visibility, such as defacing websites, leaking data or disrupting services.
Threat overview - Hacktivism
Hacktivism: When Cyber Attacks Carry a Message
Hacktivists attack to make a point, not to make money. That changes who they target and what they do.
Beginner · 2 min read - Hacktivism
Data Leaks and Doxxing: When Private Information Goes Public
Publishing stolen or gathered information is a powerful way to pressure or embarrass. Here is how it works, and how to reduce the risk.
Beginner · 2 min read - Hacktivism
DDoS: When a Crowd of Fake Visitors Takes a Website Down
A DDoS attack does not steal anything. It just makes a service so busy that real users cannot get in.
Beginner · 2 min read - Hacktivism
Threat Actors: Who Is Actually Attacking, and Why
Not every attacker wants the same thing. Knowing the type of adversary helps you guess what they will do next.
Beginner · 2 min read
Real Threats. Real Examples.
See how these attacks play out in the real world — and what to look for.
Explore Real-World Examples- RansomwareHow an attack unfolds
- PhishingFake login page example
- Credential theftHow logins get stolen