Threat Atlas
Follow the path
of a cyber attack.
Explore how threat actors operate, the techniques they use and the real-world impact — in a simple, visual way.
Explore the Threat AtlasThreat ActorWho is behind it?
CampaignWhat are they targeting?
TechniqueHow do they do it?
AttackWhat happens?
ImpactWhat's the result?
DetectionHow to spot it?
Featured threat
Ransomware
Ransomware is a type of malware that locks your files or systems and demands payment to get them back.
Learn moreThe attack chain
The attack chain
Popular Threats
One row per threat: an overview first, then articles that go deeper. Scroll a row sideways, or choose View all.
In Ransomware5 reads
- Ransomware
Ransomware: the full picture
A ransomware attack breaks into an organisation to lock or steal data and demand payment, often run by specialists in access, deployment and negotiation.
Threat overview - Ransomware
Ransomware: What Really Happens When Hackers Lock Your Files
The locked-screen moment is the loud part. Understanding what happens before it is where defenders find their advantage.
Intermediate · 4 min read - Ransomware
Double Extortion: When Locking Your Files Is Only Half the Threat
Modern ransomware often steals data first. Restoring from backup fixes the locked files, but not the threat to publish what was taken.
Intermediate · 4 min read - Ransomware
AI in Incident Response: How I Use It During Real Investigations
AI in incident response can save real time during a live investigation, but knowing exactly where its limits sit matters just as much.
Intermediate · 2 min read - Ransomware
EDR: The Flight Recorder on Every Laptop
Antivirus asks whether it's seen a file before. Endpoint detection and response, or EDR, asks what a machine is doing right now.
Beginner · 2 min read
In Phishing5 reads
- Phishing
Phishing: the full picture
A phishing campaign tricks people into handing over access, information or money using convincing fake messages, from mass emails to one tailored message.
Threat overview - Phishing
Phishing: How a Simple Email Can Lead to a Big Problem
It only takes one click. Here is how phishing works, why it is so effective, and how you can spot it.
Beginner · 4 min read - Phishing
Spear Phishing and BEC: The Email That Knows Your Name
Spear phishing and business email compromise (BEC) skip the generic tricks. They use real names, real projects and real timing.
Intermediate · 3 min read - Phishing
Social Engineering: Hacking the Human Instead of the Computer
The easiest system to break into is often a person. Social engineering is the art of persuading someone to help an attacker get in.
Beginner · 2 min read - Phishing
Phishing + AI: Can an Assistant Spot a Fake Email?
AI phishing email analysis can scan a suspicious message fast and call out its red flags, but it gets fooled too, so verify what it flags before you trust it.
Beginner · 2 min read
In Credential Attacks5 reads
- Credential Attacks
Credential Attacks: the full picture
Credential theft gets attackers valid usernames, passwords or sessions through phishing, malware, guessing or reuse, so it looks like ordinary use.
Threat overview - Credential Attacks
Credential Theft: How One Stolen Password Opens Every Door
Stolen logins are behind a large share of intrusions. Here are the common routes and what they look like to a defender.
Intermediate · 4 min read - Credential Attacks
Password Spraying and Credential Stuffing, Explained
Password spraying and credential stuffing turn login pages into the target: one tries common passwords broadly, the other reuses leaked ones.
Intermediate · 3 min read - Credential Attacks
MFA: The Second Lock That Hackers Can Still Pick
Multi-factor authentication blocks most stolen-password attacks — but not all of them. Here is how attackers get around it, and what actually holds up.
Beginner · 4 min read - Credential Attacks
Passwords: Why a Password Manager Beats Your Memory
Nobody can remember dozens of strong, unique passwords. A password manager does it for you, and does the job more safely than memory ever could.
Beginner · 2 min read
In Insider Threats4 reads
- Insider Threats
Insider Threats: the full picture
An insider threat comes from someone with legitimate access, and is more often an honest mistake, like misdirected data, than a deliberate act.
Threat overview - Insider Threats
Insider Threats: When the Risk Is Already Inside the Building
An insider threat comes from someone with legitimate access. Some incidents are deliberate, but most start with a simple mistake.
Intermediate · 3 min read - Insider Threats
Data Exfiltration: How Data Quietly Walks Out the Door
Data exfiltration, the theft of data out of an organisation, is often the real goal of an attack. Here are the routes it takes.
Intermediate · 3 min read - Insider Threats
Least Privilege: Why Nobody Should Have More Access Than They Need
The principle of least privilege limits damage from any mistake, theft or compromise by giving every account only the access it needs.
Beginner · 2 min read
In Advanced Persistent Threats5 reads
- Advanced Persistent Threats
Advanced Persistent Threats: the full picture
An advanced persistent threat (APT) is a well-resourced adversary that stays hidden in a network for a long time, pursuing a specific objective patiently.
Threat overview - Advanced Persistent Threats
What Is an APT? The Attackers Who Are Willing to Wait
An advanced persistent threat is a patient, well-funded intrusion built around one thing: staying hidden for as long as it takes.
Intermediate · 3 min read - Advanced Persistent Threats
Living off the Land: Attacks That Use Your Own Tools Against You
Living off the land means attackers skip their own malware and use the powerful, trusted tools already installed on the target.
Advanced · 2 min read - Advanced Persistent Threats
MITRE ATT&CK: The Attacker's Playbook, Published for Defenders
A shared, public catalogue of how attackers behave, used to talk about threats, plan defences and spot gaps.
Intermediate · 4 min read - Advanced Persistent Threats
Threat Hunting: Looking for Attackers Nobody Has Alerted On
Alerts catch what defenders already know to look for. Threat hunting is the deliberate search for what they haven't thought to check.
Intermediate · 2 min read
In Hacktivism5 reads
- Hacktivism
Hacktivism: the full picture
Hacktivists use attacks to make a statement. Activity often aims at visibility, such as defacing websites, leaking data or disrupting services.
Threat overview - Hacktivism
Hacktivism: When Cyber Attacks Carry a Message
Hacktivism uses hacking to make a political point rather than money, and that changes who gets targeted and what actually happens.
Beginner · 2 min read - Hacktivism
Data Leaks and Doxxing: When Private Information Goes Public
A data leak publishes stolen files, and doxxing publishes a person's private details. Here is how each works, and how to reduce the risk.
Beginner · 2 min read - Hacktivism
DDoS: When a Crowd of Fake Visitors Takes a Website Down
A DDoS attack steals nothing. It just makes a service so busy answering fake requests that real users can no longer get in.
Beginner · 2 min read - Hacktivism
Threat Actors: Who Is Actually Attacking, and Why
Not every threat actor wants the same thing. Knowing the type of adversary you're facing helps predict what they'll do next.
Beginner · 2 min read
Real Threats. Real Examples.
See how these attacks play out in the real world — and what to look for.
Explore Real-World Examples- RansomwareHow an attack unfolds
- PhishingFake login page example
- Credential theftHow logins get stolen