Ransomware surged 151% between 2020 and 2021, and security teams still face hundreds of thousands of new samples captured daily. This report maps that rise to real human drivers and measurable attack trends.
Cyber attacks aim to steal, delete, or alter information and data. The growth of IoT devices has widened the attack surface, while low security awareness keeps many users exposed.
Phishing remains the most common entry point. One click can cascade from social trickery to code-based takeover and, ultimately, ransom. That chain shows why technical controls alone often fall short.
This section sets the scene for a present-day trend report. It links the motives and methods of attackers to observable campaign patterns across the world. You will get clear definitions of attack types, the roles of intent and skill, and the sociotechnical shifts that shape risk.
Our goal is practical: translate research and real-world insight into better defenses that pair security controls with behavioral strategies for people who use computer systems every day.
Key Takeaways
- Human behavior is decisive: attackers exploit trust and attention lapses to trigger attacks.
- IoT expands risk: more connected devices mean more points of compromise.
- Technical and behavioral controls work best together.
- Motives vary: curiosity, status, and profit drive different campaign styles.
- Actionable research: this report links evidence to practical steps for security teams.
Executive overview: why understanding behavior outpaces purely technical defenses
Behavioral weak points, not just code flaws, explain why breaches keep rising even as spending grows. Today’s breaches succeed as much by bending human choices as by exploiting software flaws.
The 2020 surge in ransomware showed how fast attacks can scale when adversaries target trust and haste. Cloud, IoT, and always‑on connectivity expand the attack surface where data and information move across systems.
Spending on technology and tools matters, but it is not enough. Adversaries aim at people and decision paths. That gap keeps risk high despite better technical blocks.

Behavior‑centric defenses—trust calibration, clearer decision support, and just‑in‑time education—reduce successful attacks where time pressure matters most. Embedding behavioral guardrails into product design, workflows, and policy closes common failure modes.
- Baseline behavior risks: measure phishing click rates and shadow IT to prioritize controls.
- Blend analytics with human-centered content: timely prompts, plain-language alerts, and micro-training.
- Prioritize outcomes for executives: fewer successful attacks, faster anomaly detection, and smaller blast radii.
Interdisciplinary research must test how people respond under ambiguity and speed. Policy and compliance need practical, psychologically valid guidance so systems protect real users, not just checkboxes.
User intent and scope of this trend report
This section defines what we aim to teach and where to focus practical defenses.It frames the report’s approach to motivation, tactics, and measurable impact so teams can act quickly and confidently.
Seeing attacks as human-driven campaigns changes where defenses should focus. This report builds an evidence-backed path from motive to method and then to practical steps that reduce risk.
What you will learn:
- Clarified intent: how understanding attacker goals helps you prioritize controls and training.
- Scope: psychological profiles, community norms, lifecycle shifts, common attack types, and effects on people, information, and data.
- Boundaries: we analyze behavior and decision points, not offensive techniques.
Research shows specific, short training cuts phishing clicks more than broad computer literacy. We also describe how mouse movement and other micro-behaviors can surface awareness differences without blaming users.

Expect actionable outcomes: lower click rates, faster time-to-report, and fewer successful credential thefts. The report ends with role-specific checklists for leaders, designers, and policy makers to use in production systems.
malware author psychology
Understanding who creates harmful code helps defenders predict choices and reduce risk. This concept links motivation, identity, norms, and situation to how attacks are designed and executed.
Define the term as the interplay of intrinsic drives—challenge, recognition, craft—and extrinsic incentives like money, anonymity, and low capture risk.
Community narratives can normalize harm. Groups may rationalize damage and downplay victims, which lowers internal restraints.

Not all creators share the same mindset. Some prioritize system knowledge and selective targets. Others act indiscriminately.
Perceived invincibility online speeds decision-making: quick payoff, minimal visible consequences, and distance from affected people and systems.
- Observable link: social engineering taps urgency, habit, and trust to raise success rates.
- Variation over time: many age out or shift when life and responsibilities change.
- Role of researchers: systematic study of campaigns and artifacts reveals behavior signals defenders can use.
Understanding motive is not excusing harm; it guides better, human-centered defenses and prepares teams for multi-stage attacks covered later.
Motivations behind malware authors: from curiosity to criminal economies
Creators range from curious tinkerers to participants in organized cash-for-access schemes. This section maps intrinsic drives and external incentives to real-world choices so defenders can spot where risks converge.
Some creators start by solving puzzles; others join networks that turn code into cash. Intrinsic motives include the thrill of solving hard problems, the social credit of peer recognition, and pride in technical artisanship.

What fuels intrinsic interest?
Puzzle-solving and reputation often motivate sustained work. For many, the hook is craft—clean code that proves skill to peers.
How do extrinsic incentives change behavior?
Direct monetization—ransom payments, data sales—and low perceived risk online make attacks scalable. Cryptocurrency and marketplaces let groups cash out while obscuring attribution, increasing operational risk for targets.
When does malice become acceptable to creators?
Moral disengagement lets people reframe victims as faceless or blame careless users. Reputation markets reward proof of work and open doors to more profitable collaborations.
- Difference between hobbyists and organized groups: scale, intent, and tooling.
- Information asymmetries favor attackers; defenders often lack cross-system visibility.
Map motivations to targeting: quick-pay schemes hit broad targets; long-game campaigns harvest data quietly. Assess where these motives intersect with your people and processes to reduce exposure.
Skills, status, and identity: differences between virus writers and hackers
Skilled intruders and broad-impact coders have long belonged to different circles, but their tools now often overlap.Research shows historical divides in skill, ethics, and social status. Today that line is porous, changing how teams must defend systems.
How do their skillsets and mindsets differ?
Hackers traditionally valued deep system knowledge and careful exploration. They mapped systems, sought minimal footprints, and often debated responsible disclosure.
Virus writers focused on payload design and propagation. Their work prioritized spread and impact over subtle system navigation.

How do community norms shape tactics and status?
Communities prize different work: targeted intrusion often wins respect; indiscriminate spread attracts scorn. Yet commercialization and tech growth mean many actors now blend exploitation, payload coding, and operations.
- Security implication: defenders must prepare for precise compromises and noisy outbreaks that increase response risk.
- Research insight: discourse in underground forums signals shifting tolerances for damage and new attack techniques.
- Practical action: monitor underground trends and treat even low-skill signals as high risk when paired with social engineering.
virus, worm, or trojan comparison helps map artifacts to likely intent and informs prioritized controls.
Lifecycle and “aging out”: how creators evolve with experience
Many creators follow a predictable arc: early interest turns into skill, then life events and work demands reshape behavior.This shift matters because it changes the volume and style of attacks teams see.
Early years are driven by curiosity and quick feedback. Newcomers tinker on a personal computer and chase reputation in forums.
Peak activity often aligns with higher tolerance for risk. Quick wins and anonymity encourage bold releases. Over time, careers, relationships, and reputational concerns push many to slow down.

Frontline experience—seeing real victims or system impact—can trigger ethical re-evaluation. Many channel that experience into defensive work, strengthening system controls and policy.
- Community norms and mentorship either reinforce harm or guide ethical transitions.
- Not all exit: some escalate into organized operations where profit and perceived impunity sustain risk.
- Researchers should track lifecycle signals to anticipate changes in campaign volume and sophistication.
For security teams, these lifecycle insights inform recruitment and retention: hire for deep technical skill and offer clear, ethical career paths that turn risky interest into protective work.
Attack types that reveal mindset: phishing, malware, and ransomware
Attack types show intent: social engineering in email and web scams, coercive extortion in ransomware, and covert control with spyware and backdoors. These patterns tell defenders what to expect and where to focus controls.

How do phishing campaigns use email and web content to persuade?
Phishing relies on social cues: urgency, familiarity, and habit loops to trick people into sharing information or clicking links. Attackers craft email and web pages that mirror trusted services to lower suspicion.
Simple prompts and time pressure increase the chance people follow unsafe steps. Tailored training that mirrors real email and web cues reduces that risk best.
Why does ransomware use coercion to force payment?
Ransomware encrypts data and removes access. That loss creates time pressure and fear. The 151% rise in 2021 shows how profitable coercion has become.
Its design aims to shorten decision time and raise perceived cost of nonpayment. Rapid isolation and clear recovery options lower that leverage.
What do spyware, trojans, wipers, and backdoors reveal?
Spyware seeks silent access to information and credentials. Trojans hide payloads inside normal files. Wipers destroy systems and data. Backdoors provide long-term control.
Attackers pick types based on motive: fast cash, stealthy exfiltration, or sabotage. Blended attacks often start with phishing, then escalate to persistence or encryption.
| Type | Primary Goal | Defensive Focus |
|---|---|---|
| Phishing (email/web) | Credential theft, initial access | Clear warnings, safe defaults, targeted training |
| Ransomware | Monetization via encryption of data | Backups, rapid isolation, incident playbooks |
| Spyware / Backdoors | Surveillance, long-term control | Endpoint detection, least privilege, monitoring |
| Wipers / Trojans | Destruction or hidden payload delivery | Integrity checks, application allowlists, network segmentation |
Cascading attacks: how a single click becomes a multi-stage compromise
One click can start a staged intrusion: credentials fall, tools are installed, and attackers move laterally to steal or encrypt data. Speed and subtlety hide each step, so early user reports and tight telemetry are the best defenses.
One deceptive link can deliver credentials or a dropper. That initial access often looks minor to the user.
Next comes lateral movement across systems. Attackers probe trusts and privileges to reach valuable information and backup systems.
Later stages harvest data and may deploy coercive encryption. Each phase manipulates attention with plausible prompts and small distractions.
Report anomalies early. Pop-ups, odd mouse movement, or unexpected prompts can interrupt the chain before damage grows.
Good technology and strong design work together: behavior-informed prompts, least-privilege defaults, safe rollback, and segmented networks limit spread.
| Stage | User cue | Defender control | Telemetry signal |
|---|---|---|---|
| Lure / Click | Phishing email or fake page | Filtering, safe defaults, targeted training | Email click logs, URL reputation |
| Credential capture / Dropper | Login prompt or silent installer | Multi-factor auth, app allowlists | Failed logins, unusual processes |
| Lateral movement | Slow access to internal apps | Segmentation, least privilege | Cross-host authentication, anomalous traffic |
| Data theft / Ransom | Slow exfiltration or encryption | Backups, isolation, incident playbooks | Large outbound transfers, file changes |
Exercise these scenarios. Tabletop drills that rehearse multi-stage incidents improve coordination and user messaging. Update risk models to account for chained events, not just single vectors.
Attackers count on delayed recognition; defenders win by speeding awareness, reporting, and response. For deeper phishing tactics, see common phishing techniques.
Targeting human factors: cognition, behavior, perception, motivation, emotion
People make rapid choices under pressure; simple cues and habits steer those choices more than abstract warnings. This section explains how urgency, habit, and weak rare-signal detection raise organizational risk and what to change in design and training.
Human responses—fast choices, habits, and emotion—determine whether a deceptive message succeeds or fails.
How do urgency cues and habit loops change decisions?
Urgency cues narrow attention. Prompts like “urgent” or countdowns push individuals to act quickly and ignore verification steps.
Habit loops make clicking automatic. Repeated patterns teach fast responses that attackers exploit.
Why do rare signals go unnoticed?
When real attacks are rare, people lose practice spotting subtle signs. Fewer but more targeted phishing messages increase success by reducing noise.
“Specific cues beat general guidance: teach what to look for in a URL, not just ‘be careful.'”
What practical changes cut risky use without blocking productivity?
- Slow risky actions: add brief friction for high-impact clicks.
- Give targeted signals: show clear URL hints and trusted sender badges.
- Monitor respectfully: use anonymized micro-behavior signals for adaptive coaching.
Leaders should measure behavior change, not just training completion. Track click rates, report rates, and response times to see real reductions in risk.
| Problem | User cue | Design fix |
|---|---|---|
| Urgency prompts | Countdown text, urgent subject | Warning modals + verify option |
| Automatic clicking | Repeated button patterns | Delay + contextual label |
| Rare-signal blindness | Subtle phishing signs | Targeted examples in training |
Trust in technology and automation bias as risk multipliers
Automation speeds choices but can amplify risk when users over-rely on devices. Trust must match actual system performance, or design gaps convert helpful tools into liability.
Automation improves outcomes when it is reliable. Yet automation bias nudges users to accept system verdicts without checking available information.
What is the difference between propensity to trust and situational trust?
Propensity to trust is a stable, personal tendency to rely on technology. Situational trust is the confidence a user gives a system in a specific moment.
Design should surface evidence so situational trust tracks actual reliability.
How do complacency and out-of-the-loop problems increase risk?
When systems act for people, users lose practice. That out-of-the-loop unfamiliarity makes them slow to spot failures in a complex system.
Simple overrides become hard when routine decisions are automated and attention drifts.
What design fixes reduce mismatched trust?
- Expose confidence scores and short explanations for decisions.
- Offer clear next steps and an easy way to escalate to a human.
- Build feedback loops so user reports improve detection and system data.
“Framing matters: ‘This site shows signs of fraud’ prompts different behavior than a vague alarm.”
Research-driven testing should map where users over- or under-trust and refine messaging accordingly. Better design keeps people in the loop, lowers risk, and makes technology work as a true security partner.
Affective responses to attacks: arousal, emotional valence, and performance
How do feelings change what people do when security incidents appear? Emotional reactions — from mild annoyance to panic — shape immediate choices. Capture valence (pleasant–unpleasant) and arousal (calm–excited) to measure impact and guide better design.
From anxiety to annoyance: how emotions shape compliance
Anxiety often narrows attention and speeds decisions. That can make users skip verification steps and click risky links.
Annoyance reduces cooperation. Repeated pop-up prompts for updates create irritation and lower willingness to follow guidance.
- Design fix: use clear language, predictable steps, and reassurance to reduce negative affect.
- Timing: present urgent prompts only for true high-risk events; otherwise delay to calmer moments.
How does perceived risk differ across attack types?
Phishing usually triggers muted responses. People treat suspicious email as nuisance more than threat.
Ransomware evokes stronger arousal because it threatens money and control. This heightens panic and can worsen performance.
“Measure emotional impact with validated scales like the Self-Assessment Manikin to link feeling and behavior.”
Practical steps: collect privacy-conscious affect data, coach users to report and isolate, and craft support workflows for high-stress incidents. Prior experience with incidents colors future reactions—sometimes creating healthy caution, other times avoidance that hides real risk.
Knowledge and training: when security literacy changes behavior
Short, task-focused training that teaches URL reading and sender checks reduces clicks more than broad computer classes. Practical exercises and quick simulations create repeatable habits that show up in real email decisions.
What works? Teach people to scan URLs, verify sender addresses, and pause on odd prompts. Use short, spaced lessons and realistic simulations that mirror the messages staff actually receive.
Which knowledge matters most?
Specific phishing knowledge predicts lower susceptibility. General security lectures rarely change moment-of-decision behavior.
Train for the real cue, not the abstract rule. Show example emails and broken-down URLs. Run quick drills that reinforce these exact checks.
Can micro-behaviors guide supportive nudges?
Slow mouse movement often signals higher awareness. Hovering alone is not a reliable marker, but combined signals can trigger helpful tips.
- Use short nudges: show context-aware warnings when micro-behavior and URL risk align.
- Respect privacy: collect only anonymized signals and get consent.
- Measure outcomes: track click rates, report rates, and time-to-report to judge impact.
| Focus | Why it works | Metric |
|---|---|---|
| URL reading drills | Targets the exact decision cue in email | Click rate reduction |
| Short spaced simulations | Reinforces habit without overload | Report rate increase |
| Micro-behavior nudges | Provides timely, supportive help | Time-to-report decrease |
Technology helps. Inline tips and context-aware warnings assist individuals at the moment of risk. Blend multimodal content—video, micro-lessons, and hands-on drills—to fit varied learning styles.
“Measure behavior change, not seat time: real gains show in fewer successful attacks and lower organizational risk.”
Sociotechnical design: integrating psychology into secure systems
Good defenses treat people as part of the system, not as add-ons. Blend design, policy, and technology so users can make safer choices in context.
C. When teams fold human needs into technical planning, security becomes easier to use and harder to break.
How do we make users integral to security-by-design?
Start with real tasks: map common computer workflows and add humane controls where risk is highest.
Run iterative usability tests and measure behavior, not checkbox completion. Document decisions so teams can show how design reduced specific attacks and lowered risk.
How can policy become usable practice?
Translate GDPR-like mandates into clear consent flows, safe defaults, and transparent information handling. Cross-functional teams—engineering, UX, legal, and behavioral science—must align on feasible controls.
“Design that guides without alarming users wins trust and reduces costly errors.”
- Use contextual signals to show only what people need to act safely.
- Build safe degradation: clear roles and escalation paths when systems fail.
- Share playbooks so the community raises its baseline against common attacks.
Research frontiers: measuring and modeling human risk in cybersecurity
Decades of trust research guide new work that links behavior, affect, and system signals to real-world risk. Clear metrics, shared datasets, and models that map cues to choices can make defenses adaptive and testable.
What should research prioritize? Start by defining consistent terms and metrics so studies are comparable. Researchers must agree on labels for situational trust, susceptibility, and intervention impact. Shared language unlocks cumulative progress and clearer guidance for practitioners.
Build privacy-preserving, shared datasets that combine anonymous behavior, short affect measures, and contextual information. Those data let teams model how content cues and micro-behaviors predict clicks and reporting.
Modeling matters. Use approaches that link information cues—URLs, sender signals, time pressure—to user actions. That lets teams forecast which attacks will succeed and when to surface adaptive warnings.
| Priority | Goal | Deliverable |
|---|---|---|
| Common terms | Comparable findings | Glossary + measurement protocol |
| Shared datasets | Robust models | Privacy-first repositories |
| Modeling cues→action | Predict attack success | Actionable risk scores |
| Longitudinal studies | Durable change | Year-plus intervention trials |
Explore personalization cautiously. Tailored warnings and micro-training can reduce risk without causing fatigue, but they require validation and ethical guardrails. Passive behavioral signals show promise, yet their limits must be tested and explained.
Collaboration is essential. Invite industry partners to co-design experiments that reflect operational constraints. Open methods and replication will move findings from lab to large-scale protection. That is how research turns into technology that helps users at the moment of decision.
“Measure what matters: durable behavior change, not just immediate click drops.”
Implications for U.S. organizations and individuals
Small human mistakes often set the stage for large breaches that affect business operations and trust.This section explains what U.S. organizations and individuals should change now to lower everyday risk.
Prioritize people alongside tech. Strengthen technical controls, but pair them with clear, usable guidance so employees spot and report attacks. Align controls to how staff work on email, messaging, and browsers—the common way that threats arrive.
Make reporting easy. Build rapid reporting paths and recognition programs so individuals feel safe escalating concerns. Visible praise reduces hesitation and raises reporting rates.
What practical steps cut risk most quickly?
- Protect high-value data: minimize collection, segment systems, and enforce least privilege.
- Match controls to workflows: embed warnings in email and browser flows where attacks land.
- Support small organizations: give individuals and small businesses a short list of high-impact practices they can adopt without a security team.
Communicate transparently during incidents. Clear, timely messages restore trust and help people act correctly. Train non-technical staff with tabletop exercises—many first notice suspicious activity.
| Priority | Action | Outcome |
|---|---|---|
| Reporting & recognition | One-click report buttons; fast feedback loops | Faster containment; more reports |
| Data protection | Segment systems; limit data collection | Smaller blast radius; lower compliance risk |
| Work-aligned controls | Inline warnings in email/browser | Fewer successful attacks; better user compliance |
| Support for individuals | Simple, tailored guidance for small orgs | Improved baseline security for under-resourced groups |
Measure what matters. Track reduced successful attacks, faster containment, and increased report rates to guide ongoing investment. Treat compliance as a floor—not the goal—and build resilience that reflects how people actually use computer systems and handle information.
For evidence-based guidance on behavioral interventions, consult relevant behavioral research that links training to measurable outcomes.
Actionable recommendations for security leaders, designers, and policy makers
Practical changes in interface design and timely education stop many attacks before they spread.Make design and policy work together so people can act quickly and correctly when they see risk.
How should interfaces show trustworthiness and next steps?
Implement trust calibration: show confidence scores, clear evidence, and an obvious next action. Labels like “Verified sender” or a short reason reduce guesswork.
What just-in-time education should live inside email and web flows?
Deliver micro-lessons that surface real cues—URL fragments, sender inconsistencies, or unexpected attachments. Keep content plain, example-driven, and action-oriented.
How to validate and audit with real users?
Test with representative staff under time pressure. Observe behavior, not just stated understanding. Run audits that check warnings, recovery steps, and reporting paths for clarity and speed.
- Adaptive controls: add friction for high-risk actions, keep low-risk flows smooth.
- Easy reporting: one-click “report suspicious” in email clients and system trays.
- Post-incident learning: share short stories that show what changed and why.
- Policy alignment: rewrite terms into plain steps that show what users must do.
- Continuous measurement: track click rates, report speed, and fewer successful attacks and iterate.
“Design that gives clear evidence and a next step turns uncertainty into a report, not a mistake.”
| Recommendation | Why it matters | Immediate action | Success metric |
|---|---|---|---|
| Trust calibration UI | Aligns situational trust with real system reliability | Show confidence + short rationale on prompts | Report rate ↑; false-accepts ↓ |
| Just-in-time micro-lessons | Teaches exact cues at the moment of decision | Inline tips in email and web flows | Click rate ↓; time-to-report ↓ |
| Real-user validation | Ensures features work under pressure | Timed usability tests with representative users | Task success ↑; confusion incidents ↓ |
| Adaptive friction | Stops high-impact attacks with minimal productivity hit | Risk-based delays or confirmations | High-risk action blocks ↑; user complaints stable |
Start small and measure. Pilot a trust-calibrated prompt in email, run a two-week micro-lesson campaign, then expand based on data. That iterative path reduces risk and builds user confidence in security technology.
Conclusion
When we map motives to methods, defenses become more precise and less costly. Understanding human drivers and observable patterns gives teams clear actions that reduce real-world risk.
Core insight: study of who attacks and why shows that motives, skill levels, and group norms predict which attacks succeed and where to focus controls.
Good cybersecurity pairs thoughtful technology with user-centered design and specific training. Start with trust calibration, targeted micro-lessons, and safer defaults in common computer flows.
Measure results: track fewer successful attacks and faster reports to confirm progress. Share near-misses to improve systems, not blame people.
Keep testing; blend field research and design work. That collaborative, people-first way gives defenders a durable advantage and a pragmatic path to lower risk. For related behavioral findings, see this review of human factors and security.