Know Your Adversary: A Realistic Map of Who Is Actually Targeting You Online — and Who Isn't
Open any major technology publication on a given morning and you are likely to encounter a story about a devastating state-sponsored cyberattack, a ransomware gang crippling hospital networks, or an AI-powered intrusion tool that can defeat any defense. These stories are real. They are also, for the overwhelming majority of American internet users, a profoundly misleading guide to personal risk.
Cybersecurity threat intelligence is built on a concept called the adversarial model — a structured way of identifying who might target a specific person or organization, what capabilities that adversary possesses, and what they are actually motivated to do. Without this framework, security advice becomes noise: either catastrophically overstated or dangerously dismissive.
What follows is a data-informed breakdown of the five tiers of cyber adversaries active in 2024, calibrated to the realistic risk profile of an ordinary American.
Tier One: Opportunistic Scammers and Script Kiddies
The vast majority of individuals who will ever attempt to compromise your accounts or devices occupy this lowest tier. These are not sophisticated operators. They are, in many cases, teenagers running pre-built exploit toolkits they downloaded from forums, or overseas scammers working from call centers with scripts designed to manipulate rather than technically infiltrate.
Their defining characteristic is that they do not target you specifically. They target everyone. Phishing emails sent to millions of addresses, automated credential-stuffing attacks against leaked username-and-password combinations, robocall scams impersonating the IRS or Social Security Administration — these are volume operations. Their success rate per attempt is tiny, but the sheer scale makes them statistically significant.
According to the FBI's Internet Crime Complaint Center (IC3), Americans reported losses exceeding $12.5 billion to internet crime in 2023, with phishing and personal data breaches representing the most frequently reported categories. The perpetrators behind the majority of those incidents were not elite hackers. They were opportunists exploiting human inattention and reused passwords.
What you actually need to worry about: This tier represents your most realistic everyday threat. Strong, unique credentials, phishing awareness, and multi-factor authentication neutralize the vast majority of Tier One attacks.
Tier Two: Financially Motivated Cybercriminals
One step above opportunistic scammers are organized cybercriminal groups with genuine technical competence. These actors — many operating out of Eastern Europe, West Africa, and Southeast Asia — run what security researchers describe as "business-like" operations, complete with customer service portals, affiliate programs, and internal HR functions.
Their primary targets are not individual consumers. They pursue small and medium-sized businesses, healthcare organizations, local government entities, and any institution holding data that can be monetized — either through ransomware demands or by selling records on illicit marketplaces. When they do target individuals, it tends to be high-value individuals: executives, attorneys, real estate transaction participants, and people known to hold significant cryptocurrency.
The 2023 Verizon Data Breach Investigations Report found that financially motivated actors accounted for approximately 95 percent of confirmed breaches. However, the same report noted that large-scale attacks on enterprise targets — not individual consumers — represented the dominant pattern.
What you actually need to worry about: If you run a small business, manage financial transactions, or hold significant digital assets, this tier warrants genuine attention. For average consumers, the risk is real but largely mitigated by the same foundational practices that defeat Tier One actors.
Tier Three: Hacktivists and Ideologically Motivated Groups
This tier is perhaps the most contextually variable. Hacktivist collectives — groups motivated by political, social, or ideological objectives rather than financial gain — have historically targeted governments, corporations, law enforcement agencies, and public figures. Their tactics range from website defacement and distributed denial-of-service (DDoS) attacks to the public release of sensitive internal documents.
Ordinary Americans are rarely in the crosshairs of hacktivist operations. The exception is when an individual becomes publicly associated with a cause or institution that a group has targeted — a local politician, a corporate spokesperson, or a prominent social media figure. In those cases, the threat is real but typically manifests as harassment, doxxing, or account takeover rather than sophisticated technical intrusion.
What you actually need to worry about: Unless your professional or public profile places you adjacent to a politically contentious institution or issue, this tier is largely background noise for most US consumers.
Tier Four: Sophisticated Criminal Organizations and Ransomware Syndicates
At this level, the adversaries possess capabilities that genuinely rival those of nation-state intelligence services. Groups such as LockBit, ALPHV/BlackCat, and Cl0p — all of which faced significant law enforcement pressure in 2023 and 2024 — operate with technical depth, geopolitical awareness, and organizational resilience that makes them formidable opponents for even well-resourced defenders.
Their targets are almost exclusively institutional: hospitals, critical infrastructure operators, major corporations, and government contractors. The motivations are financial, but the scale of potential harm is systemic. The 2023 MOVEit vulnerability exploitation by the Cl0p group, which affected hundreds of organizations globally, illustrated how Tier Four actors can generate massive collateral exposure even when individual consumers are not directly targeted — your personal data held by a vendor or healthcare provider can be compromised without you ever being the intended victim.
What you actually need to worry about: You are unlikely to be directly targeted by this tier. Your indirect exposure — through organizations that hold your data — is real. Monitoring your credit, using breach notification services, and understanding your rights under state privacy laws (many US states now have comprehensive data privacy legislation) are the proportional responses here.
Tier Five: Nation-State Actors and Advanced Persistent Threats
At the apex of the threat landscape sit the intelligence services and military cyber units of nation-states. Groups attributed to China (APT41, Volt Typhoon), Russia (Sandworm, Cozy Bear), North Korea (Lazarus Group), and Iran (APT33) represent the most technically capable adversaries in the world. They conduct long-term espionage campaigns, pre-position access in critical infrastructure, and execute operations aligned with geopolitical objectives.
For the overwhelming majority of Americans, these actors are entirely irrelevant to personal security. Nation-state operators do not waste sophisticated, expensive capabilities on private citizens with no intelligence value. Their targets are government employees with security clearances, defense contractors, critical infrastructure operators, dissidents, journalists covering sensitive geopolitical topics, and high-value corporate targets holding intellectual property of strategic interest.
If you are a federal employee, a defense industry professional, a political operative, or a journalist covering national security topics, this tier warrants a fundamentally different security posture — one that includes device compartmentalization, operational security practices, and potentially consultation with professional security advisors. For everyone else, the honest assessment is that Tier Five is not your threat model.
What you actually need to worry about: Essentially nothing, unless your professional context places you in one of the high-value categories described above.
Building a Proportional Defense
The most useful insight this framework offers is not that cybersecurity threats are exaggerated — they are not — but that the threats relevant to your life are almost certainly concentrated in Tiers One and Two. This is actually good news. Those tiers are also the most readily defeated by accessible, low-cost practices.
Unique credentials managed through a reputable password manager, multi-factor authentication on high-value accounts, phishing awareness, and timely software updates address the realistic threat profile of the vast majority of American consumers with a high degree of effectiveness.
Panic-driven security spending and behavior change calibrated to Tier Five threats make no practical sense for someone whose actual adversary is a credential-stuffing script running in a data center in Eastern Europe. Understanding the landscape is not an academic exercise — it is the foundation of a security strategy that is both effective and sustainable.
Know your adversary. Defend accordingly.