{{Computer hacking}} {{redirects|Bad actor|the 2023 Mexican film|Bad Actor (film)}} {{short description|Cybersecurity term}} In cybersecurity and risk assessment, a '''threat actor''' (or ''threat agents'', ''attackers'', or ''adversaries''<ref name=":0">{{cite book |last1=Rausand |first1=Marvin |last2=Haugen |first2=Stein |title=Risk Assessment: Theory, Methods, and Applications |edition=2nd |publisher=John Wiley & Sons |year=2020 |isbn=978-1-119-37723-8 |page=611}}</ref>) is a person, group, organisation, state, or other entity with the ability to cause, carry, transmit, support, or exploit a threat.<ref name=":0" /><ref name=":032">{{Cite web |title=Cybersecurity Spotlight - Cyber Threat Actors |url=https://www.cisecurity.org/spotlight/cybersecurity-spotlight-cyber-threat-actors/ |access-date=2021-11-13 |website=CIS |language=en-US}}</ref>

Threat actors are commonly analysed according to their motivations, resources, technical capability, access to systems, relationship to a target, and degree of connection to state authority. They may exploit vulnerabilities, conduct social engineering, steal or monetise data, disrupt operations, or support other actors who carry out such activity.<ref name=":222">{{Cite journal |last1=Pawlicka |first1=Aleksandra |last2=Choraś |first2=Michał |last3=Pawlicki |first3=Marek |date=2021-10-01 |title=The stray sheep of cyberspace a.k.a. the actors who claim they break the law for the greater good |journal=Personal and Ubiquitous Computing |language=en |volume=25 |issue=5 |pages=843–852 |doi=10.1007/s00779-021-01568-7 |issn=1617-4917 |s2cid=236585163 |doi-access=free}}</ref><ref>{{Cite web |last=Ablon |first=Lillian |title=Data Thieves - The Motivations of Cyber Threat Actors and Their Use and Monetization of Stolen Data |url=https://www.rand.org/content/dam/rand/pubs/testimonies/CT400/CT490/RAND_CT490.pdf |website=www.rand.org}}</ref> Because the term covers a wide range of actors, researchers and security organisations use taxonomies that distinguish between groups such as cybercriminals, state-linked actors, ideologically motivated actors, thrill seekers or trolls, insiders, and competitors.<ref name=":13">{{Cite journal |last=Chng |first=Samuel |last2=Lu |first2=Han Yu |last3=Kumar |first3=Ayush |last4=Yau |first4=David |date=2022-03-01 |title=Hacker types, motivations and strategies: A comprehensive framework |url=https://www.sciencedirect.com/science/article/pii/S245195882200001X |journal=Computers in Human Behavior Reports |volume=5 |article-number=100167 |doi=10.1016/j.chbr.2022.100167 |issn=2451-9588}}</ref>

Threat actor classifications are used in risk management, cyber threat intelligence, and incident response to connect observed behaviour with possible objectives and likely future activity. The categories are not always mutually exclusive: the same actor may combine criminal, ideological, commercial, or state-linked motivations, and different organisations may use different names for similar actors.

== Risk assessment and security management == In risk assessment, threat actor analysis is used to identify who or what may create, carry, transmit, support, or exploit a threat, and how that actor relates to the system being assessed. Rausand and Haugen classify threat actors by their relationship to the system, distinguishing between internal and external actors, and by intent, distinguishing between intentional and unintentional actors.<ref name=":0" /> Threat actor classification may also support incident investigation. Rogers argued that actor categories could be inferred from observable case points, such as tools used, messages left, data targeted, forensic knowledge, and the degree of damage, allowing investigators to assess likely motivation and skill level.<ref name="Rogers20062">{{cite journal |last=Rogers |first=Marcus K. |year=2006 |title=A two-dimensional circumplex approach to the development of a hacker taxonomy |journal=Digital Investigation |volume=3 |issue=2 |pages=97–102 |doi=10.1016/j.diin.2006.03.001}}</ref>

Later work similarly linked actor classification to operational analysis. Chng, Lu, Kumar and Yau proposed a framework connecting hacker types, motivations and typical strategies, arguing that observed behaviour before or during an attack can help analysts infer the likely type of actor involved.<ref name=":13" />

At the strategic level, actor analysis may consider an actor's resources, capabilities, degree of state involvement, motivations and objectives.<ref name="UNIDIR20263">{{cite report |url=https://unidir.org/wp-content/uploads/2026/02/UNIDIR_Insights_into_Cyberthreats_and_International_Security_in_2025.pdf |title=Securing Cyberspace for Peace: Insights into Cyberthreats and International Security in 2025 |author=UNIDIR Security and Technology Programme |date=2026 |publisher=United Nations Institute for Disarmament Research |location=Geneva}}</ref>

== Landscape == The United Nations Institute for Disarmament Research has described the contemporary cyberthreat landscape as involving an increasingly diverse and interconnected set of actors, including state-led operations, cybercriminal syndicates, ideological hacktivists, commercial cyber mercenaries, private companies and civilian volunteers. Its 2026 report argued that these actors vary in resources, technical sophistication and relationships with states, making it traditional distinctions between state, civilian combatant roles, and legitimate and illegitimate conduct harder to apply.<ref name="UNIDIR20263" />

== Academic taxonomies == Early taxonomies classified hackers by activity, skill, motivation, or criminal profile. Landreth proposed six categories based on activity: novice, student, tourist, crasher, and thief.<ref name=":2" /> Hollinger classified computer misuse into pirates, browsers, and crackers, describing a progression from less-skilled activity to more technically serious offences.<ref name=":2" /> Chantler used attributes including activity, skill, knowledge, motivation, and duration of involvement to distinguish between an elite group, neophytes, and "losers and lamers".<ref name=":2" /> Parker proposed seven profiles of cybercriminals: pranksters, hacksters, malicious hackers, personal problem solvers, career criminals, extreme advocates, and malcontents, addicts, and irrational or incompetent people.<ref name=":2" />

[[File:TechCrunch_Disrupt_San_Francisco_2018_-_day_2_(43798654394).jpg|thumb|Marc Rogers, an influential figure in the taxonomy of threat actors at TechCrunch Disrupt in 2018]] In 2000, Marc Rogers proposed a taxonomy of hackers with seven, non-mutually-exclusive categories: newbie/tool kit users, cyber-punks, internals, coders, old guard hackers, professional criminals, and cyber-terrorists.<ref name=":2">{{cite journal |last=Rogers |first=Marc |year=2000 |title=A new hacker taxonomy |journal=University of Manitoba |page=8}}</ref>

Rausand and Haugen distinguish between internal and external threat actors, and between intentional and unintentional threat actors. Internal actors have some relationship with, access to, or position inside the system or organisation, while external actors operate from outside it. Intentional actors seek to create, exploit, or support a threat event, whereas unintentional actors may cause or enable a threat event through error, negligence, accident, or lack of awareness.<ref name=":0" />

Rogers later revised his hacker taxonomy into Novices, Cyber-punks, Internals, Petty Thieves, Virus Writers, Old Guard hackers, Professional Criminals, Information Warriors, and, more tentatively, Political Activists. In the model, motivation is grouped into four broad domains: curiosity, notoriety, revenge, and financial gain.<ref name="Rogers2006">{{cite journal |last=Rogers |first=Marcus K. |year=2006 |title=A two-dimensional circumplex approach to the development of a hacker taxonomy |journal=Digital Investigation |volume=3 |issue=2 |pages=97–102 |doi=10.1016/j.diin.2006.03.001}}</ref>

A 2022 review by Chng, Lu, Kumar and Yau examined 11 hacker typologies published over three decades and proposed a unified framework linking hacker types, motivations, and strategies. The framework identified 13 hacker types and seven motivations, and argued that observed strategies during an attack can help analysts infer the likely type of actor involved.<ref name="Chng2022">{{cite journal |last1=Chng |first1=Samuel |last2=Lu |first2=Han Yu |last3=Kumar |first3=Ayush |last4=Yau |first4=David |year=2022 |title=Hacker types, motivations and strategies: A comprehensive framework |journal=Computers in Human Behavior Reports |volume=5 |article-number=100167 |doi=10.1016/j.chbr.2022.100167 |doi-access=free}}</ref>

== Government taxonomies == Taxonomies of threat actors by governments are much more likely to include state-level threat actors.

In the United States the National Institute of Standards and Technology (NIST) uses the term ''threat source'' in its risk-assessment guidance: organisations are directed to identify and characterise threat sources of concern, including capability, intent and targeting for adversarial threat sources, and the range of effects for non-adversarial threat sources.<ref name="NIST80030">{{cite report |title=Guide for Conducting Risk Assessments |author=Joint Task Force Transformation Initiative |date=September 2012 |publisher=National Institute of Standards and Technology |doi=10.6028/NIST.SP.800-30r1 |id=NIST Special Publication 800-30 Revision 1 |doi-access=free}}</ref> NIST treats threat-source identification as part of the risk-assessment process, alongside identifying threat events, vulnerabilities, likelihood and impact.<ref name="NIST80030" />

In the EU, European Union Agency for Cybersecurity publishes the annual ''ENISA Threat Landscape'', which analyses cyber incidents and adversary behaviour affecting the European Union. The 2025 report analysed selected incidents from the previous year and grouped activity around cybercrime, state-aligned activity, foreign information manipulation and interference, and hacktivism.<ref name=":3">{{Cite web |date=2025-11-06 |title=ENISA Threat Landscape 2025 {{!}} ENISA |url=https://www.enisa.europa.eu/publications/enisa-threat-landscape-2025 |access-date=2026-05-26 |website=www.enisa.europa.eu |language=en}}</ref>

In ENISA's 2025 analysis, hacktivist activity dominated reporting, representing almost 80% of recorded incidents and consisting mainly of low-level distributed denial-of-service operations.<ref name=":3" /> ENISA also reported increasing convergence between hacktivism, cybercrime and state-nexus activity, including state-aligned use of hacktivist personas, hacktivist adoption of ransomware, and false-flag or impersonation activity.<ref name=":3" />

At the UN level, A 2026 report by the United Nations Institute for Disarmament Research described the cyberthreat landscape as involving state-led operations, cybercriminal syndicates, ideological hacktivists, commercial cyber mercenaries, and civilian volunteers, with actors varying in resources, technical sophistication, and links to states.<ref name="UNIDIR2026">{{cite report |author=UNIDIR Security and Technology Programme |date=2026 |title=Securing Cyberspace for Peace: Insights into Cyberthreats and International Security in 2025 |publisher=United Nations Institute for Disarmament Research |location=Geneva |url=https://unidir.org/wp-content/uploads/2026/02/UNIDIR_Insights_into_Cyberthreats_and_International_Security_in_2025.pdf}}</ref>

Canada defines threat actors as states, groups, or individuals who aim to cause harm by exploiting a vulnerability with malicious intent. A threat actor must be trying to gain access to information systems to access or alter data, devices, systems, or networks.<ref>{{Cite web|last=Security|first=Canadian Centre for Cyber|date=2018-08-15|title=Canadian Centre for Cyber Security|url=https://cyber.gc.ca/en/guidance/cyber-threat-and-cyber-threat-actors|access-date=2021-12-07|website=Canadian Centre for Cyber Security}}</ref>

The Japanese government's National Centre of Incident Readiness and Strategy (NISC) was established in 2015 to create a "free, fair and secure cyberspace" in Japan.<ref>{{Cite web|title=National Centre of Incident Readiness & Strategy for Cybersecurity (NISC) Japan|url=https://www.cybersecurityintelligence.com/national-centre-of-incident-readiness-and-strategy-for-cybersecurity-nisc-japan-1972.html|access-date=2021-12-07|website=www.cybersecurityintelligence.com|language=en}}</ref> The NICS created a cybersecurity strategy in 2018 that outlines nation-states and cybercrime to be some of the most key threats.<ref name=":6">{{Cite web|title=National center of Incident readiness and Strategy for Cybersecurity {{!}} NISC|url=https://www.nisc.go.jp/eng/index.html|access-date=2021-12-07|website=www.nisc.go.jp}}</ref> It also indicates that terrorist usage of the cyberspace needs to be monitored and understood.<ref name=":6" />

The Security Council of the Russian Federation published the cyber security strategy doctrine in 2016.<ref name=":7">{{Cite web|title=Совет Безопасности Российской Федерации|url=http://www.scrf.gov.ru/security/information/DIB_engl/|access-date=2021-12-07|website=www.scrf.gov.ru}}</ref> This strategy highlights the following threat actors as a risk to cyber security measures: nation-state actors, cyber criminals, and terrorists.<ref name=":12">{{Cite journal|title=Cyber Threat Actors for the Factory of the Future|url=https://www.researchgate.net/publication/342426828|journal= Applied Sciences|year=2020|language=en|doi=10.3390/app10124334|doi-access=free|last1=Sailio|first1=Mirko|last2=Latvala|first2=Outi-Marja|last3=Szanto|first3=Alexander|volume=10|issue=12|page=4334}}</ref><ref name=":7" /> thumb|A fictional example of a phishing email, one common initial access method used by different types of threat actor.

== Techniques == {{Main|Computer security}} Threat actors use techniques like Social engineering (security), and Phishing, alongside technical exploits like Cross-site scripting, SQL injection, and denial-of-service attacks.<ref>{{cite journal |last1=Bahrami |first1=Pooneh Nikkhah |last2=Dehghantanha |first2=Ali |last3=Dargahi |first3=Tooska |last4=Parizi |first4=Reza M. |last5=Javadi |first5=Hamid H. S. |year=2019 |title=Cyber Kill Chain-Based Taxonomy of Advanced Persistent Threat Actors: Analogy of Tactics, Techniques, and Procedures |journal=Journal of Information Processing Systems |volume=15 |issue=4}}</ref>

== Limitations == In practice, actor categories may overlap (Edward Snowden for example), and the same activity may combine features associated with hacktivism, cybercrime and state-linked operations. The lines between hacktivism, cybercrime and state-nexus activity had continued to blur, with shared toolsets, overlapping methods, fake personas, hacktivist adoption of ransomware, and cybercriminal or state-linked actors masquerading as other groups.<ref name=":3" /> thumb|Edward Snowden has been discussed both as a whistleblower and as an insider-threat case. Threat actor analysis also has limits as a risk-management method. NIST notes that risk assessments depend on their purpose, scope, assumptions, constraints, information sources, risk model and analytic approach, and that assessments are tied to particular time frames and organisational contexts.<ref name="NIST80030" /> NIST also warns that simple threat-vulnerability pairing may be undesirable or problematic where there are many threats and vulnerabilities, and recommends using risk scenarios to address some of those limitations.<ref name="NIST80030" />

==References== <references /> Category:Computer security Category:Cybercrime Category:Information sensitivity Category:Risk management Category:Security