The Psychology of Cybercriminals: What Really Drives an Attacker
We tend to talk about security as a technical subject, all firewalls and encryption and exploits. But behind every attack is a person. That person has motives, makes decisions, tells themselves a story about why what they are doing is acceptable, and, crucially, understands your psychology well enough to manipulate it. For anyone learning offensive security, this is not a soft topic to skim past on the way to the technical material. It is the technical material, because a huge share of real intrusions succeed through people rather than through code.
I find this the most fascinating and most underrated part of the whole field. You can patch every server and still be undone by an attacker who understands human nature better than your staff do. On authorised engagements I have watched a well crafted pretext walk straight past defences that cost a fortune to build. So let me take you inside the mind on the other side of the attack, what drives cybercriminals, how they live with what they do, and how they weaponise psychology against the rest of us. Understanding this makes you a sharper tester and a far harder target.
What actually drives them
Strip away the drama and cybercriminal motives fall into a handful of categories. Knowing which one you are facing changes almost everything about how you defend, because different motives produce completely different behaviour.
Money is the big one, by a wide margin. Ransomware, banking fraud, stealing data to sell, business email compromise. Cybercrime grew into a fully formed economy, complete with its own service providers, support desks, and reputation systems. Most attackers are not ideologues or thrill seekers. They are running a business, and they apply a cold cost benefit calculation to every target. That matters, because a financially motivated attacker abandons a target that becomes too expensive to bother with, which is the whole logic behind raising the cost of attacking you.
Ideology drives a different group. Hacktivists attack to make a political or social point, defacing sites, leaking documents, disrupting organisations they oppose, and their target selection follows their cause rather than the money. Espionage drives state backed actors, who steal secrets such as intellectual property, government intelligence, or strategic data, and who are patient, well resourced, and often willing to sit undetected inside a network for months. Revenge drives the disgruntled insider or former employee, and these are dangerous precisely because they already have knowledge and often access, with emotion rather than profit steering them, which makes them unpredictable. And a smaller group is driven by ego and curiosity, attacking for the challenge and the status, where the win is simply proving it could be done.
Reading the motive tells you how someone will behave. A criminal chasing money gives up when you make yourself unprofitable. An ideologue or a vengeful insider may not give up at all.
How they live with it, the psychology of justification
Here is what unsettles people when they first really think about it. Most cybercriminals are not cartoon villains. They are ordinary people who have found ways to make serious harm feel acceptable, and the main mechanism is moral distance.
When you rob someone in person, you see their face. When you drain their account through a screen from another continent, you never see them at all. That distance strips away the emotional weight of the act, and the victim becomes an abstraction, an IP address, a balance, a target, rather than a human being. On top of that distance, attackers build rationalisations that do the rest of the work. The company is huge, they can afford it. They should have secured it properly, so really I am teaching them a lesson. I am not hurting anyone, it is only data. Everyone does this, it is just how the game works.
These stories let otherwise normal people cross lines they would never cross face to face. I raise this not to excuse anyone, but because recognising it is genuinely useful. The barrier between an ordinary person and a cybercriminal is often psychological rather than technical, and removing anonymity and consequence is a large part of what makes cybercrime attractive in the first place. Defenders who understand this design their controls, and their culture, with that human reality in mind.
The real skill is psychological, not technical
The popular image of the attacker as a coding genius is mostly wrong, and clinging to it makes you a worse defender. A great deal of cybercrime relies on bought tools and ready made kits. The real expertise, for the most effective attackers, is in understanding people.
Social engineering, the craft of manipulating people into giving up access or information, sits behind an enormous share of real breaches. It works because it targets instincts that are universal rather than weaknesses that are rare. Authority is one of the strongest. We are conditioned to comply with people who seem to be in charge, so an email that appears to come from the chief executive, or a caller claiming to be from IT support, borrows that authority and bends the target toward compliance. Urgency is another. Pressure short circuits careful thinking, which is why a message warning that your account will be closed within the hour is engineered to make you act before you reason. Fear works the same way, because a threat of legal trouble or a security breach triggers panic, and panicked people click. Trust and reciprocity get exploited constantly, since we trust familiar brands, colleagues, and anyone who has just done us a small favour. And the simple desire to be helpful, one of our better instincts, gets turned into a weapon by an attacker who asks politely for just a small favour.
None of these are signs of a foolish victim. They are the same traits that make people functional, cooperative, and kind. The skilled attacker is essentially an applied psychologist, and the hack often lives entirely in the manipulation, with the technology as a footnote. This is why, on the offensive side, reconnaissance matters so much. A convincing pretext is built from details, and the same open source intelligence mindset behind reconnaissance and subdomain enumeration is what lets a social engineer learn enough about a target to sound like they belong. And once a pretext harvests a password, the attacker still needs it to work, which is exactly why credential attacks like those in my password cracking with Hydra guide and interception techniques like password sniffing fit into the same playbook. Psychology opens the door, and the technical tools walk through it.
Turning the tables, psychology as defence
The encouraging flip side of all this is that understanding the tactics is itself a defence. Manipulation loses much of its power the moment you can name it as it is happening, and that is a skill you can teach.
When an email manufactures urgency, that pressure is itself the warning sign, because legitimate requests rarely demand action in the next five minutes. When someone leans on authority, the right move is to verify through a separate, known channel rather than replying to the message that made the claim. When something triggers fear, that is precisely the moment to slow down, because fear is exactly what the attacker is counting on to stop you thinking clearly.
This is why good security awareness training works, and it is not because it teaches people obscure technical facts. It works because it teaches them to recognise the emotional levers being pulled, converting an automatic reaction into a deliberate pause. That pause is frequently all it takes to break the attack. On the offensive side, running authorised phishing simulations and social engineering assessments is how organisations find out where those levers still work, and it is some of the most valuable testing a red team can do, precisely because it exercises the layer that technology cannot patch.
The cognitive shortcuts attackers lean on
It is worth going a little deeper into why these tactics work, because the reasons are baked into how human minds handle a busy world, and once you see them you cannot unsee them in a phishing email.
People run on mental shortcuts. We have to, because nobody has the time to reason from scratch about every message, request, and decision that lands in front of them during a working day. Those shortcuts are usually helpful, but each one is a lever an attacker can pull. The authority shortcut says that if someone appears senior or official, we should probably just do what they ask, which is why a message that looks like it came from a chief executive gets acted on far faster than one from a stranger. The scarcity and urgency shortcut says that if something is about to run out or a deadline is about to pass, we should act now and think later, which is why so much phishing invents a ticking clock. The social proof shortcut says that if everyone else is doing something, it is probably fine, which is why an attacker will claim that a colleague has already approved the request. And the liking shortcut says we do favours for people we find agreeable, which is why a friendly, warm approach disarms us more effectively than a demanding one.
None of these make someone stupid. They make someone human, and they are running in all of us all the time, usually below conscious awareness. The uncomfortable truth is that the busier, more stressed, and more distracted a person is, the more heavily they rely on these shortcuts, which is exactly why attackers time their approaches for a Friday afternoon or the chaos of a Monday morning. A tired person at the end of a long week is not thinking carefully. They are pattern matching, and a good pretext gives them a comfortable pattern to match.
For a red teamer, understanding this is the difference between a phishing email that gets reported and one that gets clicked. The most effective authorised social engineering does not rely on a clever technical trick. It relies on presenting the target with a situation their mental shortcuts will happily resolve in the attacker’s favour, and it does so at the moment those shortcuts are working hardest. Defenders counter it not by demanding that people stop using shortcuts, which is impossible, but by building habits and processes that force a deliberate pause at the exact points where the shortcuts are most dangerous, such as verifying any payment change through a second channel no matter who seems to be asking.
Why this belongs in every hacker’s toolkit
We pour resources into technical defences and often neglect the human layer, even though the human layer is where most attacks actually land. Understanding the psychology of cybercriminals does two things at once. It demystifies the attacker, replacing the genius hacker fantasy with a more accurate and more useful picture, and it makes you alert to the manipulation aimed at you and the people around you.
The most secure organisations grasp that security is not only a technology problem. It is a human one. The attacker knows this already, because it is the core of their craft. The testers and defenders who internalise it too are the ones who are genuinely hard to fool, and if you are serious about offensive security, this is a part of the discipline worth studying as carefully as any exploit.
So read widely outside the purely technical material. Study how persuasion works, how con artists operate, how ordinary people make decisions under pressure, because every one of those subjects feeds directly into both attacking and defending the human layer. The best social engineers I have met are curious about people in a way that has nothing to do with computers, and that curiosity is what makes their pretexts land. The exploit gets you a foothold. Understanding people is what gets you through the front door in the first place.
This article is for education and defence, to help you understand attackers and resist manipulation, never to carry any of it out. The best defence combines strong technical controls with people who recognise social engineering when they see it. Any social engineering testing must be properly scoped and authorised in writing.