Threat actor
Any person or group with the intent and capability to attack: organized crime, state groups, hacktivists or insiders. Knowing them orders your defense.
Full definition
A threat actor is any person or group with the intent and capability to carry out malicious activity against systems, data or people. The term spans organized crime with economic goals, state-sponsored groups, hacktivists, opportunists and insiders with legitimate access.
Classifying them matters because each type attacks differently: criminal groups seek fast returns through ransomware and fraud; state actors pursue persistent, stealthy espionage; insiders are already inside and need no phishing. The actor's motivation and resources determine which defenses take priority.
For most midsize companies, the relevant actor is not the most sophisticated but the most frequent: criminal operators who industrialized the deception of people because it is the cheapest, most repeatable way in.
Related terms
Social engineering
Psychological manipulation that leads a person to hand over information, access or money. It is the starting point of most successful cyberattacks.
Ransomware
Malware that encrypts the victim's data and demands payment to release it. It now adds the threat of publishing what was stolen if no payment is made.
Attack surface
The set of points where an attacker can try to get in: exposed systems, accounts, vendors and, above all, people.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.