The journey of an unethical hacker is rarely just a story of someone advancing their knowledge and technical skills. Rather, it’s more like a rewiring of their brain. What starts as a person receiving a dopamine hit in their room from accidentally hacking an insecure website sometimes becomes a person who, despite being aware of morals and ethics, begins to knowingly and actively engage in attacks against a person or company. Why does this happen? How does this happen?
To understand how someone goes from a hobbyist to a legitimate threat actor,, we must look at and attempt to understand the mind of the attacker. By analyzing real-world threat intelligence, criminological theory, and a little bit of forensic psychology, we can map out how a hacker’s motivations, ego, and moral justifications can change and evolve as they climb the skills ladder, ending on top of a cybercrime empire.
The Hacker Taxonomy: Three Phases of Psychological Change
Phase 1: The Script Kiddie
If you’ve never heard of a “script kiddie” this is an informal term in the hacking community that is used to describe someone who is not necessarily highly skilled. In the context of a malicious attacker, this person, despite not having a strong skillset, manages to successfully use malicious programs or scripts written by others to carry out their cyberattacks against innocent victims. This person tends to be someone who lacks the deep technical capability to fully understand the underlying mechanics of the attack. Many of these individuals heavily rely on resources they see on platforms such as GitHub, and blindly follow the installation of recommended tools, run instructions on the read me, and then get a good dopamine hit when they see that it works. This was not successful because this person is good at hacking, or even necessarily that they are good at following instructions. Rather, the install and run instructions were high quality and well written or easy to follow, which led the novice down a path to success.
In the early stages, this type of attacker is often driven by a mix of immediate rewards and social reinforcement. Social reinforcements for any type of criminal activity could come from a variety of areas, the most popular of which are places in which delinquent subculture could exist. In the context of hacking, it leads researchers to point to internet forums and chatrooms, social gatherings, or social media.
These main motivations could include:
In order to engage in this type of activity, the attacker needs to make some kind of psychological justification to themselves, allowing themselves to not feel guilt or remorse for their actions. They will work to convince themselves that what they are doing is not truly hurting anyone. In criminology, this is referred to as Techniques of Neutralization. This is a phenomenon where someone rationalizes their behavior to temporarily suspend their personal moral constraints and violate laws or social norms. The framework identifies five cognitive mechanisms one can use to achieve navigating the justification of unethical behavior.
In the U.S., the legal system has long made a distinction between crimes that are mala in se, or acts that are wrong, and mala prohibita, acts that are illegal but not necessarily immoral (just watch Legally Blonde to learn more about this and thank me later). A criminal can make the same kind of distinction when evaluating how “wrong” their behavior is. Was the unlocked car on the side of the road stolen, or was it just “borrowed” to get from Point A to Point B? In the example of a malicious “script kiddie”, they may be using denial of injury, where they convince themselves that since they attacked a business or corporate entity, no person is being harmed by the action, therefore it is okay. In this case, the digital barrier in cybercrime allows the attacker to ignore the real-world impact of their actions. This is often referred to as the online disinhibition effect. This phenomenon is primarily driven by concepts of anonymity, invisibility, and the delay in real-time consequences. Personality styles will also impact how people behave online. While individual personality influences the extent of the disinhibition, everyone engages in some level of online disinhibition everyday and may not even realize it. From small things such as leaving an anonymous polite comment on a social media post, to something larger like online bullying, it is easier for people to say things in chat rooms, social media comments, or emails that they would never say in person. The online disinhibition effect will interact with personality variables and in some cases will make only a small deviation from someone’s offline behavior, while for others it can cause dramatic changes. Because personality style plays such a strong role, some people are more predisposed to the elements of online disinhibition compared to others. Cybercriminals may be one type of subcategory of individuals whose offline behavior is drastically different from their online behavior.
Phase 2: The Professional Pivot
By this stage, the hacker’s experience has grown, and a natural thinning of the herd has occurred, with the lazy or bad hackers having either been caught, or having quit because they hit a skill ceiling. For those that have advanced to Phase 2, the initial thrill of casual or low-level attacks is starting to fade or not have the dopamine impact that it previously was. Their motivations are likely shifting toward technical mastery, financial gain, and a stronger sense of identity within the hacker world. With the increase of technical knowledge often comes with the ability to create their own malicious code to execute their attacks. Attacks are likely becoming more targeted, and zero-day vulnerabilities may be discovered. At this point, the attacker is going to have potentially impressive bragging rights for outsmarting sophisticated networks. Wouldn’t you feel proud if you managed to outsmart someone’s defenses?
As attacks become more advanced and sophisticated, the attacker will need to further the psychological justification for their behavior. Once again leaning on the Techniques of Neutralization, they will lean on concepts of denial of the victim. In the denial of the victim, they are presenting to themselves the argument that the victim deserved it, or that it is not really an injury; rather, it is a form of rightful retaliation or punishment against that person or entity. They may view their victims as lazy or wealthy. They might assume that the corporation has cyber insurance, and that they will receive some type of restitution. They may attempt a Robin Hood argument, arguing that they are seeking justice for others outside of the law. Ultimately, the risk here is that when the victim is physically absent or is a vague abstraction (like a corporation), the awareness of the victims’ existence is weakened. Diminished awareness of the victim(s) likely plays an important role in the malicious hacker determining whether or not to commence their cyberattack.
As a malicious hacker is leaving this phase, they’ve now found it relatively easy to deviate from moral, ethics, and normative societal constructs. Now, it is no longer about the thrill of the hunt for the zero-day or a chase for the high of the attack. They will now enter the final phase, where they are no longer acting alone, but instead have joined a criminal enterprise, executing large scale cyberattacks that could have global implications across a variety of industries. This stage is where attacks reach headlines, frighten the general public, and put cybersecurity companies on high alert as their team rush to learn about the technology used in the latest attack.
Phase 3: The Appeal to Higher Loyalties
The ultimate or final evolution of a cybercriminal is one who goes from acting alone to acting within a cyber syndicate. It may surprise people to know that often these organizations function similarly to legitimate cybersecurity enterprises. For a real-world example, let’s look at the Conti Ransomware Leaks. This event pulled back the curtain on how cybercriminal groups are run, revealing a surprisingly well-structured environment, complete with HR departments and performance reviews, clear management hierarchies, and even employees complaining about burnout. The world was shocked at how well-organized this crime syndicate was being run. It forced law enforcement agencies to reconsider how they are profiling these types of groups of cybercriminals.
Once the cybercriminal has entered this stage, they are, from a psychological standpoint, completely detached. When cybercrime becomes systematically normalized, the psychological transition from “rebel” to “employee” has taken place. They are now a line in a corporate balance sheet. They are able to justify their actions by seeing the ransomware as “just business”. Just like your sales team works to close hard hitting deals in the boardroom, the unethical hacker’s mentality is that they are merely exercising a financial leverage point in order to close a deal. This is now a corporate game of metrics and KPIs, which is ironic given that they are working on taking down organizations built on the same foundation.
Defensive Takeaway: Why Forensic Psychology Matters to CISOs
My goal in helping you understand this psychological progression is not just an academic exercise. Rather, what is being laid out here will help you understand a critical defensive asset for your organization. Each stage outlined above displays a progression of psychological adaptation, and each requires the attacker to overcome new ethical barriers, justify increasingly dangerous behavior, and redefine their identity within the cybercriminal ecosystem. What begins for many as curiosity, experimentation, and a desire for learning can gradually transform into organized criminal activity that is driven instead by profit and status.
For security leaders across industries, this distinction matters. Too often, organizations are focusing exclusively on the technical components of cybersecurity threats while overlooking the human decision-making process that drives them. Security tools remain essential but understanding how threat actors think provides an additional layer of defensive intelligence because at the end of the day, cyberattacks are carried out by people making decisions; weighing risk over reward, and considering potential consequences. This is part of threat modeling, which is an adversary-centric exercise that helps you identify a variety of important information such as what you want to protect, who you want to be protected from, where you could be attacked, what exploit scenarios you should consider, and what you should be doing to defend yourself. Your threat model serves as the foundation of your entire security plan. (If you need a threat model, or want to revise the one you currently have, send an email to bd@ise.io and we will send you a complimentary threat model exercise to help you take your team to the next level).
What we’ve learned in the current ransomware landscape is that these cybercriminal organizations operate in the same way that your legitimate business does. These groups have lowered barriers to entry while simultaneously creating pathways for inexperienced individuals to rapidly advance through the cybercriminal ecosystem. In studying and understanding these structures, you become better prepared to anticipate attacker behavior by identifying opportunities to disrupt operations before significant damage can occur.
This also highlights another important truth; these attackers are not targeting organizations at random. When you create strong security controls and programs to manage your third-party vendor risk, apply manual penetration testing methods with both internal and external reviews, and adopt other elements of a robust security program, you are directly attacking the economic and psychological calculation of a syndicate operator and are forcing them to take their business elsewhere. Every security control, penetration test, vendor risk assessment, application security review, and incident response exercise that you conduct changes the attacker’s cost-benefit calculation. These groups, just like you, are seeking efficiency. They are going to go after the easiest target with the quickest path of profit and the lowest risk of being caught. Organizations that demonstrate strong security maturity become less attractive targets to attackers, because their likelihood of success decreases, and operational costs increase.
This is why investments in cybersecurity should be viewed as more than technical expenditures. Your investments in cybersecurity should be a reflection of the assets you seek to protect from exploitation. Effective security programs create friction for adversaries. Robust third-party risk management programs reduce supply chain attack opportunities. Manual penetration testing uncovers security gaps that automated tools frequently miss. Security awareness trainings help reduce social engineering success rates. When budgets are tight and leadership is looking for ways to cut corners, security is not an area where this should take place (For more on that, check out our bestseller Hackable, where you can learn how to build out a security budget that fits the size of your brand. I’ll even do you one better; if you’ve made it this far in the blog, email bd@ise.io for a complimentary signed copy from the author).
Whether it is an insider threat or an organized cybercrime network, they all rely on human psychology to justify, coordinate, and execute the attacks. Regardless of the motivating factor, the underlying psychological mechanisms often follow remarkably similar patterns. It is in understanding those patterns that leadership teams will gain valuable insight when building out their cybersecurity strategy. As technology and AI advance and threats continue to evolve, leadership teams must remember that technology alone never tells the full story. The organizations that study human nature and implement both the technical and psychological dimensions of cybercrime are the ones who will be most prepared to anticipate emerging threats and build resilient security programs to defend against them. If you and your team are looking for guidance on how to defend against malicious attacks, talk to our team of ethical hackers.