Common attack types: phishing, ransomware, DDoS
Phishing, ransomware, DDoS, social engineering: a glossary of the most common cyberattacks, so you can recognise them.
Phishing
An attempt to trick the victim into revealing sensitive information (passwords, bank details) via a message or site impersonating a legitimate source. Variants: spear phishing (targeted, personalised) and smishing (via SMS).
Ransomware
Malicious software that encrypts the victim's files and demands a ransom to decrypt them. Often spreads via a booby-trapped attachment or an unpatched vulnerability.
Paying a ransom doesn't guarantee file recovery and funds the criminal ecosystem — the best protection remains a regular backup, disconnected from the main network, tested periodically.
DDoS (Distributed Denial of Service)
Flooding an online service with a massive volume of requests from many simultaneous sources, making the service unavailable to legitimate users.
Social engineering
Psychological manipulation that gets a victim to act against their own interest (grant access, click a link, transfer money) by exploiting trust, urgency or perceived authority — often the entry point for phishing or fraud.
Summary
| Attack | Main target | Goal |
|---|---|---|
| Phishing | The human | Steal credentials or data |
| Ransomware | Files/systems | Extort a ransom |
| DDoS | Service availability | Make it unavailable |
| Social engineering | The human | Manipulate for access or action |
What most of these attacks have in common: they target the human as much as the technology. Checking the sender, never clicking under pressure, and confirming through a second channel (a phone call) remain the most effective habits.
Thanks for the feedback!