The hackers who stole over a billion dollars taught me how to defend everything I build
I am a builder who used to break things. Penetration testing and bug hunting, that was my start before I went full AI-native engineer. And the best security lesson I ever learned is simple: you cannot defend against something you refuse to understand. So I study the attackers. Not to become one, to stop being easy. Here is the field guide I wish someone had handed me. The people and the methods…
I used to be a builder who enjoyed breaking things. My initial career path involved penetration testing and bug hunting before transitioning into AI-native engineering. One security lesson that stands out as the most crucial is this: you cannot defend against something you do not comprehend. Consequently, I began studying attackers, not to adopt their techniques, but to enhance my own security posture.
Here is a comprehensive guide on the various attacks launched by hackers and the single most effective measure that can thwart each of them.
1. Phishing, the attack that evades your firewall
The majority of breaches commence with a convincing email. Phishing does not infiltrate your server; rather, it manipulates you. A message resembling that of your bank, employer, or cloud provider lures you into clicking a link, entering credentials on a fraudulent page, and granting the attacker access through an unsuspected entry point. It is mundane and remains the modus operandi behind many of history's most massive breaches.
Defense: take your time. Verify the authenticity of the sender, never enter sensitive information from a link, and enable two-factor authentication (2FA) across all platforms to prevent unauthorized access even if the password is compromised.
2. Brute force, the attack that endures endlessly
Computers do not tire. Brute force attacks and credential stuffing relentlessly attempt to crack passwords, trying millions of combinations until one proves successful, often employing leaked passwords from other compromised sites. Your imaginative password from 2019 may already reside on a list somewhere.
Defense: opt for lengthy, distinct passwords (preferably managed externally) coupled with 2FA, and implement rate limiting measures that temporarily block access after a certain number of failed attempts.
3. RATs, the covert houseguest
Remote Access Trojans (RATs) operate as described: malware that grants attackers remote control over your device. They can access cameras, steal files, record keystrokes, and more. Typically, they infiltrate through disguised cracked applications, seemingly harmless attachments, or fraudulent installers, patiently waiting in the shadows.
Defense: avoid running unverified software. Refrain from accepting random attachments, and ensure your operating system and security software are consistently updated to mitigate vulnerabilities.
4. Ransomware, the hostage-taker
Ransomware is the most high-profile attack, capturing global attention. It encrypts all your data and demands a ransom for its release. This malicious software has crippled hospitals, pipelines, and entire city governments. Paying the ransom provides no guarantee and funds further attacks, while choosing not to pay leaves you vulnerable, but with a backup plan, you can restore your data without paying.
Defense: maintain offline and regularly tested backups, ensuring they are not dependent on cloud services. A ransom note is less intimidating when you can simply erase and restore your data from a backup.
5. Lazarus Group, when the attacker represents a nation-state
This scenario shifts from individual hackers to state-sponsored operations. Lazarus Group, a North Korean-affiliated entity, targets financial gain and geopolitical leverage. Their achievements include fraudulent SWIFT transfers, hospital lockups worldwide, and multi-billion dollar crypto heists. These adversaries are sophisticated, well-funded, and patient. Their approach teaches us that no single defense mechanism can guarantee protection, but a layered security strategy significantly reduces risk.
Defense: assume you are a target, even if your organization feels insignificant. Adopt a proactive stance, verifying identities, segmenting networks, and preparing for a breach. The best defense is a comprehensive, multi-layered security approach that addresses all potential attack vectors.
Upon delving into this field, I did not become paranoid. Instead, I became more composed. Understanding the attacker transforms security from a vague fear into a clear, actionable checklist. Verify emails, use unique and complex passwords with 2FA, avoid executing untrusted software, ensure data backups are functional, and always operate with the assumption that you are a potential target.
This mindset becomes an integral part of building systems, not an afterthought. The most dangerous notion in technology remains the unspoken question: "Who would ever bother attacking me?" The answer is that attackers already attempt to breach systems daily, and the critical question is whether you have studied their tactics first.
As Ksatria Bintang Samudra, an AI-native full-stack engineer with a background in penetration testing, I invite remote collaborations globally. Discover more of my work at ksatriabintangsamudra.com.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.