CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsEasy

A security analyst reviews an incident where attackers encrypted a hospital's patient records and demanded payment in cryptocurrency for the decryption key. The attackers left no political message and appear to operate as a for-profit criminal enterprise with structured roles. Which type of threat actor is MOST likely responsible?

  1. AScript kiddie
  2. BNation-state
  3. CHacktivist
  4. DOrganized crime
Show answer & explanation

Correct answer: D. Organized crime

Organized crime groups are financially motivated threat actors that often operate with structured, business-like hierarchies and use ransomware for direct monetary gain. The lack of a political statement rules out hacktivism, and the level of sophistication rules out a script kiddie.

Why the other options are wrong

  • A. Script kiddies use pre-made tools for notoriety, not structured, large-scale extortion campaigns.
  • B. Nation-states are typically motivated by espionage or geopolitical advantage, not direct financial extortion.
  • C. Hacktivists are politically or socially motivated and typically leave a message, not a ransom demand.

Organized Crime (Threat Actor)

A financially motivated threat actor group operating with business-like structure, often specializing in ransomware, fraud, or data theft for profit.

  • Primary motivation is financial gain
  • Often highly resourced with specialized roles (developers, negotiators, money launderers)
  • Common tactic: ransomware-as-a-service

Memory trick: 'Organized crime' = organized like a company, chasing cash.

More Threats, Vulnerabilities, and Mitigations questions