CompTIA Security+ (SY0-701)Threats, Vulnerabilities, and MitigationsEasy
A security analyst reviews an incident where attackers encrypted a hospital's patient records and demanded payment in cryptocurrency for the decryption key. The attackers left no political message and appear to operate as a for-profit criminal enterprise with structured roles. Which type of threat actor is MOST likely responsible?
- AScript kiddie
- BNation-state
- CHacktivist
- DOrganized crime
Show answer & explanationAnswer & explanation
Correct answer: D. Organized crime
Organized crime groups are financially motivated threat actors that often operate with structured, business-like hierarchies and use ransomware for direct monetary gain. The lack of a political statement rules out hacktivism, and the level of sophistication rules out a script kiddie.
Why the other options are wrong
- A. Script kiddies use pre-made tools for notoriety, not structured, large-scale extortion campaigns.
- B. Nation-states are typically motivated by espionage or geopolitical advantage, not direct financial extortion.
- C. Hacktivists are politically or socially motivated and typically leave a message, not a ransom demand.
Organized Crime (Threat Actor)
A financially motivated threat actor group operating with business-like structure, often specializing in ransomware, fraud, or data theft for profit.
- Primary motivation is financial gain
- Often highly resourced with specialized roles (developers, negotiators, money launderers)
- Common tactic: ransomware-as-a-service
Memory trick: 'Organized crime' = organized like a company, chasing cash.