Skip to content
Cybersecurity

How Hacker Attacks Work: Stages and Defences

How hacker attacks work: the typical stages from reconnaissance to extortion, what AI changes for attackers, and which measures stop each stage.

Published on 4 min read

Row of staggered glass panes in an empty office, a glass front with a city view behind them.

A successful attack on a company is not a single moment but a process in several stages over days, often weeks. At every stage attackers leave traces, and at every stage they can be stopped.

The six stages of an attack

For practical purposes, six stages suffice:

  1. Reconnaissance. Attackers collect domains, email addresses, reachable systems and names in accounting and management from the website, job advertisements, social networks and the commercial register. This stage goes unnoticed because there is no contact with the target.
  2. Initial access. Entry almost always comes via stolen credentials, an unpatched vulnerability at the network edge (VPN gateway, firewall, mail server, remote maintenance) or phishing.
  3. Persistence. Attackers secure their access against reboots and password changes: extra user accounts, scheduled tasks, legitimate-looking remote maintenance tools.
  4. Lateral movement and privilege escalation. From one workstation, attackers use stored passwords, over-privileged service accounts and shares to reach the file server, domain controller and backup. In a flat, unsegmented network this takes hours, not weeks.
  5. Data exfiltration. Before encrypting, attackers copy contracts, personnel data or customer lists out as a second lever in case the company can restore from backups. According to the BSI’s 2025 situation report, this happens in most ransomware attacks.
  6. Encryption and extortion. Only now does the attack become visible: servers and workstations encrypted, backups deleted, a ransom demand.

What changes in the age of AI

AI has not changed the basic pattern but has made three stages faster and cheaper:

  • Reconnaissance is automated. Language models compile public information into a profile in minutes: organisation chart, contacts, projects, providers.
  • Phishing becomes flawless and personal. Fluent messages in the style of the actual managing director, citing a real project. Voices can be cloned from a few seconds of audio.
  • Vulnerabilities are exploited faster. Often only days pass between a vulnerability’s publication and the first automated attack. The BSI counted an average of 119 new vulnerabilities per day in its 2025 reporting period.

AI also serves defenders, for example to detect anomalies in sign-ins and data movements, as described in the article Artificial intelligence in cybersecurity.

Defences for each stage

It is enough to interrupt the attack at any stage before stage 6.

StageWhat attackers needWhat stops the attack
ReconnaissancePublic informationSparing details on the website and in job advertisements
Initial accessCredentials, open vulnerability, inattentive personMulti-factor authentication on all remote access, patch management with fixed deadlines, mail filtering, training
PersistenceAdministrator rights, unmonitored systemsSeparate admin accounts, endpoint detection and response (EDR)
Lateral movementFlat network, stored passwords, service accounts with full rightsNetwork segmentation, firewall rules between zones, least privilege
ExfiltrationUnobstructed path outOutbound firewall rules, monitoring of unusual data volumes
EncryptionReachable backups, no planImmutable, separated backups, rehearsed emergency plan, restore tests

In our experience, three items offer the best effort-to-effect ratio: multi-factor authentication on every external access, a backup that attackers with administrator rights cannot delete, and a segmented network where an infected workstation does not automatically reach the server. Segmentation, firewalls and Wi-Fi separation are described on the page Network and IT infrastructure.

How to recognise an attack in progress

Between stages 2 and 6 lies the window in which an attack can still be stopped. Typical signs:

  • Sign-ins at unusual times or from unusual countries
  • New user accounts or group memberships that nobody created
  • Remote maintenance tools on computers where they do not belong
  • Disabled antivirus or failed backup runs without obvious reason
  • Unusually high outbound data traffic, often at night or at weekends

Each sign alone may be harmless; several within a few days are reason to act immediately: disconnect affected systems without switching them off, so traces are preserved, change administrator passwords, secure logs and bring in a service provider experienced in incident response. Exfiltrated personal data triggers the 72-hour GDPR reporting obligation.

Why a structured assessment of network, remote access, permissions and backups is the most sensible first step for smaller companies is described in the article Cybersecurity for SMEs: the IT security check.

Key points

  • An attack runs through six stages over days or weeks. It only becomes visible with encryption but can be stopped at any stage before that.
  • AI accelerates reconnaissance, phishing and vulnerability exploitation but does not change the basic pattern.
  • Multi-factor authentication on all remote access, immutable backups and network segmentation offer the best effort-to-effect ratio.

How DEVACON assesses the current state with its IT security check and prioritises measures is described on the page Cybersecurity.

Topics Hacker attack Ransomware Phishing AI Attack stages

This article comes from the DEVACON blog and was editorially revised for the new website.