Cyber One Information Technology "Your IT Partner For Growth and Success" Call 407-394-1000 to schedule a FREE BUSINESS EVALUATION

Who Is a Potential Victim for a Hacker Nowadays — and What Do They Want to Steal?

By Richard Medina, Certified Ethical Hacker

9/9/20266 min read

Cyberattacks used to seem like something that happened only to large corporations, banks, or government agencies. Today, that is no longer the case.

Almost anyone who uses a smartphone, computer, email account, online banking, cloud storage, or business network can become a target.

Cybercriminals are constantly looking for the easiest way to make money, steal valuable information, gain access to other systems, or disrupt an organization. In many cases, they aren't specifically targeting you—they are looking for a vulnerability they can exploit.

The question isn't necessarily "Am I important enough for a hacker to target me?"

The better question is: "What do I have that a hacker wants?" and Who Are Hackers Targeting?

1. Small Businesses

Small businesses are particularly attractive targets because they often have valuable information but fewer cybersecurity resources than large corporations.

A small business may have:

  • Customer information

  • Employee records

  • Credit card information

  • Bank account information

  • Tax records

  • Passwords

  • Business contracts

  • Intellectual property

  • Email accounts

  • Remote-access systems

  • Cloud accounts

  • Sensitive documents

A hacker doesn't need to steal millions of dollars from one company. Criminals can attack hundreds or thousands of small businesses using automated tools.

The Federal Trade Commission warns that scammers may use phishing, social engineering, malware and ransomware to obtain passwords, financial information and access to business systems.

2. Medical Practices and Healthcare Organizations

Healthcare organizations are especially attractive because they maintain extremely valuable information.

A medical practice may possess:

  • Patient names and addresses

  • Social Security numbers

  • Insurance information

  • Medical histories

  • Prescription information

  • Billing information

  • Financial information

  • Login credentials

  • Copies of identification documents

For healthcare organizations, cybersecurity isn't simply an IT issue. It is also a patient privacy and regulatory issue.

The HIPAA Security Rule requires covered entities and business associates to implement appropriate administrative, physical and technical safeguards to protect electronic protected health information (ePHI). HHS also identifies risk analysis as a foundational component of HIPAA Security Rule compliance.

For a small medical practice, one compromised employee account can potentially become the doorway into an entire network.

3. Employees

One of the most important things to understand about cybersecurity is that hackers often target people rather than computers.

An employee may receive an email appearing to come from:

"Your CEO"

"Microsoft"

"Your bank"

"A customer"

"Your IT department"

"A vendor"

The message may ask the employee to click a link, open an attachment, reset a password, purchase gift cards, transfer money, or provide login information.

Modern phishing attacks can look remarkably legitimate. The FTC specifically warns that criminals can imitate familiar companies, coworkers and executives to trick employees into revealing information or sending money.

What Do Hackers Actually Want to Steal?

The answer may surprise you.

Hackers aren't necessarily looking for just one thing.

They are looking for anything that can be monetized, exploited, sold or used to gain additional access.

Passwords and Login Credentials

A username and password can be extremely valuable.

If criminals obtain your email password, they may be able to reset passwords for other accounts.

One compromised account can potentially lead to:

Email → Cloud storage → Financial accounts → Business systems → Customer information

This is why protecting email accounts should be a high priority.

Money

Sometimes the objective is straightforward:

Steal money.

Criminals may attempt to:

  • Access online banking

  • Redirect payroll

  • Change vendor payment information

  • Conduct fraudulent wire transfers

  • Use stolen credit cards

  • Create fraudulent purchases

  • Impersonate executives

  • Extort businesses

Business Email Compromise (BEC) attacks are particularly dangerous because they may involve convincing an employee to transfer money to what appears to be a legitimate account.

Personal Information

Your personal information has value.

Hackers may seek:

  • Social Security numbers

  • Driver's license information

  • Dates of birth

  • Addresses

  • Phone numbers

  • Tax information

  • Financial records

  • Insurance information

This information can potentially be used for identity theft, fraud or additional attacks.

Medical Information

Medical information can be especially sensitive.

Criminals may attempt to obtain:

  • Patient records

  • Diagnoses

  • Prescriptions

  • Insurance information

  • Billing information

  • Medical identification numbers

For a healthcare organization, protecting this information is critical not only for patient privacy but also for maintaining trust and meeting applicable regulatory obligations.

Your Computer and Network

Sometimes hackers don't immediately want your data.

They want access.

Once inside a computer or network, criminals may attempt to:

  1. Establish persistence.

  2. Steal credentials.

  3. Move to other computers.

  4. Access servers.

  5. Locate backups.

  6. Steal sensitive information.

  7. Deploy ransomware.

This can turn one compromised workstation into a much larger cybersecurity incident.

Ransomware: When Your Data Becomes a Weapon

One of the most damaging attacks against businesses is ransomware.

Imagine arriving at work Monday morning and discovering that:

Every computer is locked.

Your files won't open.

Your server won't work.

Your accounting system is unavailable.

Your patient-management system is inaccessible.

And a message appears demanding payment.

That's ransomware.

According to the FTC, ransomware can begin with something as simple as an employee clicking a malicious link or opening an attachment. Attackers can then encrypt files and demand payment to restore access.

And paying the ransom doesn't guarantee that criminals will actually restore your files.

So How Can You Protect Yourself?

There is no single cybersecurity product that makes someone completely immune to hacking.

Effective cybersecurity requires multiple layers of protection.

1. Enable Multi-Factor Authentication

Passwords alone aren't enough.

Multi-factor authentication (MFA) requires an additional method of verifying your identity.

For example:

Password + Authenticator

or

Password + Security Key

CISA recommends MFA for business systems and particularly emphasizes stronger, phishing-resistant methods.

Whenever possible, use MFA for:

  • Email

  • Microsoft 365

  • Google Workspace

  • Banking

  • VPN

  • Remote access

  • Cloud applications

  • Administrative accounts

2. Use Strong, Unique Passwords

Don't use the same password everywhere.

If one website suffers a data breach and your password is exposed, criminals may try that same password on your email, banking and other accounts.

A password manager can help you create and store unique passwords.

3. Keep Computers and Software Updated

Cybercriminals frequently exploit known vulnerabilities in outdated software.

Keep your:

  • Operating systems

  • Browsers

  • Applications

  • Routers

  • Firewalls

  • Servers

  • Security software

patched and updated.

CISA specifically recommends regularly patching and updating software and addressing known exploited vulnerabilities.

4. Back Up Your Data

A backup can be the difference between a serious inconvenience and a catastrophic business interruption.

But there is an important distinction:

Having a backup isn't enough.

You need a backup strategy that considers ransomware.

Ideally, organizations should maintain protected backups that aren't continuously accessible to the same systems an attacker could compromise.

The FTC recommends regularly backing up important data and maintaining a plan for responding if ransomware occurs.

And don't simply assume your backup works.

Test it.

A backup that cannot be restored isn't much of a backup.

5. Protect Your Email

Email is one of the most common entry points for cybercriminals.

Businesses should consider layered email protection that can help detect:

  • Phishing

  • Malicious links

  • Malware

  • Impersonation

  • Suspicious attachments

  • Credential theft

Employees should also be trained to recognize suspicious messages.

6. Train Your Employees

Your employees are not your weakest link.

Untrained employees are.

Employees should understand how to recognize:

  • Phishing emails

  • Fake Microsoft/Google login pages

  • Suspicious attachments

  • Fake invoices

  • Executive impersonation

  • Urgent wire-transfer requests

  • Password-reset scams

  • Social engineering

A simple rule can prevent many expensive mistakes:

Stop. Verify. Then act.

If an email requests money, credentials or sensitive information, verify the request through a separate trusted communication method.

7. Know What Is Connected to Your Network

You can't protect something you don't know exists.

Businesses should maintain an inventory of:

  • Computers

  • Servers

  • Laptops

  • Mobile devices

  • Printers

  • Routers

  • Firewalls

  • Cloud applications

  • Remote-access tools

  • User accounts

Regular vulnerability assessments can help identify weaknesses before criminals find them.

8. Don't Wait Until After an Attack

One of the biggest cybersecurity mistakes a business can make is waiting until something goes wrong.

Cybersecurity should be treated as an ongoing process.

That means:

Identify → Protect → Detect → Respond → Recover

For healthcare organizations, HHS emphasizes that risk analysis should be an ongoing process used to understand threats and vulnerabilities and determine appropriate safeguards.

Cybersecurity Isn't Just for Large Companies

If you own a small business, you may think:

"We're too small for a hacker to care about us."

Unfortunately, that's exactly the assumption cybercriminals want you to make.

Your business may have only five, ten or twenty employees—but your systems could contain valuable information worth far more than you realize.

And attackers increasingly use automation, making it possible to target businesses at scale.

Your size doesn't determine whether you're a target. Your vulnerabilities may.

Final Thought

How Cyber One Information Technology Can Help

At Cyber One Information Technology, we believe cybersecurity should be practical, proactive and affordable for small businesses.

Our focus is helping businesses—particularly small businesses and healthcare practices—strengthen their IT environment and reduce their exposure to cyber threats.

Cybersecurity services can include:

  • 24/7 security monitoring

  • Endpoint protection and EDR

  • Managed detection and response

  • SIEM monitoring

  • AI-assisted threat detection

  • Vulnerability assessments

  • Multi-factor authentication

  • Identity and access management

  • Backup and disaster recovery

  • Data encryption

  • Network security

  • Security awareness

  • HIPAA cybersecurity assistance

  • Security policies and documentation

  • Ongoing cybersecurity management

The goal isn't simply to install another piece of software.

The goal is to build layers of protection around your business.

Don't Know How Secure Your Business Really Is?

That's exactly why we offer a free business cybersecurity consultation.

Cyber One Information Technology can help you identify potential weaknesses in your current environment and discuss practical ways to improve your security.

You don't have to wait until your business has been hacked.

Find the vulnerabilities before the hackers do.

Schedule Your Free Cybersecurity Consultation

Cyber One Information Technology, LLC

Managed IT • Cybersecurity • HIPAA Security • 24/7 Monitoring

Serving small businesses and healthcare organizations.

Contact Cyber One Information Technology today for your FREE business cybersecurity consultation.

Cybersecurity isn't an expense you hope you never need. It's an investment in keeping your business, your employees and your customers protected.

For more info visit www.CyberOneInfo.com

Richard Medina, Certified Ethical Hacker https://www.linkedin.com/in/richme/

Security

Protecting your business with advanced IT solutions.

Telephone

Services

407-394-1000

© 2026. All rights reserved. Cyber One Information Technology, LLC