Cyber One Information Technology "Your IT Partner For Growth and Success" Call 407-394-1000 to schedule a FREE BUSINESS EVALUATION
Who Is a Potential Victim for a Hacker Nowadays — and What Do They Want to Steal?
By Richard Medina, Certified Ethical Hacker
9/9/20266 min read


Cyberattacks used to seem like something that happened only to large corporations, banks, or government agencies. Today, that is no longer the case.
Almost anyone who uses a smartphone, computer, email account, online banking, cloud storage, or business network can become a target.
Cybercriminals are constantly looking for the easiest way to make money, steal valuable information, gain access to other systems, or disrupt an organization. In many cases, they aren't specifically targeting you—they are looking for a vulnerability they can exploit.
The question isn't necessarily "Am I important enough for a hacker to target me?"
The better question is: "What do I have that a hacker wants?" and Who Are Hackers Targeting?
1. Small Businesses
Small businesses are particularly attractive targets because they often have valuable information but fewer cybersecurity resources than large corporations.
A small business may have:
Customer information
Employee records
Credit card information
Bank account information
Tax records
Passwords
Business contracts
Intellectual property
Email accounts
Remote-access systems
Cloud accounts
Sensitive documents
A hacker doesn't need to steal millions of dollars from one company. Criminals can attack hundreds or thousands of small businesses using automated tools.
The Federal Trade Commission warns that scammers may use phishing, social engineering, malware and ransomware to obtain passwords, financial information and access to business systems.
2. Medical Practices and Healthcare Organizations
Healthcare organizations are especially attractive because they maintain extremely valuable information.
A medical practice may possess:
Patient names and addresses
Social Security numbers
Insurance information
Medical histories
Prescription information
Billing information
Financial information
Login credentials
Copies of identification documents
For healthcare organizations, cybersecurity isn't simply an IT issue. It is also a patient privacy and regulatory issue.
The HIPAA Security Rule requires covered entities and business associates to implement appropriate administrative, physical and technical safeguards to protect electronic protected health information (ePHI). HHS also identifies risk analysis as a foundational component of HIPAA Security Rule compliance.
For a small medical practice, one compromised employee account can potentially become the doorway into an entire network.
3. Employees
One of the most important things to understand about cybersecurity is that hackers often target people rather than computers.
An employee may receive an email appearing to come from:
"Your CEO"
"Microsoft"
"Your bank"
"A customer"
"Your IT department"
"A vendor"
The message may ask the employee to click a link, open an attachment, reset a password, purchase gift cards, transfer money, or provide login information.
Modern phishing attacks can look remarkably legitimate. The FTC specifically warns that criminals can imitate familiar companies, coworkers and executives to trick employees into revealing information or sending money.
What Do Hackers Actually Want to Steal?
The answer may surprise you.
Hackers aren't necessarily looking for just one thing.
They are looking for anything that can be monetized, exploited, sold or used to gain additional access.
Passwords and Login Credentials
A username and password can be extremely valuable.
If criminals obtain your email password, they may be able to reset passwords for other accounts.
One compromised account can potentially lead to:
Email → Cloud storage → Financial accounts → Business systems → Customer information
This is why protecting email accounts should be a high priority.
Money
Sometimes the objective is straightforward:
Steal money.
Criminals may attempt to:
Access online banking
Redirect payroll
Change vendor payment information
Conduct fraudulent wire transfers
Use stolen credit cards
Create fraudulent purchases
Impersonate executives
Extort businesses
Business Email Compromise (BEC) attacks are particularly dangerous because they may involve convincing an employee to transfer money to what appears to be a legitimate account.
Personal Information
Your personal information has value.
Hackers may seek:
Social Security numbers
Driver's license information
Dates of birth
Addresses
Phone numbers
Tax information
Financial records
Insurance information
This information can potentially be used for identity theft, fraud or additional attacks.
Medical Information
Medical information can be especially sensitive.
Criminals may attempt to obtain:
Patient records
Diagnoses
Prescriptions
Insurance information
Billing information
Medical identification numbers
For a healthcare organization, protecting this information is critical not only for patient privacy but also for maintaining trust and meeting applicable regulatory obligations.
Your Computer and Network
Sometimes hackers don't immediately want your data.
They want access.
Once inside a computer or network, criminals may attempt to:
Establish persistence.
Steal credentials.
Move to other computers.
Access servers.
Locate backups.
Steal sensitive information.
Deploy ransomware.
This can turn one compromised workstation into a much larger cybersecurity incident.
Ransomware: When Your Data Becomes a Weapon
One of the most damaging attacks against businesses is ransomware.
Imagine arriving at work Monday morning and discovering that:
Every computer is locked.
Your files won't open.
Your server won't work.
Your accounting system is unavailable.
Your patient-management system is inaccessible.
And a message appears demanding payment.
That's ransomware.
According to the FTC, ransomware can begin with something as simple as an employee clicking a malicious link or opening an attachment. Attackers can then encrypt files and demand payment to restore access.
And paying the ransom doesn't guarantee that criminals will actually restore your files.
So How Can You Protect Yourself?
There is no single cybersecurity product that makes someone completely immune to hacking.
Effective cybersecurity requires multiple layers of protection.
1. Enable Multi-Factor Authentication
Passwords alone aren't enough.
Multi-factor authentication (MFA) requires an additional method of verifying your identity.
For example:
Password + Authenticator
or
Password + Security Key
CISA recommends MFA for business systems and particularly emphasizes stronger, phishing-resistant methods.
Whenever possible, use MFA for:
Email
Microsoft 365
Google Workspace
Banking
VPN
Remote access
Cloud applications
Administrative accounts
2. Use Strong, Unique Passwords
Don't use the same password everywhere.
If one website suffers a data breach and your password is exposed, criminals may try that same password on your email, banking and other accounts.
A password manager can help you create and store unique passwords.
3. Keep Computers and Software Updated
Cybercriminals frequently exploit known vulnerabilities in outdated software.
Keep your:
Operating systems
Browsers
Applications
Routers
Firewalls
Servers
Security software
patched and updated.
CISA specifically recommends regularly patching and updating software and addressing known exploited vulnerabilities.
4. Back Up Your Data
A backup can be the difference between a serious inconvenience and a catastrophic business interruption.
But there is an important distinction:
Having a backup isn't enough.
You need a backup strategy that considers ransomware.
Ideally, organizations should maintain protected backups that aren't continuously accessible to the same systems an attacker could compromise.
The FTC recommends regularly backing up important data and maintaining a plan for responding if ransomware occurs.
And don't simply assume your backup works.
Test it.
A backup that cannot be restored isn't much of a backup.
5. Protect Your Email
Email is one of the most common entry points for cybercriminals.
Businesses should consider layered email protection that can help detect:
Phishing
Malicious links
Malware
Impersonation
Suspicious attachments
Credential theft
Employees should also be trained to recognize suspicious messages.
6. Train Your Employees
Your employees are not your weakest link.
Untrained employees are.
Employees should understand how to recognize:
Phishing emails
Fake Microsoft/Google login pages
Suspicious attachments
Fake invoices
Executive impersonation
Urgent wire-transfer requests
Password-reset scams
Social engineering
A simple rule can prevent many expensive mistakes:
Stop. Verify. Then act.
If an email requests money, credentials or sensitive information, verify the request through a separate trusted communication method.
7. Know What Is Connected to Your Network
You can't protect something you don't know exists.
Businesses should maintain an inventory of:
Computers
Servers
Laptops
Mobile devices
Printers
Routers
Firewalls
Cloud applications
Remote-access tools
User accounts
Regular vulnerability assessments can help identify weaknesses before criminals find them.
8. Don't Wait Until After an Attack
One of the biggest cybersecurity mistakes a business can make is waiting until something goes wrong.
Cybersecurity should be treated as an ongoing process.
That means:
Identify → Protect → Detect → Respond → Recover
For healthcare organizations, HHS emphasizes that risk analysis should be an ongoing process used to understand threats and vulnerabilities and determine appropriate safeguards.
Cybersecurity Isn't Just for Large Companies
If you own a small business, you may think:
"We're too small for a hacker to care about us."
Unfortunately, that's exactly the assumption cybercriminals want you to make.
Your business may have only five, ten or twenty employees—but your systems could contain valuable information worth far more than you realize.
And attackers increasingly use automation, making it possible to target businesses at scale.
Your size doesn't determine whether you're a target. Your vulnerabilities may.
Final Thought
How Cyber One Information Technology Can Help
At Cyber One Information Technology, we believe cybersecurity should be practical, proactive and affordable for small businesses.
Our focus is helping businesses—particularly small businesses and healthcare practices—strengthen their IT environment and reduce their exposure to cyber threats.
Cybersecurity services can include:
24/7 security monitoring
Endpoint protection and EDR
Managed detection and response
SIEM monitoring
AI-assisted threat detection
Vulnerability assessments
Multi-factor authentication
Identity and access management
Backup and disaster recovery
Data encryption
Network security
Security awareness
HIPAA cybersecurity assistance
Security policies and documentation
Ongoing cybersecurity management
The goal isn't simply to install another piece of software.
The goal is to build layers of protection around your business.
Don't Know How Secure Your Business Really Is?
That's exactly why we offer a free business cybersecurity consultation.
Cyber One Information Technology can help you identify potential weaknesses in your current environment and discuss practical ways to improve your security.
You don't have to wait until your business has been hacked.
Find the vulnerabilities before the hackers do.
Schedule Your Free Cybersecurity Consultation
Cyber One Information Technology, LLC
Managed IT • Cybersecurity • HIPAA Security • 24/7 Monitoring
Serving small businesses and healthcare organizations.
Contact Cyber One Information Technology today for your FREE business cybersecurity consultation.
Cybersecurity isn't an expense you hope you never need. It's an investment in keeping your business, your employees and your customers protected.
For more info visit www.CyberOneInfo.com
Richard Medina, Certified Ethical Hacker https://www.linkedin.com/in/richme/
