Paso Robles TechLearning Hub
5 min

How an Attack Actually Unfolds

Trace the common stages of an attack and identify the specific points where the right control stops the chain.

An attack is a chain, not an event

How an attack unfolds

An attack is a chain, not a single event.

Compromises rarely happen in one dramatic moment — they progress through stages. A chain can be broken at any link: you do not need to stop every stage, just reliably stop at least one and detect the rest.

02

The five stages of a compromise

  1. 01
    Entry

    A convincing email or an exposed service gives the attacker a first foothold.

  2. 02
    Credential theft

    The attacker captures a password, often through a fake login page.

  3. 03
    Quiet expansion

    With valid credentials, the attacker quietly explores email, files, and connected systems.

  4. 04
    Preparation

    Backups are located, security tools are disabled, and valuable data is copied.

  5. 05
    Impact

    Files are encrypted, funds are redirected, or data is published.

Learn more: what happens inside each stage

Entry can also come from a malicious attachment or a compromised website, not just email. In credential theft, the fake login page often looks exactly like the real one. Quiet expansion can last weeks with few obvious symptoms — and often the group that breaks in sells that access to another that carries out the damage, which is why a quiet intrusion with no immediate impact still matters. Impact is usually the first stage an organization actually notices.

Learn more: why the backups are attacked first

Attackers understand that a business with working backups does not need to negotiate. Locating and corrupting backups before triggering encryption is a standard step, which is why backup isolation and integrity verification matter as much as backup itself.

03

Why capable people still get caught

Modern phishing does not look like fraud — it looks like work.

Phishing references a real project, arrives on a busy afternoon, and imitates a vendor or colleague you already expect to hear from. The request is small and plausible.

Common pressure tactics

Urgency

A deadline that discourages verification.

Authority

An apparent request from an owner, manager, or accountant.

Familiarity

A real vendor name, logo, or ongoing conversation thread.

Routine

A request that resembles work the recipient does every day.

Awareness reduces clicks. It never eliminates them.

Training reduces how often someone clicks, but the systems behind the click have to assume that someone eventually will.

Did you know?

A single convincing email is still the most common entry point for a business compromise — which is why no amount of caution replaces the controls behind it.

The blind spot

The blind spot

You will notice the final stage first — unless something is watching the quiet ones.

05

Interrupting the chain in practice

Controls that break the chain at different links

Secure DNS & web filtering

Blocks malicious destinations early, before a connection is ever made.

Multi-factor authentication

A stolen password is not enough to get in on its own.

Endpoint detection & response

Catches malware behavior on the device itself.

Monitoring with professional oversight

Quiet expansion gets noticed instead of dwelling undetected.

The same attack, with and without layered controls

Malicious link clicked

Unprotected environment

Fake login page loads normally.

Layered environment

Secure DNS filtering blocks the known-malicious destination before it loads.

Password captured

Unprotected environment

Credentials immediately work from anywhere.

Layered environment

Multi-factor authentication stops the login without the second factor.

Malware executed

Unprotected environment

Runs undetected on the endpoint.

Layered environment

Endpoint detection identifies the behavior and isolates the device.

Attacker explores quietly

Unprotected environment

No one is watching for unusual activity.

Layered environment

Monitoring surfaces the anomaly for professional review.

Files encrypted

Unprotected environment

Recovery depends on paying a ransom.

Layered environment

Verified, isolated backups restore operations without negotiating.

Every layer adds another chance to detect an attacker — and every layer an attacker has to defeat buys you time to respond.

These controls each break the chain at a different point. Module 3 explains why they work best as coordinated layers, so that when one fails another still blocks, detects, or limits the attack.

What to remember

Four ideas worth carrying forward

  • An attack is a chain of stages — entry, credential theft, expansion, preparation, and impact.
  • Most organizations first notice the final stage, long after entry occurred.
  • Attackers deliberately target backups before triggering encryption.
  • Layered controls force an attacker to defeat several independent defenses, and each layer adds a chance to detect them.

Terms used in this module

Select a term to read its definition without leaving this page.

Finished this module?

Mark it complete to save your progress, or continue without marking it complete.