Types of Hackers in Cyber Security: A Banker's IIBF Guide

CYBERCRIME By Ashish Jain · IIBF STORE Editorial · 20 August 2026 · Updated 01 Oct 2026 · 11 min read · 34 views
Types of Hackers in Cyber Security: A Banker's IIBF Guide

Every fraud file a bank opens eventually reaches the same two questions: who did this, and what did they want? Knowing the types of hackers in cyber security answers both, and it is the reason the IIBF Prevention of Cyber Crime paper spends an entire chapter on attacker profiles rather than on tools. Motive decides the target, the target decides the control, and the control decides whether your branch or data centre was ever going to survive the attempt.

This guide maps each attacker profile to the banking asset it goes after, the control that actually stops it, and the section of the IT Act 2000 a charge-sheet would rest on. Use it as your revision sheet for the attacker-classification questions that show up every cycle.

🕵️ Why Attacker Profiling Comes Before Any Control

Banks buy controls in layers — firewalls, endpoint detection, privileged access management, transaction monitoring. Those layers are not equally useful against every adversary. A next-generation firewall is close to worthless against a clerk who already holds a valid login and simply misuses it, while maker-checker discipline does nothing against a nation-state actor who has compromised your vendor's update server.

That is the practical value of studying the types of hackers in cyber security: it forces you to ask which threat a given control was designed for. The IIBF syllabus builds this idea across the Computer Hackers chapter and the linked Computer Insecurity chapter, which explains why systems are exploitable in the first place.

Three variables separate one attacker from another, and examiners test all three:

  • Authorisation — did anyone at the bank permit this activity, in writing, with a defined scope?
  • Motive — money, ideology, curiosity, reputation, disruption, or espionage.
  • Capability — a downloaded toolkit versus a funded team that can burn a zero-day exploit.

Get those three right and the classification question answers itself. A useful discipline before the exam is to run through our cyber crime prevention checklist for bankers and tag each control with the attacker profile it is meant to defeat. Anything you cannot tag is either redundant spend or a gap you have not noticed yet.

💡 Exam Tip: When a question describes an intrusion, look for the permission word first — "engaged by the bank", "without authorisation", "no prior consent". Authorisation, not skill level, is what separates a white hat from a grey hat from a black hat.
Black hat white hat and grey hat compared
Black hat white hat and grey hat compared

🎩 The Hat Taxonomy: White, Black and Grey

The oldest classification borrows from Western films, and it survives because it is built purely on authorisation and intent.

White hat

An ethical hacker who tests systems under a signed engagement letter with an agreed scope, time window and disclosure route. In a bank this is your VAPT vendor, your red team, or a researcher operating inside a formal bug-bounty policy. The defining feature is not that they are employed — it is that written authorisation exists before the first packet is sent. Findings go to the CISO, never to a public forum.

Black hat

An attacker with no authorisation and a harmful or self-serving objective — card data, credentials, funds, or extortion leverage. Almost every reported banking incident sits here. Black hats are increasingly organised as services: one group sells access, another monetises it, a third launders the proceeds through mule accounts.

Grey hat

The one candidates get wrong. A grey hat intrudes without permission but usually without malicious intent — they find the flaw, then approach the bank, sometimes asking for a fee or public credit. The absence of malice does not create a defence in Indian law: unauthorised access is an offence under Section 43 read with Section 66 of the IT Act 2000 regardless of how politely it is disclosed.

⚠️ Common Mistake: Treating "no damage caused" as equal to "no offence committed". Section 66 turns on dishonest or fraudulent unauthorised access, not on the size of the loss. A grey hat with good intentions is still outside the safe harbour a white hat's contract provides.
Bank security team reviewing an intrusion alert
Bank security team reviewing an intrusion alert

📊 Types of Hackers in Cyber Security: Profile Comparison

The table below is the single highest-yield revision item in this article. Read it row-wise — motive, target, control — and the MCQs stop being guesswork.

Attacker profilePrimary motiveTypical banking targetControl that bites hardest
White hatAssurance under contractWhatever the scope document listsScope control and evidence handling
Black hatFinancial gainCard data, net banking credentials, payment gatewaysTransaction monitoring and strong authentication
Grey hatCuriosity, recognition, bountyInternet-facing portals and mobile appsPublished disclosure policy and patching cadence
Script kiddieThrill, peer statusPublic websites, exposed test serversPatching, WAF, removing shadow IT
HacktivistIdeology or protestWebsite defacement, DDoS on public channelsDDoS scrubbing and content integrity checks
State-sponsored / APTEspionage, strategic disruptionSWIFT terminals, core banking, vendor supply chainNetwork segmentation and third-party assurance
Malicious insiderMoney, grievance, coercionCustomer data, dormant accounts, overridesMaker-checker and privileged access review

Two rows deserve extra attention. The state-sponsored row is why cross-border payment messaging terminals sit behind their own control family — that terminal is a strategic target, not an opportunistic one. The insider row is why privileged access reviews are a quarterly obligation rather than an annual formality.

Insider threat controls inside a bank branch
Insider threat controls inside a bank branch

🏦 How Each Profile Actually Hits an Indian Bank

Classification only earns its keep when you can trace a real attack path, so here is how the types of hackers in cyber security behave once they are pointed at an Indian bank.

Script kiddies scan the internet indiscriminately for unpatched software and default credentials. They rarely target a bank by name; they find a forgotten UAT server that someone exposed for a weekend demo and never took down. The damage is usually defacement or a data dump, but the reputational hit is real and the RTI-style questions that follow are worse.

Hacktivists pick their target deliberately and time it to an event. Their preferred instruments are distributed denial of service against public-facing channels and homepage defacement, because both are visible. Availability, not confidentiality, is the asset under attack.

Black hats follow the money and increasingly attack the customer rather than the bank, because the customer is the cheapest door. That is why social-engineering variants such as sim swap fraud in banking remain so productive — no perimeter is breached at all. The IIBF chapter on Human Traits exists precisely because urgency, authority bias and fear of loss are exploitable in ways that no patch fixes.

Advanced persistent threats behave differently: they get in quietly, stay for months, escalate privileges, study your payment workflow, and act once. Detection depends on behavioural anomalies — a service account logging in at 3 a.m., a workstation talking to a payment server it has never touched — rather than on signatures.

Insiders need no intrusion at all. They already hold credentials, know which approvals are rubber-stamped, and understand which reports nobody reads. Rotation of duties, mandatory leave, and dual authorisation on high-risk actions are the controls that work here, and they are administrative rather than technical.

📌 Remember: An attacker's category can change mid-incident. A black hat who steals credentials often sells them to a second party who exfiltrates data and a third who deploys ransomware. Your incident report must describe the observed behaviour, not guess at a single label.

🛡️ Mapping the Types of Hackers in Cyber Security to Indian Law

Once an incident is confirmed, classification drives the charge and the reporting route. The Cyber Laws In India chapter is the anchor here, and these provisions of the Information Technology Act, 2000 carry most of the exam weight:

  • Section 43 — unauthorised access, downloading, damage or introduction of contaminants; civil liability to pay compensation.
  • Section 43A — a body corporate that is negligent in maintaining reasonable security practices while handling sensitive personal data owes compensation to the affected person.
  • Section 65 — tampering with computer source documents.
  • Section 66 — the criminal counterpart of Section 43, where the act is done dishonestly or fraudulently.
  • Section 66C — identity theft, including fraudulent use of another person's password or electronic signature.
  • Section 66D — cheating by personation using a computer resource, the workhorse provision for phishing and impersonation frauds.
  • Section 66F — cyber terrorism, the provision most relevant to state-sponsored actors, punishable with imprisonment for life.
  • Section 70B — CERT-In as the national nodal agency for incident response.

One trap worth memorising: Section 66A was struck down as unconstitutional by the Supreme Court in 2015 in Shreya Singhal v. Union of India. Any option presenting it as live law is wrong.

On the operational side, an incident must move through your documented escalation path — containment, evidence preservation, regulatory reporting, customer communication — as set out in the Incident Management chapter. Note the distinction examiners love: the six-hour reporting clock belongs to the CERT-In Directions of April 2022, while the RBI's own expectation of reporting within two to six hours traces to its 2016 cyber security framework circular for banks. They are separate obligations, not one.

Where a customer loses money, liability is settled not by the attacker's label but by how quickly the customer reported and whether the bank was deficient — see our explainer on customer liability in unauthorised transactions. Candidates preparing across papers will find the same control logic applied to market infrastructure in NDS-OM and government securities trading, where access discipline on a trading terminal matters as much as it does on a payment terminal. More revision material on this paper sits under the Prevention of Cyber Crime article hub.

📎 Always cross-check the current text of the governing circular on the CERT-In website before you rely on it in the exam hall or at your desk.

🧠 Practice MCQs: Types of Hackers in Cyber Security

Q1. Which attacker profile tests a bank's systems only after a written engagement with an agreed scope and disclosure route? (a) Grey hat (b) White hat (c) Black hat (d) Script kiddie

Answer: (b) — A white hat operates under prior written authorisation, which is what separates the activity from an offence.

Q2. A researcher enters a bank's server without permission, takes no data, and then emails the CISO offering the flaw details for a fee. He is best classified as: (a) White hat (b) Hacktivist (c) Grey hat (d) State-sponsored actor

Answer: (c) — Unauthorised entry without malicious intent is the defining grey-hat pattern, and it is still unauthorised access in law.

Q3. Which provision of the IT Act 2000 deals specifically with cheating by personation using a computer resource? (a) Section 66C (b) Section 66D (c) Section 66F (d) Section 65

Answer: (b) — Section 66D covers cheating by personation using a computer resource; Section 66C covers identity theft.

Q4. The current legal status of Section 66A of the IT Act 2000 is that it was: (a) Amended by the 2008 amendment (b) Struck down as unconstitutional by the Supreme Court in 2015 (c) Merged into Section 66F (d) Restricted in application to intermediaries only

Answer: (b) — Section 66A was struck down in Shreya Singhal v. Union of India (2015) and cannot be invoked.

Q5. Which attacker profile is best countered by maker-checker discipline and privileged access reviews rather than by perimeter defences? (a) Script kiddie (b) Hacktivist (c) Malicious insider (d) External black hat

Answer: (c) — A malicious insider already holds valid credentials, so administrative segregation controls matter more than perimeter technology.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Is a grey hat hacker punishable under Indian law even if no damage is caused?

Yes. Unauthorised access is actionable under Section 43 of the IT Act 2000, and Section 66 applies where the access is dishonest or fraudulent. Absence of damage may affect the quantum of compensation but does not create an exemption.

What makes an ethical hacker legally different from an intruder?

Prior written authorisation with a defined scope, time window and reporting route. Without that document, identical technical activity becomes unauthorised access, which is why banks issue engagement letters before every VAPT exercise.

Which hacker profile poses the greatest risk to a bank's customer data?

Statistically the malicious insider, because the access is already legitimate and no perimeter alarm fires. Controls are administrative — segregation of duties, mandatory leave, dual authorisation and periodic privileged access recertification.

How many attacker categories should I memorise for the IIBF exam?

Seven cover the syllabus comfortably: white hat, black hat, grey hat, script kiddie, hacktivist, state-sponsored or APT, and malicious insider. Learn each by motive and by the control that defeats it rather than by definition alone.

Knowing the types of hackers in cyber security is the cheapest analytical tool in a banker's kit — it turns a vague incident into a short list of likely motives, likely targets and applicable sections of law. Revise the comparison table until you can reproduce it from memory, then test yourself against timed chapter mocks and the risk chapters in our CAIIB course to see how the same control logic repeats across papers.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading