You Are Under Attack
You are under attack. Whenever you engage in Internet-based resources or access “things” via the online world, you are being attacked. Your devices and accounts are being monitored, probed, tested, and bombarded with code and communications meant for harm. By simply plugging into the Internet or connecting to WiFi, your device will be almost instantly engaged with digital attacks.
When is this happening? Always. If your SmartPhone, tablet, or computer is on and connected to WiFi or plugged into a network, it is being attacked. Your online accounts are always “on” inside the servers in remote data centers. The information you last transmitted is still buzzing around the Internet. It may be saved on disk somewhere, or someone may be viewing it right now. But the attacks are constant.
What we call online adversaries or threat actors have built tools and infrastructure that runs automatically 24x7x365 scanning every IP address, website, web application, login interface, router, remote access service…everything. They work to identify what exists, and then they automatically identify what it is and then probe it with selected malicious payloads to see if they can break in or otherwise compromise the resource. But these attacks are not just coming from automated systems.
Online attackers are people, and many of them attack by lurking in places of common use, spreading their influence and sin, recruiting others to join them, grooming them into participation or inviting them into their schemes. They hunt for allies and influence and find reward in that.
Other adversaries are of a more crafty nature, blending into normal society and operating complex espionage and fraud campaigns. They hunt for specific targets and work diligently over time to gain confidence and ever expanding layers of trust, influence, and access, constantly working toward whatever final outcome they seek.
All of the adversaries behind these attacks are targeting you. Their methods and tradecraft, the degrees of success, and their intended impact may vary greatly, but they are constantly active. And behind all of these attacks are people, though unlike we within whom goodness prevails, in them darkness prevails. Whether they intend harm can be debated, and in some parts of the world, well educated and good intentioned people turn to a life of cybercrime and fraud, because it is the only way to earn money via the skills, talents, and interests they have. Others are simply operating on behalf of the orders from the government they live under. Indeed, in China, every citizen is required by law to participate in cyber espionage. In North Korea, financial crime is one of the primary sources of money flowing into that isolated state.
When it comes to their victims, for the most part, these adversaries are simply looking for targets of opportunity; someone who crosses their path, or falls within their crosshairs, or responds to their scanners. But there are also predators lurking, stalkers, spies, and malicious individuals who have specific targets or types of targets in mind and they intentionally work their way toward them so they can strike without warning for the greatest effectiveness against their prize.
This isn’t hyperbole. The Cybersecurity industry that fights this adversary with people, process, and technology working 24x7x365 is a multi-trillion dollar one.
According to a Cybercrime Magazine assessment, in 2025 the cybercrime economy was expected to exceed $10 trillion USD, possibly closer to $12 trillion. This is effectively the third largest economy in the world. It is an economy that has been growing steadily at around 15% each year with an increasing upward trend.
To put this $12 trillion economy into perspective, the total US economy is estimated to be $29 trillion, making the cybercrime world about ⅓ of that. For references, the US economy is ¼ of the total world economy. It’s a really big problem that causes an estimated $16 billion a day in damages globally.
You Are Being Abused
It isn’t only the obvious bad guys who are positioned as your digital adversary. In fact the very platforms and providers who facilitate your access to the Internet have been designed to function in what many have characterized as predatory in nature. The online world has been drawn together toward a digital center that is a few core platform providers: Google, Meta, X, Microsoft, Apple,
These platforms and services are designed to capture and keep your attention, so that many of us become addicted to them. In exchange for our addiction, we participate with the platforms and their services, and that generates data which the platform providers collect, analyze, and monetize as if it is some precious metal and we are like miners handing them the raw material. This is called data monetization and it is the financial boon that drives the wealth of Silicon Valley.
The information these providers collect about you and the lengths they go, including very specific wording of their use policies and service terms and conditions, exposes them as malicious in nature. This is especially the case of platform providers who openly claim to be concerned about privacy and security, yet intentionally spy on their own customers, build loopholes into their “conditions,” and build backdoors into their code to siphon off what seems to be incidentally exposed.
The original purpose started with collecting data to feed targeted advertising, but many of these platforms and digital outlets are purpose built for and engaged in larger scale influence operations. They are designed to monitor you constantly, control what you are aware of, thinking about, and therefore what you are doing. But they also partner with powerful individuals and organizations engaged in a cultural revolution within the West. The goal is to reshape the world.
Indeed, in recent years Tech Leaders have been called to testify before Congress about the predatory nature of their platforms, not only criticizing how the platforms are used but the very nature of the platforms themselves. Additionally, these Tech Providers have been openly accused by the public in general of engaging in election interference and other politically based suppression of free speech, undermining of parents, deplatforming of voices, and artificial elevation of radical ideas…all in an attempt to engage in a cultural transformation of the West. And they don’t deny it. Instead, we have witnessed numerous executives within Big Tech lament that they have not been successful in achieving their desired political and cultural outcomes. They want to do more.
This too isn’t hyperbole. It’s well documented.
You are under attack. Constantly.
A Battle for Power and Control
Why is the world so openly hostile toward you and I by default? Because you have resources and power. You store money online that is accessible via the Internet. You store information online that can be stolen and used for financial gain, fraud, impersonation, or other forms of abuse. You have computer resources that can be hijacked and used for malicious online operations. You have contacts saved in email or on your computer or smartphone that represent more targets. You are a friend to someone else they want to access or influence. You have influence over your own world. You purchase things, you vote, you promote, you circulate, you advertise…you do many things that can be leveraged in order to achieve some larger outcome by anyone who can control you.
And those are just some of the few reasons adversaries are interested in you.
But you are under attack. Constantly.
Signs and Symptoms
If this is true, that we are under attack constantly, then what is the result? Where is the impact? In the following sections, we will unpack that answer and reveal to you just how incredibly damaging cybercrime and online manipulation are.
Most of the truly malicious activity of classical cybercrime is thwarted automatically, thanks to the investment businesses and IT providers make in detecting and preventing attacks, or hardening software, services, and devices so they are impervious from these bombardments. Purpose-built processes and technology operated by dedicated staff keep code secure and systems protected from exploitation and abuse. This is what defines the Cybersecurity industry.
But that cost is of course passed down to the consumer and inflates the prices of technology and services. The Cybersecurity industry itself is estimated to be valued between $200-300 billion dollars globally, and that’s mostly just among vendors who sell Cybersecurity tools, technology, and services to other businesses and government agencies. That doesn’t count the cost incurred by businesses to hire and maintain security professionals, and that doesn’t necessarily include the cost consumers pay for solutions at home like AntiVirus.
As mentioned before, the impact of cybercrime has resulted in an underground economy where stolen information, services, and other illicit and illegal goods and services are traded, and is estimated to be valued at around $12 trillion USD, growing at a rate of about 15% every year. The mere fact that this exists is a sign of the transfer of wealth via the transfer of digital property. That money is coming from somewhere.
Traditional adversaries work to steal information like passwords, email addresses, physical addresses, account numbers, social security numbers, details about individual people, location information, pictures, plans, documents…anything that can be sold by someone looking to buy and weaponize that data. Buyers of all this information have various uses and purposes, but mostly it is to engage in attacks and fraud.
Some adversaries earn their living simply by building hacking tools, developing malicious code, selling malware, bots, or compromising Internet infrastructure that they then rent out access to for use by other adversaries who conduct the actual data theft.
Other adversaries leverage attack tools to cause disruptions in Internet provided services or business functions, demanding payment in order to stop the attack so their victim’s normal operations can resume. Often these attacks are seen and reported as DDoS or ransomware attacks, but they often happen in secret and are not always made public. The organizations who pay off cyber criminals usually do so quietly, and some attacks that consume resources to disrupt business operations are designed to increase the burden on the business without overwhelming it. They can be a sort of proof of concept threat; pay us or we will increase the attack. So you and I never “see” it, but the businesses do, and they pay for it, and that cost is absorbed by consumers.
The underground economy of the cybercriminal world is also used to resource human trafficking and real-world criminal organizations, the mafia, cartels, and others. The impact of cyber crime fuels the international drug trade, weapons trade, human trafficking, human abuses, slavery, and in the case of Iran, North Korea, and other nation states, cyber crime is a source of national income. In fact, the North Korean nuclear weapons research program is said to be mostly funded by cybercrime - primarily through crypto currency theft or coin mining operations. For China, cyber espionage and theft of business secrets from the West largely powers their economy, at least by giving them a competitive advantage in international trade.
Data monetization by Big Tech and the influence operations they run via Social Media and other “free” digital services and apps basically runs the US economy since Big Tech is almost exclusively what is driving the value of the stock market and has been for several decades. The mere fact that Google is free, as are Meta, WhatsApp, Gmail, Yahoo mail and many other apps and services, is an indication of the exploitation of you and I and the monetization of our information by the so-called good guys who run the tech industry. Have you ever thought about that? How did Google and Meta become two of the largest companies in the world by offering “free” services? They achieved this before offering additional streams of revenue to professional contexts. It is, in my opinion, simply another form of property theft but one that is achieved through coercion and deception rather than overt stealing.
These are some of the less visible impacts of cybercrime, but you and I will also from time to time feel the direct impact. You may find malware or viruses running on your computer and will have to spend time and/or money to clean them off and restore your system. You may have your credit card stolen and fraudulent charges posted to your accounts. You may have your identity stolen and used to access financial or government services. It’s also common for fraudsters to file fake tax returns using your information so they can get massive tax refunds on your behalf. In this case, when you go to file your return you will be denied because someone else already did, using your identity. That can lead to a lengthy process of proving fraud and can cause a lot of additional stress and delays in a process that is already a burden for most.
Fraudulent purchases using stolen credit cards were estimated to impact 63% of US credit card holders, with 62 million Americans reporting fraudulent charges in 2024 exceeding $6 billion total.
That’s $6 billion in purchases, many times with the purchased good or service having been shipped or delivered by the vendor before the crime is noticed. Some of the most commonly purchased items with stolen credit cards are gift cards, transportation passes, or tickets to sporting events. The moment the transaction completes, the funds have changed hands (digitally) and possibly used to procure access or goods.
Someone has to foot this bill, and that’s usually our banks who write it off as losses, but also pass the impact in part to their customers through banking fees, interest rates, and other means of recouping the damages. Those huge credit card fees and interest rates are not only about issuing credit to high risk customers. Banks have to factor in recovering financial losses from fraud and all the infrastructure they have to invest in for fraud detection and recovery operations.
Fortunately about 90% of cases involving fraudulent credit purchases are “refunded” by banks, but not all are, and again, those banks have to recover the loss somehow.
Fraudulent loans or lines of credit opened using identity theft is another form of financial fraud. This is a little more difficult to get an accurate picture on the total scale, but fraudulent loans have been reported in small amounts totaling a few thousand dollars, to moderate amounts in the tens of thousands. The most common form of financial fraud involving credit is opening credit card accounts using stolen identities.
According to Experian, a credit management company,
The FTC logged 1.1 million identity theft reports in 2024
There were 2.6 million identity theft related cases of fraud in 2024
Total losses were estimated at $12 billion in that year alone
That’s just among the most common forms of financial fraud.
It doesn’t stop there. Another impact to you and I as a result of cybercrime, is the time and money we spend dealing with these issues as well as the toll the stress can take on our bodies and minds.
Dealing with a ransom note, blackmail, financial fraud or theft, or other personal threat has been so damaging that it has been attributed to cases of broken homes, depression, and suicide. These are extremes of course, but they do happen.
The impact is certainly there. It’s just been largely masked over so life can continue for most people without having to make drastic changes. Afterall, what would happen if we all suddenly asked our banks and providers to take cybersecurity seriously? Much about the convenience of current life would end. So, the impact of cybercrime is pushed to the background…but we feel it.
Stiffled Economy
Cyber espionage by nation state adversaries has resulted in the decimation of numerous US businesses and entire industries, not to mention the competitive advantage it gives those who conduct the espionage.
Perhaps the most obvious of these examples is the solar technology industry and its related battery industry. Originally, almost all development of solar technology was done in US companies and mostly in Silicon Valley and nearby public institutions and research centers. Engineering, material science, manufacturing, production and distribution - it was almost all done in a closed manner within the US. However, largely through various forms of industrial espionage, including cyber, most of the trade secrets of this industry were stolen and used to create or improve competitors in China. Today, there are almost no solar companies in the US and almost all battery production, engineering, and development work is done in China by Chinese companies.
It has actually become common practice for US companies developing new ideas to have those ideas stolen through digital espionage by Chinese actors. The ideas are then given to Engineers and Business Developers in China who finish them or file patents for them in part, forcing the US company who originally developed the idea to cede use of it in the marketplace.
Influence, Despair, and Brain Rot
The impact of online attacks are not only monetary and they are not only administered by those we commonly recognize as criminals or national enemies.
The “free” services we use and the devices themselves are being operated by US Tech Companies in ways that have been described in Congressional testimony as “predatory,” “addictive,” “harmful.” Social Media is by nature designed to be a tool of influence and radicalization. In fact, in form it answers what the US Government has described are the three core accelerants for political radicalization: frequency of exposure, peer participation, and method of engagement. Social Media has been proven to be addictive, it is designed to reward participation, it seeks to centralize much of life into one place, and it is focused on leveraging participation to gain influence over others.
Google and Meta/Facebook are among the worst of the digital predators, and they incorporate their predatory policies into all of their sub-products, affiliates, and acquisitions. In fact, Meta and Google are among the largest brokers (buyers and sellers) of information about people that has been collected by software, hardware, and service providers. They buy this information so they can use it.
The mental health effect of ongoing use of Meta, Instagram, and TikTok has been studied and well documented by many health organizations including the National Institute of Health (NIH). The modern phenomenon known as brain rot has been directly attributed to use of these platforms, and TikTok has earned a psychological diagnosis of its own called TikTok Brain which is characterized by depression, isolation, the inability to pay attention, and other forms of both cognitive decline as well as interpersonal and relational dysfunction.
Some notable Psychologists and Neuropsychologists including Jordan Peterson and J.D. Haltigan, have professionally attributed the transgenderism movement and its related identity and meaning crisis to social media use among teens, young adults, and adults who cannot tolerate or regulate these platforms appropriately. They both regularly attribute a psychosis called “cluster B personality disorder” to the cultural movement of our times, and cite the root method of its spread as social media.
And the providers of these technology platforms not only know of these impacts from their “free” services, but they also intentionally feed and expand them as the Tech Leaders view themselves as agents of change, holding a unique position and power in our society that can be wielded to shape, change, and in their minds to fix our culture.
This is why I include many of the Silicon Valley Big Tech executives as adversaries.
The AI Revolutionaries
And it’s not only the Big Tech platforms and services that are having a negative impact on our culture and mental health. The AI Revolution itself and the men behind it promises to completely revolutionize the human condition by transferring all the activity of mankind to machines so we are freed from our natural state of being and can pursue a higher plane of existence. This is just another form of cultural revolution as it is commonly described as transhumanism. It is the next step from its predecessor, transgenderism. In fact one of the leaders of the AI Revolution, Peter Thiel, famously commented that his criticism of transgenderism is that it was “too pathetically weak,” and he sees AI as a means to achieve total transformation of who we are as a species.
The main method by which the transhumanism agenda is being implemented is through the re-purposing of a technology known as AI and encouraging people to use it in every aspect of life to replace whatever it is we do.
Work, education, wisdom, knowledge, friendship, creativity, planning, play, entertainment, relationships, faith, medicine…every aspect of life that makes human living have meaning, purpose, and value, we are being asked to move into the machines so that we cease doing those things.
The early results are so far devastating. The meaning & identity crisis brought by the online world of social media and physical isolation is accelerating. Reports of despair and depression are increasing. Careers are being ended, as are families, marriages, friendships, pursuits of interests and more.
All of this earns these tech leaders a place among the list of online adversaries, because they seek to force their will upon us toward an end that is devastating to us but empowering to them, and it is being done mostly through deception and through dark influences.
Introducing Your Adversary Problem
One of my career highlights was when I was working for a software company that developed applications for consumer and small business financial management. The company had a huge problem with fraud, but they had no real handle on how it was being conducted, nor by whom. As the head of threat intelligence, I took on a project to identify some of the individual people who were running criminal gangs that leveraged this company’s software to commit massive amounts of financial fraud. I found some of them. Some were in Africa, some were in Europe. At a presentation before the legal department and Chief Legal Officer of the company, I showed them the faces, operations, and scale of their adversary. It was a game changing moment.
Hackers. Fraudsters. Adversaries. Predators. Hacktivists. Espionage. Cybercrime. Digital Health. Cybersecurity. Nation State Threat Actors. These are all buzzwords used in a technical context by speakers of a language that is foreign to many. That’s why when I describe to people that I work in Cybersecurity defending individuals and organizations against their adversary and online threats in this digital age, many people have no basis for grasping what I’m talking about, what I actually do, and how that has any relationship to them. In fact, when I was approached about my first job in what was called computer security at the time, I thought it meant something like being a security guard to physically protect computers at businesses. I get it. These words are a bunch of jargon. But the concepts behind the jargon are deeply important to you.
Many people I talk to about the Internet will readily recognize that there is some harm that comes from it. Online influence, social media and its influencer culture, screen time, identity theft, data breaches - these are all topics that have immediate relevance in common conversation, because they refer to the negative impact that has flown out of the Internet-based adversaries, and touched you and I personally. Yet these things are still clouded in mystery because they come from this technical other world and still seem to belong to another lexicon.
So the goal of this article is to bridge the gap. To bring you basic awareness of the problem that Cybersecurity professionals are so concerned about, and where those problems come from: sinful people of the digital age.
Before the digital age, we knew these people though we called them different things and they materialized in our physical world. We called them criminals, thiefs, robbers, gangsters, spies, conmen, the mafia, foreign agents. You know, the people who live among us but have corrupted souls & character and turn to abusing others for their source of personal enrichment.
They are the same people behind the threats we face today via the Internet. If you think about it this way, if a burglar chooses to target your home for theft, then they are your adversary. They have declared a sort of mini-war against you. They see what you have and have decided to take it by force, even by injury if the need be. In this way they are your enemy. They are still there, walking among us and dressed as if they are our peers, contributing to society in a constructive way. But many of them have turned their energy and activity to using the Internet to facilitate harm. And their numbers have grown dramatically.
This is also the case of someone you might meet in the real world who sees an innocence or vulnerability in you that they can take advantage of in order to get you to act on their behalf. In the real world, we call these people con artists or scammers. But those who do this via Internet provided services are so good at masking their deception that we don’t see it, yet they wield tremendous power over us that yields enormous financial wealth and power for them.
You might find it interesting to know that in the professional world, we usually characterize this network of online enemies and our combat with them as a war. We even use military language to characterize the Internet as a battlefield, referring to attacks as “campaigns,” orchestrated according to a “kill chain,” bringing a collection of “tools, techniques, and procedures” to bear against targets to achieve objectives. There was even talk back in the early 2000s of designating Cybersecurity professionals as war fighters. I think this is the right way to characterize the situation.
In The Art of War, Sun Tzu wrote, “If you know the enemy and know yourself, you need not fear the result of a hundred battles.” I often rephrase this by saying we need to understand our adversary, and understand ourselves in relation to them, so we can defend ourselves effectively. Or more simply put; know your adversary, know yourself, act accordingly.
Now you know your adversary and what you mean to them. Now you can choose how to act accordingly.









