Cyber Security Basics 📂 Cyber for Students · 3 of 6 30 min read

Insider Threats, Zero-Day Attacks & Real Cyber Incidents

Discover how the deadliest cyberattacks actually happen — from Edward Snowden's 1.5M-file leak to the Cosmos Bank ₹94 crore heist and the SolarWinds supply-chain breach. This guide breaks down insider threats, zero-day exploits, real-world incidents with newspaper references, and emerging 2026 trends like AI phishing, deepfake fraud, and post-quantum risks. Includes visual diagrams, case studies, and 8 non-negotiable defence rules.

Section 01

The Enemy Inside — Why Insiders Are the Deadliest Threat

Edward Snowden — 1.5 Million Files From the World's Most Secure Agency
In May 2013, a 29-year-old NSA contractor named Edward Snowden boarded a flight to Hong Kong with four laptops. Inside them was arguably the largest intelligence leak in history — an estimated 1.5 million classified files from the National Security Agency of the United States.

The NSA had firewalls that could stop nation-states. It had encryption that took supercomputers years to break. It had the best cyber talent on earth. And yet a single trusted contractor walked out of the building with the crown jewels on ordinary USB drives.

Snowden was not a genius hacker. He was an insider with legitimate access — the most dangerous role in every organisation on earth.

— covered by The Guardian, Washington Post, and Der Spiegel from June 2013 onwards.

Firewalls face outward. Intrusion detection systems watch the perimeter. Antivirus scans for malicious code. But insider threats already have the keys, know the layout, and — crucially — are trusted by the security controls themselves. This tutorial covers the twin nightmares of every CISO: insider threats and zero-day attacks, then walks through real breach case studies, emerging trends, and the practical defences that actually work in 2026.

📊
The Numbers Don't Lie

The 2024 Ponemon Institute Cost of Insider Risks report found that insider incidents rose 44% in three years, with the average annual cost per organisation now $16.2 million. Meanwhile, the average time to contain an insider incident is 86 days — nearly three months of undetected damage.


Section 02

The Three Faces of an Insider Threat

Not every insider is a villain. In fact, most insider incidents come from ordinary employees who made an ordinary mistake. Understanding the three categories is the first step to defending against them.

😈
The Malicious Insider
Intent to harm
A disgruntled employee, a departing engineer stealing source code for a competitor, or a spy planted years ago. Motivated by revenge, greed, or ideology. Rare — but individually catastrophic.
🤕
The Negligent Insider
Careless, not cruel
Emails the customer database to a personal Gmail "to work on at home." Uses Password123. Leaves a laptop unlocked at Starbucks. Accounts for ~55% of all insider incidents.
🤠
The Compromised Insider
Hijacked account
A legitimate employee whose credentials were phished, guessed, or stolen. From the security system's view, the attacker is the employee — same login, same VPN, same permissions. Hardest to detect.
⚠️
The Trust Paradox

Every access badge, every VPN account, and every admin credential is an act of trust. The more trust you extend, the more you enable both productivity and damage. The goal of an insider-threat program is not to eliminate trust — it is to make trust verifiable.


Section 03

The Insider Threat Kill Chain

01
Recruitment or Grievance
A passed-over promotion, a poor performance review, a foreign intelligence pitch, or a payoff offer on the dark web. Motive forms silently — HR rarely sees it coming.
02
Reconnaissance
The insider maps sensitive systems — customer lists, source repositories, salary tables. They already have access; they just need to know where the value lives.
03
Escalation
If their normal permissions aren't enough, they borrow a colleague's credentials, exploit a misconfigured share, or request "temporary" elevated access for a fake project.
04
Staging & Exfiltration
Data is collected into archives (often encrypted) and moved out via USB, personal cloud storage, printed pages, WhatsApp Web, or even code repositories disguised as legitimate commits.
05
Cover-Up & Departure
Logs are deleted, cache cleared, and the insider often resigns weeks before the breach is discovered — leaving behind neither smoking gun nor forwarding address.

Section 04

Insider Threats in the Headlines

Year Insider What Happened Damage
2013 Edward Snowden (NSA) Contractor exfiltrated 1.5M classified files revealing mass-surveillance programs (PRISM, XKeyscore). Global diplomatic fallout, immeasurable intelligence loss
2016 Harold Martin (NSA) Contractor stashed 50 terabytes of classified data at his home over 20 years. Bigger than Snowden — barely covered. 9 years in federal prison
2018 Anthony Levandowski (Google→Uber) Engineer downloaded 14,000 files of Waymo self-driving car research before joining Uber. Sparked landmark IP theft trial. $179M judgement; 18 months prison (later pardoned)
2019 Capital One (Paige Thompson) Former AWS engineer exploited a misconfigured firewall she had insider knowledge of. Exposed 106 million customer records. $270M+ in fines and settlements
2022 Twitter Whistleblowers Peiter "Mudge" Zatko and others disclosed serious security failings including thousands of employees with excessive access to production data. SEC investigation, congressional hearings
2023 Tesla Data Leak (Germany) Two former employees leaked 100 GB of internal data — customer complaints, employee salaries, Autopilot flaws — to Handelsblatt. Ongoing lawsuits; 75,000+ affected
📰
India Context

In 2019, The Economic Times and Business Standard reported multiple Indian IT service firms (TCS, Infosys, Wipro) tightening insider controls after cases of engineers stealing client source code. In 2022, a former Paytm employee was arrested for allegedly leaking sensitive user KYC data — reported by Livemint and NDTV.


Section 05

Zero-Day Attacks — The Unknown Enemy

Why "Zero Day"? Because You Have Zero Days to Prepare.
A zero-day vulnerability is a flaw in software that the vendor does not yet know about. A zero-day exploit is malicious code that weaponises that flaw. A zero-day attack is when that exploit hits real victims — before a patch exists, before antivirus signatures exist, before the world even knows the hole is there.

The name comes from developer folklore: the day the flaw becomes public is "day 1." Every day of secret attack before that is "day zero." From the defender's point of view, a zero-day is a lock without a key — and every attack is a first-time surprise.
🔥
Why Zero-Days Are So Dangerous

Traditional defences (antivirus, IDS, WAF) rely on known signatures — recognising an attack pattern seen before. A zero-day has no signature yet. Your security tools cheerfully wave the attack through. Only behavioural detection and defence-in-depth stand a chance.


Section 06

The Life of a Zero-Day — From Discovery to Patch

ZERO-DAY LIFECYCLE — THE WINDOW OF EXPOSURE
TIME → Bug born developer typo Attacker finds it DAY 0 WINDOW OF EXPOSURE — attacks in silence Vendor alerted bug reports flood in Patch shipped but many won't apply it DANGER ZONE — days to months of undetected attacks

Google Project Zero's 2024 report found the average zero-day lasted 44 days in the wild before public disclosure — and another 32 days before a patch was released.


Section 07

Famous Zero-Day Attacks That Changed the World

Year Zero-Day Where It Lived Impact
2010 Stuxnet Chained 4 zero-days in Windows + Siemens PLCs Physically destroyed Iranian uranium centrifuges. Opened the era of cyber-physical warfare.
2017 EternalBlue Windows SMB protocol (stolen from NSA and leaked by "Shadow Brokers") Powered WannaCry and NotPetya. Combined damage: $14 billion+.
2021 Log4Shell (CVE-2021-44228) Log4j — a logging library inside millions of Java apps Nicknamed "the internet's worst vulnerability." Nearly every major cloud service scrambled to patch within hours.
2021 ProxyLogon Microsoft Exchange Server 60,000+ organisations compromised globally. Attributed to Chinese group HAFNIUM.
2023 MOVEit Transfer (CVE-2023-34362) File-transfer software used by governments and Fortune 500 companies Clop ransomware group hit 2,600+ organisations, 90M+ individuals — BBC, British Airways, US DoE.
2024 XZ Utils Backdoor (CVE-2024-3094) Supply-chain zero-day planted in Linux compression library over 2 years Caught days before mass deployment. Would have compromised most Linux servers on earth.

Section 08

The Zero-Day Marketplace — Who Buys Vulnerabilities

A working zero-day is one of the most valuable digital assets on earth. There are three parallel markets where they trade — each with different ethics and price tags.

🏭
The White Market
Bug Bounties — Legal
Researchers report bugs to the vendor via programs like HackerOne, Bugcrowd, or Google VRP. Payouts: hundreds to $100k+. Apple pays up to $2M for a full iPhone chain.
🏢
The Grey Market
Brokers & Governments
Firms like Zerodium and Crowdfense buy exploits from researchers and resell them to Western intelligence agencies. A full Android chain: $2.5M+. Legal — but ethically contested.
👻
The Black Market
Criminal Forums
Dark-web markets and closed Telegram groups sell exploits to ransomware crews and state-sponsored groups. Prices are lower but demand is constant. This is where most enterprise zero-days actually get weaponised.
💰
Price Tag Reality Check

A remote-code-execution zero-day in a widely used product like Chrome, iOS, or Windows routinely fetches $1M–$2.5M in the grey market. That is more than most researchers earn in a decade — which is why the black-and-grey markets keep growing faster than bug bounties.


Section 09

Real-World Cyber Incidents — Headlines That Shaped Policy

Year Incident What Broke Consequence
2013 Target (USA) Attackers stole HVAC vendor credentials, pivoted to point-of-sale systems. 40M credit cards stolen. CEO resigned. $202M total cost.
2016 Bangladesh Bank Heist Attackers used SWIFT credentials + malware to send 35 fraudulent wire transfers. $81M stolen (typo saved another $850M).
2017 Equifax Unpatched Apache Struts flaw (CVE-2017-5638) — patch was available 2 months prior. 147M Americans' SSNs exposed. $1.4B+ settlement.
2018 Cosmos Bank (India) Malware inserted in bank's ATM switch. 12,000 fake ATM transactions in 2 hours across 28 countries. ₹94 crore stolen (~$13.5M). See Section 11.
2021 Kaseya VSA Ransomware inserted through a managed-service-provider tool — 1,500 businesses hit in one day. Grocery chains, schools, dentists offline across 17 countries.
2024 CrowdStrike Global Outage Not a hack — a faulty security update bricked 8.5 million Windows machines worldwide. Airlines grounded, hospitals scrambled, banks froze. $10B+ losses.

Section 10

Case Study 1 — SolarWinds SUNBURST (2020)

Widely regarded as the most sophisticated supply-chain attack in history. Attributed by US intelligence to Russia's SVR (nicknamed "Cozy Bear" / APT29).

🛠️ How the SolarWinds Attack Unfolded
Step 1
Foothold in vendor — Attackers compromised the build environment of SolarWinds, a Texas-based IT-monitoring vendor used by 300,000 customers worldwide.
Step 2
Malicious code planted — Attackers injected a backdoor (SUNBURST) into legitimate updates for Orion, SolarWinds' flagship product. The update was digitally signed by SolarWinds itself.
Step 3
Silent distribution — Over 18,000 customers installed the "trusted" update. The backdoor slept for two weeks to evade sandboxes.
Step 4
Selective activation — The attackers cherry-picked ~100 high-value targets from the 18,000 — US Treasury, State Department, DHS, Justice Department, Microsoft, FireEye — and moved deeper.
Step 5
Discovery — by accident — Cybersecurity firm FireEye noticed a strange second login on an employee's phone. Investigating that anomaly unravelled the entire campaign.
🔑
The Lesson

Your security is only as strong as the weakest vendor in your software supply chain. Every automatic update from every vendor is an act of trust. The industry response — SBOMs (Software Bill of Materials), executive orders, and reproducible builds — began the day SolarWinds was announced. Coverage: Reuters, Wired, and The New York Times, December 2020 onwards.


Section 11

Case Study 2 — Cosmos Bank Heist (India, 2018)

₹94 Crore Vanished in 2 Hours Across 28 Countries
On 11 August 2018, over a weekend when banking traffic was lowest, hackers pulled off one of the largest cyber-heists in Indian banking history. Their target: Cosmos Cooperative Bank, a 112-year-old Pune-based bank.

Working from India, they had spent weeks quietly implanting malware in the bank's ATM authorisation switch — the software layer between an ATM machine and the bank's core systems. When ATMs anywhere in the world requested transaction approval, the malware answered "approved" without ever consulting the core banking system.

In just two windows spanning under 8 hours, 12,000 fraudulent transactions were carried out at ATMs across 28 countries. A second wave used the SWIFT network to send $2M to a Hong Kong-based shell company.

— reported by The Hindu, Times of India, Indian Express, and later analysed in RBI's 2019 advisory to cooperative banks.

Attack Anatomy — What Went Wrong

❌ Weak Points Exploited
Malware planted via phishing email to a bank IT staff member.
ATM switch software had not been segmented from admin network.
Real-time transaction monitoring alerts were configured but not being watched actively during the weekend.
Legacy SWIFT terminal shared credentials — no MFA.
Money mules ready in 28 countries; cash drawn within minutes.
✅ What Should Have Been in Place
24×7 SOC (Security Operations Centre) with automated alerting for anomalies.
Strict network segmentation between core banking, ATM switch, and admin zones.
Behaviour-based fraud detection flagging 1000+ ATM hits in minutes across geographies.
MFA on every SWIFT terminal and privileged system.
Regular red-team exercises simulating exactly this scenario.
🌐
Regulatory Aftermath

Following Cosmos Bank, the Reserve Bank of India tightened cyber security norms for Urban Cooperative Banks (UCBs), mandated dedicated CISOs, and introduced tiered cyber-security frameworks based on bank size. Regulation almost always follows a headline.


Section 12

Emerging Trends 2026 — What's Changing Now

🧠
AI-Powered Attacks
Attackers use LLMs to write convincing phishing emails in any language, generate novel malware variants, and mimic writing styles of executives for whaling attacks. "Grammatical mistakes" are no longer a red flag.
LLM phishing, deepfake voice
🔒
Ransomware-as-a-Service
RaaS groups (LockBit, ALPHV/BlackCat, Cl0p) sell subscription ransomware to "affiliates" for a cut of the ransom. Even non-technical criminals now launch enterprise-grade attacks.
LockBit, affiliate model
🔌
Supply-Chain Attacks
Instead of attacking 1,000 companies, attackers compromise one vendor whose software those 1,000 use. SolarWinds, Kaseya, MOVEit, 3CX, XZ Utils — a growing epidemic.
vendor compromise, SBOM
🕷️
Deepfake Fraud
In 2024, a Hong Kong finance clerk transferred $25M after a video call with a "CFO" who was entirely AI-generated. Deepfake wire fraud is the whaling scam of 2026.
video & voice cloning
📡
Critical Infrastructure Targeting
Power grids, water utilities, hospitals, and railways face nation-state attacks. The 2023 attack on Israel's Aliquippa water plant and 2022 attacks on Ukrainian power grids are early warnings.
OT/ICS, cyber-physical
🔑
Post-Quantum Panic
Quantum computers will eventually break today's RSA and ECC encryption. Nation-state attackers are running "Harvest Now, Decrypt Later" campaigns — collecting encrypted data today to decrypt in 2030s.
PQC, HNDL

Section 13

Supply-Chain Attack — Visual Anatomy

SUPPLY-CHAIN ATTACK — ONE VENDOR, THOUSANDS OF VICTIMS
ATTACKER 1 breach TRUSTED VENDOR e.g. software update server [COMPROMISED] US Treasury Department Microsoft & FireEye Homeland Security (DHS) Fortune 500 Corporations State & Local Governments ... 18,000 more customers SolarWinds Pattern signed update = trusted delivery

One breach at the vendor becomes 18,000 breaches at the customers — because "update from a trusted source" bypasses every security control designed for external threats.


Section 14

Defence Playbook — What Actually Works Against These Threats

👤
Zero Trust Architecture
"Never trust, always verify"
Assume every user, device, and network is hostile until proven otherwise. Verify identity for every request, not just at login. Micro-segment networks so one compromised system can't reach the crown jewels.
📈
UEBA
User & Entity Behaviour Analytics
Baseline what "normal" looks like for every user, then flag deviations — downloading 10× more files than usual, logging in from an unusual country, accessing systems outside their job. Catches malicious & compromised insiders.
🛡️
Principle of Least Privilege
Just enough access
Every user, service, and process gets only the permissions strictly needed to do its job — and only for as long as needed. Review quarterly. This alone would have blunted Snowden, Capital One, and countless smaller leaks.
📂
DLP — Data Loss Prevention
Watch the exits
DLP tools monitor and block sensitive data leaving your network — through email, USB, cloud uploads, or printers. Modern DLP uses ML to detect data patterns even inside images and code.
🛠️
EDR / XDR
Behavioural detection
Signature-based antivirus misses zero-days. EDR (Endpoint Detection & Response) watches system behaviour — flagging suspicious process chains, memory injections, and unusual network calls. Essential for zero-day defence.
📚
SBOM & Supply-Chain Vetting
Know what you ship
A Software Bill of Materials lists every dependency in your product. When the next Log4Shell hits, you know in minutes — not weeks — which of your systems are exposed.

Section 15

Golden Rules — For Every Security Team

🛡️ The 8 Non-Negotiable Rules for Enterprise Cyber Defence
1
Assume breach. Design your systems as if the attacker is already inside. Micro-segmentation, encryption of data at rest, and continuous monitoring matter more than trying to make the perimeter unbreakable.
2
Least privilege, always. No employee needs access to "everything just in case." Review permissions quarterly, revoke stale ones immediately, and use just-in-time elevation for admin work.
3
Patch fast — measure it. Track MTTP (Mean Time To Patch) as a KPI. Critical vulnerabilities should be patched within 72 hours, not "next quarterly cycle."
4
Watch the humans, not just the machines. Deploy UEBA and DLP. Anomalous behaviour — mass downloads, off-hours logins, geographic impossibilities — is your earliest warning of insider or compromised-account activity.
5
Vet every vendor. Your supply chain is your attack surface. Require SBOMs, third-party audits, and contractual security requirements from every SaaS vendor and open-source dependency.
6
Rehearse the disaster. Run tabletop exercises and red-team drills at least twice a year. The middle of a real breach is not the time to discover your incident-response plan is a PDF nobody has read.
7
Log everything, retain for years. Insider incidents surface an average of 86 days after they begin. Without long-tail logging, forensics is guesswork.
8
Treat departing employees as high risk. Revoke access on the day of notice — not the last day of work. Audit downloads and cloud activity in the 30 days prior. Most IP theft happens in the resignation window.
🏆
Final Thought

Every incident in this tutorial — from Snowden to SolarWinds to Cosmos Bank — was preventable in hindsight. The controls that would have stopped them existed at the time. Security is rarely a technology problem; it is an attention problem. The organisations that stay safe are the ones that treat security not as a project with an end date, but as a discipline practised daily, forever.