7 types of cyber attacks & how to protect yourself against them
The increase in cyberattacks observed over the COVID-19 pandemic has had a lasting impact on how we access the web here in Australia. It’s growing more commonplace to use a VPN service in Australia, alongside other tools like password managers and antivirus software.
Although you may be familiar with malware or computer viruses, hackers can use many other methods to collect your data online. So what are these other cyber attacks, and how do you protect yourself against them?
We’ve outlined seven common cyber attacks experienced in Australia today. Read on to unearth how you can bolster your own personal cybersecurity strategy.

1. DoS/DDoS attack
Also known as a ‘Denial of Service’ or ‘Distributed Denial of Service’ attack, these hacking methods crash websites by inundating them with access requests. It’s important to note that DDoS attacks are a little different to DoS attacks. Whilst DoS attacks are carried out with one device, DDoS attacks use many devices to generate requests from many IP addresses. This large number of varied (or ‘distributed’) access requests makes it difficult to filter out malicious traffic. This then creates vulnerabilities on a website that can then be used to target site visitors.
As DoS/DDoS attacks work by using a myriad of IP addresses, you can reduce your risks of being involved in this cyberattack by concealing your IP address. You can conceal your IP address by using a VPN.
DoS/DDoS attacks can also target home networks by inundating routers with access requests. If you suspect that your home network has been hit with a DoS/DDoS attack, call your ISP (internet service provider) to block these access requests further upstream.
-
Fake WAP
Fake WAPs (or ‘wireless access points’) are just like honeypots, except they target unsuspecting users instead of hackers. A good example of a fake WAP is trying to connect to the Wi-Fi network in your local cafe and finding two networks with the same name. One of these networks has likely been set up by a third party who’s looking to lure local web users into a vulnerable position.
As is the case with any unsecured public Wi-Fi network, fake WAPs can be used by hackers to track your internet connection and gain access to personal user data. The best way to protect yourself against fake WAPs is to avoid connecting to any public Wi-Fi networks. Get into the habit of using your mobile hotspot if you need a connection on the go.
Users should also refrain from connecting to unfamiliar networks, even if they’re password-protected. It’s always better to be cautious when it comes to protecting yourself online.
-
Spear-phishing attack
As you may imagine, spear-phishing attacks are like phishing attacks, except with one major distinction. Spear-phishers use tailored attack strategies to go after their target.
Spear-phishers already have access to some of your personal information, derived from either previous successful phishing attacks or through data breaches. Because of this, it’s often more difficult to spot a spear-phishing attack over a phishing attack. Targets assume messages sent by spear-phishers are legitimate simply because the source has their personal information.
Users can avoid falling victim to spear-phishing attacks by maintaining a conscientious approach to responding to unverified messages, emails, or texts. If you’re not 100% certain of the source of any request for your personal information, then disengage and report the message as a potential scam.
-
Cookie theft
Websites are set up to record user sessions for performance analytics. Every time you access a website, the site creates a unique session ID that’s used to keep a record of the time you spent on that domain. Also referred to as ‘session hijacking’, cookie theft involves accessing a user’s session ID by duplicating the tracking cookie that enables these site visitor records to be created. Once the user’s active session is open to third-party onlookers, they can view wherever your device goes within the website.
As a large majority of cookie theft cases occur on public Wi-Fi networks, users are advised against accessing these and other unsecured networks. Doing so can help prevent you from falling victim to a session hijacking.
-
Rubber ducky
Don’t be misled by this attack’s adorable name! Rubber duckies are some of the most aggressive and avoidable cyberattacks plaguing device users today. This particular cyberattack involves converting USB sticks into emulations of USB keyboards. These emulated keyboards are also designed to trigger typing demands when plugged into a device. You can tell if you’ve been hit with a rubber ducky attack straight after plugging in a USB stick, as your computer will start typing commands independently.
You can avoid falling victim to a rubber ducky attack by refraining from plugging in any USBs from unknown sources. This safety precaution is already a measure implemented by organisations worldwide, both to protect against rubber duckies and a range of other USB attacks.
-
Man-in-the-middle attack
Man-in-the-middle (or MITM) attacks involve hackers positioning themselves between two parties in digital communications. This is achieved by taking advantage of vulnerabilities in websites or other digital channels. Once in position, hackers can then use their access to place their own malicious links. MITM attacks may also utilise web forms or emails to request personal information from the involved, unsuspecting parties.
MITM attacks are commonly observed across unsecured websites or websites that don’t have SSL certificates. By avoiding these unsecured channels, users can reduce their risks of experiencing a man-in-the-middle attack.
-
Bait-and-switch hacking
Bait and switch attacks involve hackers setting up malicious links online that are presented as legitimate or innocuous links. These bait-and-switch links can be presented as seemingly authentic ‘Click Here’ buttons or disguised as ‘X’ exit buttons. Bait and switch links can even take the form of clickable images.
You can avoid falling for bait-and-switch attacks by hovering over clickable links or icons and inspecting the URL that you will be directed to. If it’s an external link (or a link that directs you to another website), then err on the side of caution. Be sure to also look for signs of a potential scam, like poorly edited images or spelling mistakes.
Understanding how these cyberattacks work and what to look for is foundational knowledge in this digital day and age. Utilising a VPN service as well as other security measures can also help support your safety and security when accessing the web. Be sure to continuously invest in your cybersecurity measures to make sure that your personal security strategies stay as effective as possible.