Get fresh insights, pro tips, and thought starters–only the best of posts for you.
Big-game hunting in cyber security is a targeted attack strategy in which cybercriminals focus on large organizations with valuable data, critical operations, and a greater ability to pay ransom demands. Understanding big-game hunting in cyber security helps organizations recognize why attackers invest time infiltrating enterprise environments before launching ransomware or other extortion attacks. Instead of targeting many victims, they focus on fewer, high-value organizations to maximize financial returns.
Large enterprises often have complex IT environments, sensitive business information, and operational dependencies that make them attractive targets for extortion.
Attackers use this strategy to:
Attackers typically plan and execute these campaigns over an extended period instead of launching opportunistic attacks.
Threat actors usually conduct reconnaissance and expand their access before carrying out the final stage of the attack. A typical attack progression includes:
This method increases operational disruption and strengthens the attacker’s leverage during negotiations.
Targeted enterprise attacks often share several common characteristics.
| Characteristic | Security significance |
|---|---|
| Enterprise targets | Increase potential financial return |
| Extended reconnaissance | Identify valuable systems before attack |
| Privilege escalation | Expand attacker access |
| Lateral movement | Reach critical assets |
| Data theft | Increase pressure through extortion |
These characteristics distinguish targeted enterprise attacks from large-scale opportunistic campaigns.
Organizations should limit attacker movement and detect suspicious activity before attackers compromise critical systems. Important security practices include:
These controls help reduce the likelihood and impact of targeted ransomware operations.
Attackers often move across multiple systems before deploying ransomware during big-game hunting attacks. Security teams need endpoint visibility to track attacker activity, identify compromised devices, and determine how attackers reached critical systems.
Hexnode XDR supports investigations by providing:
These capabilities help security teams investigate targeted attacks and coordinate response efforts.
No. Big-game hunting is an attack strategy that often leads to ransomware deployment, but it can also involve data theft and other extortion techniques.
Large enterprises, healthcare providers, financial institutions, manufacturers, government agencies, and other organizations with valuable data or critical operations are common targets.
Attackers often map the environment, obtain privileged access, identify valuable assets, and maximize the potential impact before carrying out the final stage of the attack.