DEV Community

Cover image for The hackers who stole over a billion dollars taught me how to defend everything I build
Ksatria Bintang Samudra
Ksatria Bintang Samudra

Posted on

The hackers who stole over a billion dollars taught me how to defend everything I build

I am a builder who used to break things. Penetration testing and bug hunting, that was my start before I went full AI-native engineer. And the best security lesson I ever learned is simple: you cannot defend against something you refuse to understand.

So I study the attackers. Not to become one, to stop being easy.

Here is the field guide I wish someone had handed me. The people and the methods actually trying to get into the apps you and I ship, and the one move that stops each of them.

1. Phishing, the attack that skips your firewall

Most breaches do not start with genius code. They start with a convincing email. Phishing does not hack your server, it hacks you. A message that looks like your bank, your boss, or your cloud provider. One click, one login on a fake page, and the attacker walks in through a door you opened for them.

It is boring. It is also how the biggest breaches in history began.

Defense: slow down. Check the sender's real domain, never enter credentials from a link, and turn on 2FA everywhere so a stolen password is not enough.

2. Brute force, the attack with infinite patience

A computer does not get tired. Brute force and credential stuffing just try passwords, millions of them, until one works, usually using leaked passwords from some other site you reused. Your "clever" password from 2019 is probably already on a list.

Defense: long unique passwords (a manager, not your memory), 2FA, and rate limiting that locks the door after a few bad tries.

3. RATs, the quiet houseguest

A Remote Access Trojan is exactly what it sounds like: malware that hands an attacker a remote seat at your machine. Camera, files, keystrokes, all of it. It usually arrives disguised as a cracked app, a "harmless" attachment, or a fake installer. Then it just sits there, watching.

Defense: do not run what you cannot trust. No pirated software, no random attachments, and keep your OS and security tools updated.

A figure at a keyboard in the dark

4. Ransomware, the hostage-taker

This is the one that makes the news. Ransomware encrypts everything you own and demands payment to give it back. It has frozen hospitals, pipelines, and entire city governments. Pay, and you are funding the next attack with no guarantee. Do not pay, and you had better have backups.

Defense: backups, offline and tested. Not "I think it is backing up." Tested. A ransom note is a lot less scary when you can just wipe and restore.

5. Lazarus Group, when the attacker is a country

Here is where it stops being lone hackers in hoodies. Lazarus Group is a state-linked operation tied to North Korea, and they are not after your selfies. They are after money and leverage, at national scale.

Their record is terrifying: fraudulent SWIFT transfers that drained tens of millions from a central bank, a worm that locked up hospitals across the world, and a string of crypto heists, one of which cleared well over a billion dollars in a single hit. These are not kids. They are a funded, patient, professional adversary.

And the lesson from the top of the food chain is the humbling one: no single trick saved their victims, and no single trick would have stopped them. Layers did. People who verified, who segmented, who assumed breach.

Defense: assume you are a target, even if you feel too small to matter. Especially then.

What studying all of this actually did to me

It did not make me paranoid. It made me calm.

Because once you understand the attacker, security stops being a vague fog of fear and becomes a checklist. Phishing, verify. Passwords, unique plus 2FA. Downloads, trust nothing. Data, back it up. Yourself, assume you are a target.

I build with that mindset baked in, not bolted on, because I have seen the other side. And the single most dangerous sentence in tech is still the quietest one:

"Who would ever bother attacking me?"

They already are. The only real question is whether you studied them first.


I am Ksatria Bintang Samudra, an AI-native full-stack engineer with a penetration-testing background, open to remote work worldwide. More of what I build at ksatriabintangsamudra.com.

Top comments (0)