Key Takeaways
- Hackers are categorized by “hat” colors that reflect their intent and ethics. Black-hat hackers are malicious criminals; white-hat hackers are defensive professionals, and gray-hats fall somewhere in between.
- Black-hat hackers typically act for personal or financial gain, targeting individuals, organizations and governments. Their methods include malware, data theft and selling stolen information on the dark web.
- White-hat hackers, also called ethical hackers, are the cybersecurity world’s first line of defense. Their job is to find and fix vulnerabilities before malicious actors can exploit them.
- Ethical hacking is a well-compensated and in-demand career path. The average ethical hacker earns over $100,000 annually, with salaries varying based on location, education and experience.
- Beyond the three main categories, several other hacker types exist, each with distinct motivations and methods. These include green-hats (beginners), blue-hats (contracted security testers) and red-hats (vigilantes who target black-hat hackers).
They may not be physically wearing a hat, but hackers are classified by their metaphysical “hat” colors. Have you ever seen a Western movie where the hero is wearing white, and the outlaw is dressed in black? Similar to that, white-hat hackers are the heroes of the cybersecurity world and black-hat hackers are the criminals. Gray-hat hackers fall in-between.
What Is a Black-Hat Hacker?
A black-hat hacker is a person that illegally breaks into computer networks. They may be aiming to steal log-in credentials, personal and bank information, modify or delete stolen data, sell data on the dark web, or commit other malicious cybercrimes. A black-hat hacker is most often acting for personal or financial gain, criminal intentions or employed by rogue nations. A black-hat hacker will typically work alone or with other like-minded hackers.
Famous black-hat hackers
Kevin Mitnick hacked into over 40 corporations, including IBM, Motorola and U.S. National Defense warning system. He was arrested and jailed and afterward became a cybersecurity consultant and white-hat hacker.
Julian Assange: The founder of WikiLeaks, a website where news leaks and classified documents can be published anonymously. He also hacked NASA, Stanford University and the Pentagon. He was arrested in 2010 under the Espionage Act of 1917.
What Is a White-Hat Hacker?
A white-hat hacker or ethical hacker is a cybersecurity professional who finds vulnerabilities in networks and software to secure weak spots. Their main objective is to find and fix any security openings before black-hat hackers can get to them. Another responsibility is to disclose vulnerabilities to software vendors so they can patch customer systems. A white-hat hacker may be employed as a penetration tester or similar profession, or they may work independently and freelance their skills.
Famous white-hat hacker
Tsutomu Shimomura: In 1994, Shimomura was hacked by Kevin Mitnick (when he was a black-hat hacker) and had his cellular phone tools and other private data stolen. Shimomura, a computational physicist and white-hat hacker, helped the FBI track Mitnick down. After a few months, Mitnick was arrested, largely thanks to Shimomura’s digital detective work.
What Is a Gray-Hat Hacker?
Gray-hat hackers are in the middle of the ethical spectrum. Not necessarily fueled by malice, these hackers break into networks without permission to find vulnerabilities. Some may be looking to profit by offering to fix the issue found. Some may hack into a network just to see if they can. Oftentimes, gray-hat hackers will hold ransom a victim’s personal information, but may or may not release it to the public. Gray-hat hackers typically work alone or in small groups with like-minded hackers.
Famous gray-hat hacker
Khalil Shreateh found a bug on Facebook that allowed people to post to a user’s wall even if they enabled the privacy settings to prevent this. Facebook employees continually ignored the bug that he reported, so he ultimately hacked into Facebook and wrote on Mark Zuckerberg’s wall for attention. Facebook then fixed the bug but deleted Shreateh’s account for fear of further hacking attempts.
Black-Hat vs. White-Hat vs. Gray-Hat Hackers
| Black-Hat Hackers | Gray-Hat Hackers | White-Hat Hackers | |
| Ethical Intentions | Hacks for malicious reasons or for self gain. | Can hack for self-gain or to test systems or their own skills. | Employed or self-motivated to find and patch vulnerabilities before a black- or gray-hat hacker exploits a target |
| Primary methods of hacking | Malware | Ransomware | Penetration testing |
| Typical targets | Individuals, organizations and governments | Organizations and governments | Their own employers or governments |
Where Does the Ethical Hacker Career Fall in These Categories?
Ethical hackers are white-hat hackers who find vulnerabilities in order to fix them (not exploit them). Those interested in a career in ethical hacking are in luck — there is a desperate need for cybersecurity professionals in the workforce. According to Salary.com* the average ethical hacking salary in the United States is $103,583 with the typical range between $93,400 and $118,169. The salary ranges on multiple factors, including location, education, certifications, industry experience and more.
*Note: Salary information is updated in real-time, and the numbers listed here reflect the average at the time this article was written.
[RELATED] Penetration Testers on the Front Lines of Cyber Security>>
Other Types of Hackers
- Green-hat hacker: A green-hat hacker is someone that is new to hacking and lacks advanced technical skills and education.
- Blue-hat hacker: A blue-hat hacker is either an amateur hacker motivated by revenge or a security professional contracted by a company to inspect for software vulnerabilities (Examples: Microsoft and Windows).
- Red-hat hacker: A red-hat hacker is the “enemy” of the black-hat hackers. A “vigilante” who seeks out malicious hackers to report them, but also shut down or destroy their computers.
Tips to Reduce Risk & Stay Safe from Hackers
Cybercriminals are always evolving and improving their attack tactics, and so must cybersecurity professionals. Luckily there are a lot of resources that cyber professionals can use to stay up to date and continue to fight against cyber threats. Here are a few tips for businesses and individuals to stay safe.
For businesses
- Invest in a cybersecurity professional that has an advanced degree to lead the team.
- Continue to periodically train staff.
- Limit user permissions and admin settings.
- Make sure remote employees are on a closed network/VPN and using multi-factor authentication.
For individuals
- Don’t use the same password (or easily guessable passwords) for multiple accounts.
- Limit who you share personal information with.
- Keep tabs on your online financial accounts.
- Review and set your privacy settings on social media.
Want to see the top-paying jobs in cybersecurity? Read this article.
Want to see the top entry-level jobs in cybersecurity? Read this article.
Want to see the top non-technical jobs in cybersecurity? Read this article.
Want to learn how to land the best jobs in cybersecurity?Read this article.
frequently asked questions
Is it illegal to hack a system if you report the vulnerability afterward?
Accessing a computer system without authorization can create legal liability even if you report the vulnerability afterward and intend no harm. Good intentions and after-the-fact disclosure don’t automatically create permission to test a system, which is why unauthorized security research can carry legal risk regardless of motive. Organizations respond differently to unsolicited vulnerability reports, and some have pursued legal action against researchers who discovered genuine flaws. The key issue is whether you had authorization to conduct the testing and whether you stayed within its scope. Laws and their application also vary by country and jurisdiction.
What laws apply to hacking in the United States?
The Computer Fraud and Abuse Act (CFAA) is the primary federal law addressing certain forms of unauthorized computer access and other computer-related misconduct in the U.S. Depending on the conduct, violations can result in criminal penalties and, in some circumstances, civil liability. Other federal laws may also apply, including statutes addressing wiretapping, identity theft and trade secrets. Most states have their own computer crime laws as well. Potential penalties depend on factors such as the nature of the conduct, the harm caused and the circumstances surrounding the offense. It’s important to note, however, that this is a general overview and not legal advice.
What is a bug bounty program?
A bug bounty program is a formal arrangement in which an organization invites security researchers to find and report vulnerabilities, often in exchange for payment. Programs define which systems are in scope, what testing methods are permitted and how researchers should submit findings. Platforms such as HackerOne and Bugcrowd host programs for many organizations. Bug bounty programs provide an authorized way for researchers to test designated systems, but that authorization is limited by the program’s terms and scope. Testing systems or using methods that fall outside those boundaries can still create legal or contractual risk.
What is a vulnerability disclosure policy?
A vulnerability disclosure policy is a public statement explaining how an organization wants to receive reports about security vulnerabilities and how it will respond. Unlike a bug bounty program, it typically doesn’t offer payment, although some organizations may provide recognition or other incentives. Some policies also include safe-harbor language stating that the organization will not pursue legal action against researchers who follow the policy’s requirements. Many government agencies and companies publish vulnerability disclosure policies. If you discover a potential vulnerability in a system you weren’t authorized to test, checking whether the organization has a disclosure policy can be a sensible first step before taking further action.
Do companies hire former black-hat hackers?
Yes, some organizations do hire people with a history of illegal hacking, although these cases are less common than high-profile examples might suggest. Technical skill can be attractive to employers, but a criminal record can create practical obstacles, including background-check concerns, difficulty obtaining certain security clearances and concerns about client or customer trust. A history of criminal conduct does not automatically make someone ineligible for every security clearance, but it can be a significant factor in the clearance process. Anyone interested in cybersecurity is better served building experience through authorized channels such as bug bounty programs, certifications, security competitions and legitimate employment.
Are hacktivists black-hat or gray-hat hackers?
Hacktivists don’t fit neatly into the black-hat or gray-hat categories, which is one reason the hat framework has limitations. Hacktivism generally involves using hacking or other digital techniques to advance a political or social cause rather than to make money. Some hacktivist activities involve unauthorized access, service disruption or disclosure of information obtained without permission, which can create legal liability regardless of the stated motive. Some sources classify hacktivists as gray hats based on their motivations, while others classify them as black hats based on their conduct. The legal consequences depend on the specific actions and applicable law, not on which label applies.




