State-sponsored hacking groups are backed by a nation-state. That doesn't always mean they're official government employees sitting, though sometimes they are. The U.S. Cybersecurity and Infrastructure Security Agency describes these actors as pursuing advanced persistent threat activity on behalf of national governments, with China's government singled out as one of the most active, engaging in cyber operations to advance its own national interests. A Department of Justice indictment cited by the Orion Policy Institute described China's Ministry of State Security as relying on a mix of "intelligence officers, contractor hackers, and support personnel" to carry out its campaigns, a structure that includes formal government staff with outside hackers.
An example is Volt Typhoon, a China-linked group that U.S. and international agencies say has compromised critical infrastructure across communications, energy, transportation, and water sectors in the United States and its territories, including Guam, positioning itself for potential disruption during a future crisis or conflict.
Hackers-for-hire, on the other hand, sell hacking services to whoever is willing to pay, which includes corporations engaged in industrial espionage, private individuals settling personal disputes, law firms, or even governments that want to outsource an operation without building in-house capability. Citizen Lab's investigation into an operation it named Dark Basin found that the group had "likely conducted commercial espionage on behalf of their clients" targeting journalists, politicians, and advocacy organizations, and traced the activity with high confidence to an Indian firm called BellTroX InfoTech Services.
Strategy vs. profit
State-sponsored groups are driven by national interest. According to CISA's threat advisories, Chinese state-sponsored actors have been observed pre-positioning themselves inside US infrastructure networks for potential disruptive or destructive use in the event of future geopolitical tensions. According to a joint advisory from CISA and partner agencies, Russia's FSB has been documented tasking criminal hackers for espionage purposes, showing how criminal actors can be included into a state's strategic goals. Speaking to InformationWeek about North Korea's activity, security executive Henry noted, "Labyrinth Chollima is one of the more prolific North Korean adversaries that we've tracked," pointing to a group that has stayed active for more than a decade.
Hackers-for-hire are driven by whatever the client wants. In the Dark Basin case, targets ranged across continents and included senior politicians, government prosecutors, corporate executives, and environmental advocacy groups tied to the #ExxonKnew campaign, which argued Exxon Mobil had downplayed the risks of climate change for decades.
Operational style
State-sponsored groups have access to more resources such as dedicated budgets, teams of specialists, and custom-built malware. According to the joint CISA advisory on Volt Typhoon, the group's technique is "living off the land," using legitimate system tools rather than custom malware to blend into normal network traffic and evade detection for extended periods. Russia's SVR-linked operators have been observed using custom multi-platform malware and a "credential hopping" technique that steals browser cookies to bypass multi-factor authentication, according to the CISA reporting on Russian state-sponsored threats.
Hackers-for-hire tend to work faster and with more commercially available tooling. The Dark Basin operation relied on large-scale phishing, with researchers documenting nearly 28,000 fake websites built to make malicious links look legitimate.
Read also: Types of breaches
Legal and accountability differences
State-sponsored hacking is rarely prosecuted through ordinary criminal channels because it's conducted by or on behalf of a government. The U.S. did indict North Korean national Park Jin-hyok in connection with the Sony hack, WannaCry, and other intrusions, but he remains at large, showing how such charges are often not easily enforceable. The FBI has said it will keep working with partners to "combat malicious cyber activity" tied to North Korea, but the country has denied involvement, as it did again after the FBI linked Lazarus Group to a $620 million cryptocurrency theft.
Hackers-for-hire are treated as ordinary criminals when caught, but enforcement is inconsistent and often depends on jurisdiction. BellTroX's director, Sumit Gupta, was indicted in the United States over the Dark Basin campaign yet was never arrested, according to reporting from The Quint. Apple, in its 2021 lawsuit against NSO Group, argued in its complaint that the company's employees were "amoral 21st century mercenaries," showing how commercial spyware vendors can be considered legitimate business or even criminal enterprises.
Where there is confusion
Some hackers-for-hire firms count governments among their clients, this means doing state outsourced offensive-cyber capability while still taking private commercial work on the side. Some state-sponsored groups also use individuals who pursue financially motivated work independently, using similar tactics, according to InformationWeek's reporting on nation-state threats. Discussing the Lazarus Group specifically, the Atlantic Council's Beau Woods described the situation as "a blurred line" between state and non-state actors, noting that governments sometimes tolerate or informally back groups whose goals happen to align with their own.
This overlap is why an intrusion might be state-directed espionage, a hacker-for-hire operation commissioned by a state, or a criminal group acting independently before later selling access to a nation-state actor. Researchers have to rely on circumstantial evidence such as infrastructure reuse, targeting patterns, working hours aligned with a particular time zone, or malware code overlaps to make an educated guess, and even then, formal government attribution doesn't always happen.
Why the distinction matters
A state-sponsored intrusion, like Volt Typhoon's presence inside U.S. infrastructure, is a long-term goal, needing a forensic sweep rather than just patching the initial entry point. A hacker-for-hire incident, like the targeted phishing seen in Dark Basin, might point toward a personal or business motive worth investigating, since someone specifically commissioned the attack for a reason tied to the victim.
The difference is important in healthcare. In July 2022, CISA, the FBI, and the Treasury Department jointly warned that North Korean state-sponsored actors had been deploying Maui ransomware against Healthcare and Public Health Sector organizations since at least May 2021, on the assumption that hospitals would be willing to pay quickly to restore patient-care systems. A follow-up advisory the agencies issued the next year went further, assessing that revenue from these healthcare-sector ransomware attacks was being funneled back into funding the North Korean government's other priorities, including espionage against the U.S. and South Korean defense sectors. FBI Director Christopher Wray said in 2022 that the bureau's cyber division had prevented an Iran-sponsored attempt to breach the IT network of Boston Children's Hospital.
Lastly, both categories represent real and growing threats, but knowing the characteristics such as who's paying, why, and how they tend to operate gives a better framework for making sense of breaches.
Read also: A deeper understanding of attacks on healthcare
FAQs
Is state-sponsored hacking considered an act of war?
Most governments treat it as espionage or sabotage rather than an armed attack, though a destructive incident could be considered that under international law.
Can an ordinary person be targeted by a state-sponsored group, or is it only governments and big companies?
Yes, journalists, activists, and even private citizens with no government ties have been targeted when their work or relationships intersect with a state's interests.
Is it illegal to work as a hacker-for-hire?
In most countries, yes, unauthorized computer access is a crime regardless of who's paying, though enforcement differs.
How can investigators tell whether an attack was state-sponsored or hired hacking?
They rely on indirect clues like malware reuse, infrastructure overlaps, language artifacts, and time-zone patterns.
