Security (Imunify360, ModSecurity)

What are the Most Common Types of Cyber Attacks and How to Prevent Them

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (10 sections)

Most attacks on small businesses are not targeted. They are automated campaigns that try stolen passwords, trick staff with fake emails, and scan websites for outdated software. Knowing the common attack types, and the few habits that stop most of them, protects your website, your email and your customers. This guide explains each major attack in plain language and what to do about it.

Key takeaways

The attacks small businesses meet most are phishing, stolen or guessed passwords, malware and ransomware, attacks on outdated website software, and floods of traffic (DDoS). Most are stopped by the same basics: two-factor authentication, unique passwords in a password manager, prompt updates, backups kept away from your main systems, and staff who pause before clicking. If you are attacked in India, report it at cybercrime.gov.in or call the 1930 helpline.

1. Phishing and social engineering

Phishing is a message that pretends to come from someone you trust, such as a bank, a courier, a supplier, a government office or your own hosting provider, to get you to click a link, enter a password, pay money or open an attachment. Social engineering is the same trick in person or by phone: a caller claiming to be from "technical support" or a "KYC update" team.

Common forms in India include fake bank or UPI "KYC expired" messages, fake courier or customs fees, fake invoices from "suppliers" with changed bank details, and fake domain or hosting renewal notices.

  • Check the sender's real address and the link's real destination before you click.
  • Never share an OTP, UPI PIN or password with anyone, even someone who says they are from your bank.
  • Confirm payment or bank-detail changes by calling a number you already have, not one in the message.
  • Log in by typing the address yourself, not from a link in an email.

For email-specific defences, see email security best practices.

2. Password attacks

Attackers rarely "crack" a strong password. Instead they reuse passwords leaked from other websites (credential stuffing), try common passwords across many accounts (password spraying), or guess repeatedly against one login (brute force). Keyloggers and fake login pages steal the rest.

  1. Turn on two-factor authentication
    for email, banking, your domain and hosting accounts, and your website's admin login.
  2. Use a password manager
    so every account gets a long, unique password. See the best password managers.
  3. Use passkeys where offered.
    They can't be phished or reused.
  4. Change a password when there is a reason
    , such as a breach or a staff member leaving, rather than on a fixed timer.

3. Malware, ransomware and spyware

Malware is any malicious software: viruses, worms, trojans, rootkits and spyware. It usually arrives through an email attachment, a pirated program, a fake update or an infected USB drive. Spyware quietly records passwords and activity. Rootkits hide deep in the system to keep an attacker's access.

Ransomware encrypts your files and demands payment to unlock them, often after stealing a copy to threaten publication. Paying doesn't guarantee your data back.

  • Keep your operating system, browser and apps updated; turn on automatic updates.
  • Use the built-in protection (such as Microsoft Defender on Windows) or a reputable security suite, and keep it on.
  • Install software only from official sources, never "cracked" or "nulled" versions.
  • Keep backups that ransomware can't reach: at least one copy offline or in a separate account, and test that it restores.

4. Attacks on websites and web applications

Automated scanners test every website they find for known holes. The most common:

AttackWhat happensMain defence
SQL injectionMalicious input changes a database query to read or alter dataParameterised queries and prepared statements
Cross-site scripting (XSS)Injected script runs in visitors' browsersEscape output, validate input, add a Content Security Policy
Broken access controlChanging a URL or ID shows someone else's dataCheck permissions on the server for every request
Vulnerable plugins and themesKnown holes in outdated CMS add-ons are exploitedUpdate promptly; delete what you don't use
Nulled softwarePirated themes or plugins ship with hidden backdoorsBuy from the developer or use free official versions

The older idea of "URL poisoning" is today's broken access control: never trust an ID or parameter in the URL without checking that the user may see it. For a developer checklist, see securing web applications across all stacks, and for WordPress, the complete WordPress hardening guide.

5. DDoS attacks and botnets

A distributed denial-of-service (DDoS) attack floods a website or server with traffic from thousands of hijacked devices (a botnet) until real visitors can't get through. Botnets are built from infected computers, routers, cameras and other devices with default passwords.

  • Change default passwords on routers and smart devices, and update their firmware.
  • For a site that is a likely target, use a CDN or DDoS mitigation service in front of it.
  • Keep your site light and cached, so it copes better with sudden traffic.

More in the comprehensive guide to DDoS mitigation.

6. Man-in-the-middle and DNS attacks

In a man-in-the-middle attack, someone intercepts traffic between you and a website, typically on public Wi-Fi, to read or change it. HTTPS on every page defeats most of this, so make sure your own website uses a valid SSL certificate everywhere.

DNS attacks send visitors to the wrong server: by poisoning a DNS cache, or more often by taking over the domain's registrar or DNS account and changing the records. Protect the account that controls your domain with a strong password and two-factor authentication, and keep your contact email current so renewal and security notices reach you. See domain security.

7. Supply-chain, watering-hole and insider threats

  • Supply-chain attacks compromise a supplier or a software update you trust, so the attack arrives through a legitimate channel. Limit which vendors have access, and remove plugins and integrations you no longer use.
  • Watering-hole attacks infect a website that your staff or customers visit often. Updated browsers and security software block most of them.
  • Insider threats come from current or former staff and contractors. Give each person their own account with only the access they need, and remove access the day someone leaves.

8. If you are attacked

Act fast, and don't destroy evidence

Disconnect an infected computer from the network, change passwords from a clean device, and tell your bank at once if money is involved. Don't wipe systems before you know what happened.

  • Report cybercrime at cybercrime.gov.in or by calling 1930, the national cybercrime helpline. Report financial fraud quickly: the sooner you report, the better the chance of stopping the payment.
  • Organisations covered by CERT-In's directions must report specified incidents to CERT-In within 6 hours of noticing them. Check whether this applies to you.
  • For a hacked website, follow what to do if your website has been hacked or defaced.

9. What Domain India does, and what stays with you

On Domain India cPanel and DirectAdmin shared hosting, server-wide protection covers every plan: CloudLinux account isolation, the Imunify360 web application firewall and malware scanning with automatic cleanup, a firewall that blocks repeated failed logins, free SSL, and weekly JetBackup 5 backups you can restore yourself. On cPanel, you can turn on two-factor authentication for your control panel login, and DKIM email signing is on by default for new accounts. Details: the software that secures our shared hosting servers.

What stays with you: your passwords, your website's software and plugins, your staff's habits, and your own copy of your data. Turn on two-factor authentication for your Domain India account too.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

The card shows live Domain India list prices, excluding 18% GST. To report abuse by a website hosted with us, such as phishing or spam, email [email protected] with the details.

Frequently asked questions

What is the most common type of cyber attack?

Phishing. Most successful attacks on small businesses start with a fake email, SMS or call that tricks someone into giving away a password, an OTP or a payment.

Does two-factor authentication really help?

Yes. It stops most attacks that use stolen or guessed passwords, because the attacker also needs the second factor. Use an authenticator app or passkey rather than SMS where you can.

How do I protect my business from ransomware?

Keep software updated, avoid pirated programs, train staff to spot phishing, and keep at least one backup copy offline or in a separate account. Test that you can restore from it.

Where do I report a cyber attack in India?

Report cybercrime at cybercrime.gov.in or call the national cybercrime helpline 1930. Organisations covered by CERT-In's directions must also report specified incidents to CERT-In within 6 hours.

Does Domain India protect my website from hackers?

Domain India shared hosting includes server-wide protection such as a web application firewall, malware scanning with automatic cleanup and weekly backups. You are still responsible for updating your website software, using strong passwords and keeping your own backups.

What is a DDoS attack?

A distributed denial-of-service attack floods a website or server with traffic from many hijacked devices so real visitors can't reach it. CDNs and DDoS mitigation services absorb large floods.

Ready to put these defences in place? Start with two-factor authentication, compare cPanel hosting for a site with server-side protection built in, or open a support ticket if you think your account has been attacked.

Worried your site or account was attacked?

Our support team is on 24/7 live chat, and tickets get a first response within 15 minutes.

Open a support ticket

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Common Cyber Attacks and How to Prevent Them | Domain India