What Do Hackers Actually Do?

In movies and TV shows, hackers are portrayed as mysterious figures hunched over glowing keyboards in dark rooms. In reality, hackers include "white-hat hackers" who are employed and praised by companies — and it's one of the most in-demand careers in the IT industry. This article explains the original meaning of "hacker," the three types, and what they actually do day to day.

What Is a Hacker, Really?

The word "hacker" originally meant "a person who deeply understands how computers work and can freely tinker with them." It was never meant to mean "a bad person." The term was born in the 1960s at MIT (Massachusetts Institute of Technology), where students who modified machines to discover new uses called the practice "hacking."

From the 1980s onward, as cases of unauthorized computer intrusion increased, the public image of "hacker = criminal" took hold. The original meaning still exists, and in the IT industry the word is sometimes used as a compliment. Some communities distinguish the malicious type by calling them "crackers" instead.

The Three Types of Hackers

In the security world, hackers are divided into three types by "hat color" — you may have seen this in films.

Three Hacker Types: Telling Them Apart by Permission, Intent, and Law "The same action can be legal or criminal depending on whether permission was granted — and why." Factor ○ White Hat △ Grey Hat × Black Hat Permission Owner's prior consent ○ Signed contract Scope and timeline defined △ Implied or none Reports after the fact × Fully unauthorized Or actively concealed Intent Why do they break in? Find and report weaknesses → Strengthen defenses Raise issues / curiosity No malice, but ambiguous Theft / financial gain Destruction / extortion Law (Japan) Unauthorized Access Law ○ Legal (paid job) Security engineer △ Potentially illegal Many are prosecuted × Illegal (prison) Up to 3 years or fines Examples Typical activities CTF / vulnerability audits Bug bounty programs Find a hole without permission → Report to operator later SNS account hijacking Ransomware attacks As a career Legal working style ○ High-paying career ¥8M–¥20M/year Not a career Hobby or activist Not a career — it's a crime Arrest / criminal record ▶ The same skill set leads to a career or a crime depending on "permission" and "intent"
Fig. 1: Differences among the three hacker types. The technology itself is neither good nor bad — "permission" and "intent" flip the outcome completely.

What White-Hat Hackers Actually Do

White-hat hackers are formally called "security engineers" or "penetration testers" and are employed by companies and government agencies. The real job is mostly unglamorous: reading code, examining server configurations, and writing reports. The fast-typing scenes you see in movies are almost nonexistent in real life.

The key rule is "investigate with permission." White-hat hackers agree in advance on scope, duration, allowed methods, and who to report to. For example: "only test this staging site," "do not touch production data," "do not use excessively destructive techniques." Technical skill alone is not enough — keeping your word is equally required.

White-Hat Hacker: Main Duties and Required Skills "Movie-style dramatic hacking" is rare — most time is spent on routine investigation and report writing Duty What They Do Skills Needed Time Split Vulnerability Assessment Web application audit Systematically test for SQL injection, XSS, etc. Tools (Burp Suite) + manual checks Web tech + HTTP 30% Penetration Testing Simulated real-world intrusion Act as an attacker to attempt intrusion Scope and methods defined by contract Networking + OS 20% Report Writing Document findings in writing Describe what's vulnerable and how to fix it Writing that executives can also understand English + clear writing 25% Incident Response Investigating active attacks Identify "what, when, from where" from logs May include late-night/weekend work Log analysis + calm judgment 10% Training & Education Security awareness for staff Teach staff to spot phishing, etc. Communication skill matters more than tech Presenting + plain English 15% ▶ "Attacking" takes only about 20% of time. The other 80% is reports, education, and methodical investigation. Technical skill alone is not enough — writing and explaining clearly are equally essential for white-hat hackers.
Fig. 2: White-hat hacker duties and time allocation. "Attacking" is a smaller part of the job than reporting and teaching.

Pitfalls to Watch Out For

Three things you must never do
  • Breaking into someone else's website "just to test your skills." In Japan this violates the Unauthorized Computer Access Law and leads to arrest.
  • Logging into a friend's account without permission. Even on the same home Wi-Fi, it is illegal.
  • Copying a "how to hack X" method you found on social media. Without the target's permission, it is dangerous and illegal.

If you want to test your skills, "CTF (Capture The Flag)" security competitions provide a safe, legal arena. Because you solve purpose-built challenges, you can learn without harming anyone's real sites or accounts. Even if you practice on a school PC or home network, always get permission from whoever manages it first.

Where Should Teens Start?

The first thing to learn is not attack techniques but fundamentals. Linux commands, IP addresses and DNS, web basics like HTML and HTTP, password management, and reading logs. With this foundation, security concepts click as "how things work" rather than rote facts to memorize.

For programming, a little Python or JavaScript goes a long way. Beyond finding vulnerabilities, you can use code to organize logs or automate repetitive checks. English is also valuable — most security information is published in English, so practice reading error messages and official documentation and it directly builds your skill.

How Does This Help Your Future?

White-hat hackers and security engineers are professionals who protect a company's information assets. The job demands broad knowledge of programming, networking, and operating systems, but it all starts with "enjoying how computers work." There are learning opportunities for young people — such as CTF competitions and security boot camps — that change their entry requirements and content each year, so check official sources for up-to-date information.

What You Can Do Today

3 steps to practice legally
  1. Sign up for a legal learning platform such as TryHackMe or Hack The Box.
  2. Work through beginner courses (Linux commands, web security) one challenge at a time.
  3. Look into applying for "Security Camp" (for ages 22 and under, organized by the Japanese government, held every August).

Summary

The word "hacker" originally meant someone who deeply understands computers. It splits into those with malicious intent (black-hat hackers) and those who protect companies (white-hat hackers). The technology itself is neutral; what matters is using it with proper permission. If you're interested in security, start in a legal practice environment like CTF competitions.

Check When you sort hackers, what matters?