Obtaining a hash typically involves breaching one of the security layers:
⏺Gaining access to databases
⏺Intercepting (sniffing) unencrypted data
⏺Intercepting encrypted files
⏺Intercepting authentication packets (for wireless networks)
— Obtaining a hash may require extensive penetration testing; this compromise alone can be considered a significant success.
But for the captured hashes to be of real use, they must be decrypted.