News Article · May 18, 2026 at 9:00 AM
3 min read 0
The Cuckoo's Egg: A 75-Cent Error That Caught KGB Hackers
Deep Dives #security #internet history #espionage #hacking

The Cuckoo's Egg: A 75-Cent Error That Caught KGB Hackers

In 1986 an astronomer was told to find out why the lab accounts were out by seventy-five cents. The trivial chore unravelled into one of the first cases of international cyber-espionage, with a hacker selling secrets to the KGB.

In 1986, an astronomer turned reluctant computer manager at a California laboratory was handed a trivial chore: find out why the accounting system was out by seventy-five cents. Someone had used a sliver of computer time that nobody had paid for. It should have taken an afternoon. Instead it unravelled, thread by thread, into one of the first documented cases of international cyber-espionage, with a hacker in Germany selling American secrets to the Soviet KGB.

A magnifying glass over a ledger with one tiny error and a red thread leading away
A seventy-five cent discrepancy, followed far enough, led somewhere nobody expected.

The seventy-five cent clue

The astronomer was Clifford Stoll, working at Lawrence Berkeley National Laboratory. In an era when computer time was metered and billed, a tiny discrepancy meant a tiny amount of usage that did not match any paying account. Most people would have written it off. Stoll, with the obsessive curiosity of a scientist, treated the seventy-five cents as a loose thread and started to pull. The unpaid time, he realised, belonged to an intruder who had quietly slipped into the lab's systems.

The patient hunt

What followed was a months-long stakeout conducted almost entirely by one stubborn man. Stoll wired up printers to log everything the intruder did, sleeping under his desk to catch the late-night sessions, and watched as the hacker used the lab as a stepping stone to leap into military and defence networks across the country, hunting for anything marked secret. The early internet was built on trust and had almost no defences, so a single foothold could become a skeleton key to dozens of systems.

A glowing thread connecting a computer to a distant point across a world map
Stoll followed the intruder across the early internet the way a detective follows a wire.

The trap

To catch the intruder, Stoll needed to keep them online long enough to trace the connection across the world. So he invented a problem that is now a standard security technique. He created a stash of official-looking but entirely fake documents about a fictional military programme, irresistible bait for a spy. The hacker took it, lingering for hours to download the fiction, and that delay was enough. The trail led to a man in West Germany named Markus Hess, who had been breaking into systems and selling what he found to the Soviet intelligence services.

A glowing document folder set as bait inside a spider web
Stoll baited the intruder with fake secret files, an early honeypot, to buy time for the trace.

Why it still matters

Stoll wrote up the whole adventure in a book that became a classic, and the case landed at almost the same moment as the Morris worm, the two together jolting the computing world into realising that its friendly, open networks now had real adversaries. It is remembered as a founding story of digital forensics and network security, and as proof of a principle that has only grown truer with time: the smallest anomaly, followed with enough patience, can expose something enormous. Every security team that pulls on a strange log entry today is doing what Stoll did with his seventy-five cents.

The networks have grown unimaginably since, but the shape of the work has not. Tracing where traffic really comes from, and who runs the machine at the other end, is still the heart of it, which is the whole idea behind tools like our who is hosting this site tool and the network and ASN data behind it. The protocols Stoll exploited and defended are still documented in our RFC archive, written for a more innocent internet than the one he discovered.

Sources and further reading

0 Comments

No comments yet

Be the first to share your thoughts on this article.