The Cuckoo's Egg: A 75-Cent Error That Caught KGB Hackers
In 1986 an astronomer was told to find out why the lab accounts were out by seventy-five cents. The trivial chore unravelled into one of the first cases of international cyber-espionage, with a hacker selling secrets to the KGB.
In 1986, an astronomer turned reluctant computer manager at a California laboratory was handed a trivial chore: find out why the accounting system was out by seventy-five cents. Someone had used a sliver of computer time that nobody had paid for. It should have taken an afternoon. Instead it unravelled, thread by thread, into one of the first documented cases of international cyber-espionage, with a hacker in Germany selling American secrets to the Soviet KGB.

The seventy-five cent clue
The astronomer was Clifford Stoll, working at Lawrence Berkeley National Laboratory. In an era when computer time was metered and billed, a tiny discrepancy meant a tiny amount of usage that did not match any paying account. Most people would have written it off. Stoll, with the obsessive curiosity of a scientist, treated the seventy-five cents as a loose thread and started to pull. The unpaid time, he realised, belonged to an intruder who had quietly slipped into the lab's systems.
The patient hunt
What followed was a months-long stakeout conducted almost entirely by one stubborn man. Stoll wired up printers to log everything the intruder did, sleeping under his desk to catch the late-night sessions, and watched as the hacker used the lab as a stepping stone to leap into military and defence networks across the country, hunting for anything marked secret. The early internet was built on trust and had almost no defences, so a single foothold could become a skeleton key to dozens of systems.

The trap
To catch the intruder, Stoll needed to keep them online long enough to trace the connection across the world. So he invented a problem that is now a standard security technique. He created a stash of official-looking but entirely fake documents about a fictional military programme, irresistible bait for a spy. The hacker took it, lingering for hours to download the fiction, and that delay was enough. The trail led to a man in West Germany named Markus Hess, who had been breaking into systems and selling what he found to the Soviet intelligence services.

Why it still matters
Stoll wrote up the whole adventure in a book that became a classic, and the case landed at almost the same moment as the Morris worm, the two together jolting the computing world into realising that its friendly, open networks now had real adversaries. It is remembered as a founding story of digital forensics and network security, and as proof of a principle that has only grown truer with time: the smallest anomaly, followed with enough patience, can expose something enormous. Every security team that pulls on a strange log entry today is doing what Stoll did with his seventy-five cents.
The networks have grown unimaginably since, but the shape of the work has not. Tracing where traffic really comes from, and who runs the machine at the other end, is still the heart of it, which is the whole idea behind tools like our who is hosting this site tool and the network and ASN data behind it. The protocols Stoll exploited and defended are still documented in our RFC archive, written for a more innocent internet than the one he discovered.
0 Comments
No comments yet
Be the first to share your thoughts on this article.