HOME

TheInfoList



OR:

The list of security hacking incidents covers important or noteworthy events in the history of security hacking and cracking.


1900


1903

* Magician and inventor
Nevil Maskelyne Nevil Maskelyne (; 6 October 1732 – 9 February 1811) was the fifth British Astronomer Royal. He held the office from 1765 to 1811. He was the first person to scientifically measure the mass of the planet Earth. He created '' The Nautical Al ...
disrupts
John Ambrose Fleming Sir John Ambrose Fleming (29 November 1849 – 18 April 1945) was an English electrical engineer who invented the vacuum tube, designed the radio transmitter with which the first transatlantic radio transmission was made, and also established ...
's public demonstration of
Guglielmo Marconi Guglielmo Giovanni Maria Marconi, 1st Marquess of Marconi ( ; ; 25 April 1874 – 20 July 1937) was an Italian electrical engineer, inventor, and politician known for his creation of a practical radio wave-based Wireless telegraphy, wireless tel ...
's purportedly secure
wireless telegraphy Wireless telegraphy or radiotelegraphy is the transmission of text messages by radio waves, analogous to electrical telegraphy using electrical cable, cables. Before about 1910, the term ''wireless telegraphy'' was also used for other experimenta ...
technology, sending insulting
Morse code Morse code is a telecommunications method which Character encoding, encodes Written language, text characters as standardized sequences of two different signal durations, called ''dots'' and ''dashes'', or ''dits'' and ''dahs''. Morse code i ...
messages through the auditorium's projector.


1930s


1932

* Polish cryptologists
Marian Rejewski Marian Adam Rejewski (; 16 August 1905 – 13 February 1980) was a Polish people, Polish mathematician and Cryptography, cryptologist who in late 1932 reconstructed the sight-unseen German military Enigma machine, Enigma cipher machine, aided ...
,
Henryk Zygalski Henryk Zygalski (; 15 July 1908 – 30 August 1978) was a Polish mathematician and cryptologist who worked at breaking German Enigma-machine ciphers before and during World War II. Life Zygalski was born on 15 July 1908 in Posen, German Empi ...
and Jerzy Różycki broke the
Enigma machine The Enigma machine is a cipher device developed and used in the early- to mid-20th century to protect commercial, diplomatic, and military communication. It was employed extensively by Nazi Germany during World War II, in all branches of the W ...
code.


1939

*
Alan Turing Alan Mathison Turing (; 23 June 1912 – 7 June 1954) was an English mathematician, computer scientist, logician, cryptanalyst, philosopher and theoretical biologist. He was highly influential in the development of theoretical computer ...
,
Gordon Welchman William Gordon Welchman OBE (15 June 1906 – 8 October 1985) was an English mathematician. During World War II, he worked at Britain's secret decryption centre at Bletchley Park, where he was one of the most important contributors. In 1948, a ...
and
Harold Keen Harold Hall "Doc" Keen (1894–1973) was a British engineer who produced the engineering design, and oversaw the construction of, the British bombe, a codebreaking machine used in World War II to read German messages sent using the Enigma machi ...
worked together to develop the codebreaking device
Bombe The bombe () was an Electromechanics, electro-mechanical device used by British cryptologists to help decipher German Enigma machine, Enigma-machine-encrypted secret messages during World War II. The United States Navy, US Navy and United Sta ...
(on the basis of Rejewski's works on Bomba). The
Enigma machine The Enigma machine is a cipher device developed and used in the early- to mid-20th century to protect commercial, diplomatic, and military communication. It was employed extensively by Nazi Germany during World War II, in all branches of the W ...
's use of a reliably small key space makes it vulnerable to brute force.


1940s


1943

* René Carmille,
comptroller A comptroller (pronounced either the same as ''controller'' or as ) is a management-level position responsible for supervising the quality of accountancy, accounting and financial reporting of an organization. A financial comptroller is a senior- ...
general of the
Vichy French Vichy France (; 10 July 1940 – 9 August 1944), officially the French State ('), was a French rump state headed by Marshal Philippe Pétain during World War II, established as a result of the French capitulation after the defeat against G ...
Army, hacked the
punched card A punched card (also punch card or punched-card) is a stiff paper-based medium used to store digital information via the presence or absence of holes in predefined positions. Developed over the 18th to 20th centuries, punched cards were widel ...
system used by the Nazis to locate Jews.


1949

*The theory that underlies computer viruses was first made public in 1949, when computer pioneer
John von Neumann John von Neumann ( ; ; December 28, 1903 – February 8, 1957) was a Hungarian and American mathematician, physicist, computer scientist and engineer. Von Neumann had perhaps the widest coverage of any mathematician of his time, in ...
presented a paper titled "Theory and Organization of Complicated Automata". In the paper, von Neumann speculated that computer programs could reproduce themselves.


1950s


1955

* At
MIT The Massachusetts Institute of Technology (MIT) is a private research university in Cambridge, Massachusetts, United States. Established in 1861, MIT has played a significant role in the development of many areas of modern technology and sc ...
, "hack" first came to mean playing with machines. The minutes of an April 1955 meeting of the
Tech Model Railroad Club The Tech Model Railroad Club (TMRC) is a student organization at the Massachusetts Institute of Technology (MIT). Historically, it has been a wellspring of hacker culture and the oldest such hacking group in North America. Formed in 1946, its HO ...
state that "Mr. Eccles requests that anyone working or hacking on the electrical system turn the power off to avoid fuse blowing."


1957

* Joe "
Joybubbles Joybubbles ( – ), born Josef Carl Engressia Jr. in Richmond, Virginia, was an early phone phreak. Born blind, he became interested in telephones at age four. He had absolute pitch, and was able to whistle 2600 hertz into a telephone, an operat ...
" Engressia, a blind seven-year-old boy with perfect pitch, discovered that whistling the fourth E above middle C (a frequency of 2600 Hz) would interfere with AT&T's automated telephone systems, thereby inadvertently opening the door for
phreaking Phreaking is a slang term coined to describe the activity of a culture of people who study, experiment with, or explore telecommunication systems, such as equipment and systems connected to public telephone networks. The term ''phreak'' is a se ...
.


1960s

* Various
phreaking boxes A phreaking box is a device used by Phreaking, phone phreaks to perform various functions normally reserved for operators and other telephone company employees. Most phreaking boxes are named after colors, due to folklore surrounding the earliest ...
are used to interact with automated telephone systems.


1963

* The first ever reference to malicious hacking is ' telephone hackers' in
MIT The Massachusetts Institute of Technology (MIT) is a private research university in Cambridge, Massachusetts, United States. Established in 1861, MIT has played a significant role in the development of many areas of modern technology and sc ...
's student newspaper, ''The Tech'' of hackers tying up the lines with
Harvard Harvard University is a private Ivy League research university in Cambridge, Massachusetts, United States. Founded in 1636 and named for its first benefactor, the Puritan clergyman John Harvard, it is the oldest institution of higher lear ...
, configuring the
PDP-1 The PDP-1 (Programmed Data Processor-1) is the first computer in Digital Equipment Corporation's PDP series and was first produced in 1959. It is known for being the most important computer in the creation of hacker culture at the Massachusetts ...
to make free calls,
war dialing Wardialing (or war dialing) is a technique to automatically scan a list of telephone numbers, usually dialing every number in a local area code to search for modems, computers, bulletin board systems ( computer servers) and fax machines. Hacke ...
and accumulating large phone bills.


1965

* William D. Mathews from
MIT The Massachusetts Institute of Technology (MIT) is a private research university in Cambridge, Massachusetts, United States. Established in 1861, MIT has played a significant role in the development of many areas of modern technology and sc ...
found a vulnerability in a CTSS running on an
IBM 7094 The IBM 7090 is a second-generation transistorized version of the earlier IBM 709 vacuum tube mainframe computer that was designed for "large-scale scientific and technological applications". The 7090 is the fourth member of the IBM 700/7000 se ...
. The standard text editor on the system was designed to be used by one user at a time, working in one directory, and so it created a temporary file with a constant name for all instantiations of the editor. The flaw was discovered when two system programmers were editing at the same time and the temporary files for the message of the day and the password file became swapped, causing the contents of the system CTSS password file to display to any user logging into the system.


1967

* The first known incidence of network penetration hacking took place when members of a computer club at a suburban Chicago area high school were provided access to IBM's APL network. In the Fall of 1967, IBM (through
Science Research Associates Science Research Associates (SRA), founded by Lyle Spencer in 1938, was a Chicago-based publisher of educational materials and schoolroom reading comprehension products. The company was acquired by McGraw-Hill Education in the early 2000s. Histo ...
) approached
Evanston Township High School Evanston Township High School (ETHS) (District 202) is a public high school in Evanston, Illinois. The campus is located in a northern suburb of Chicago along the Lake Michigan shore. ETHS was established in 1883 and serves the city of Evanston a ...
with the offer of four 2741 Selectric teletypewriter-based terminals with dial-up modem connectivity to an experimental computer system which implemented an early version of the APL programming language. The APL network system was structured into Workspaces which were assigned to various clients using the system. Working independently, the students quickly learned the language and the system. They were free to explore the system, often using existing code available in public Workspaces as models for their own creations. Eventually, curiosity drove the students to explore the system's wider context. This first informal network penetration effort was later acknowledged as helping harden the security of one of the first publicly accessible networks:


1970s


1971

* John T. Draper (later nicknamed Captain Crunch), his friend Joe Engressia (also known as
Joybubbles Joybubbles ( – ), born Josef Carl Engressia Jr. in Richmond, Virginia, was an early phone phreak. Born blind, he became interested in telephones at age four. He had absolute pitch, and was able to whistle 2600 hertz into a telephone, an operat ...
), and
blue box A blue box is an Electronics, electronic device that produces tones used to generate the in-band signaling tones formerly used within the North American long-distance telephone network to send line status and called number information over voi ...
phone
phreaking Phreaking is a slang term coined to describe the activity of a culture of people who study, experiment with, or explore telecommunication systems, such as equipment and systems connected to public telephone networks. The term ''phreak'' is a se ...
hit the news with an ''
Esquire Esquire (, ; abbreviated Esq.) is usually a courtesy title. In the United Kingdom, ''esquire'' historically was a title of respect accorded to men of higher social rank, particularly members of the landed gentry above the rank of gentleman ...
'' magazine feature story.


1979

*
Kevin Mitnick Kevin David Mitnick (August 6, 1963 – July 16, 2023) was an American computer security consultant, author, and convicted hacker. In 1995, he was arrested for various computer and communications-related crimes, and spent five years in prison ...
breaks into his first major computer system, the Ark, the computer system
Digital Equipment Corporation Digital Equipment Corporation (DEC ), using the trademark Digital, was a major American company in the computer industry from the 1960s to the 1990s. The company was co-founded by Ken Olsen and Harlan Anderson in 1957. Olsen was president until ...
(DEC) used for developing their
RSTS/E RSTS () is a multi-user time-sharing operating system developed by Digital Equipment Corporation (DEC, now part of Hewlett-Packard) for the PDP-11 series of 16-bit minicomputers. The first version of RSTS (RSTS-11, #Versions, Version 1) was implem ...
operating system software.


1980s


1980

* The
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
investigates a breach of security at
National CSS National CSS, Inc. (NCSS) was a time-sharing firm in the 1960–80s, until its acquisition by Dun & Bradstreet in 1979. NCSS was originally headquartered in Norwalk, Connecticut, but relocated to Wilton in 1978. Sales offices, data centers, and ...
(NCSS). ''
The New York Times ''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
'', reporting on the incident in 1981, describes hackers as : :The newspaper describes white hat activities as part of a "mischievous but perversely positive 'hacker' tradition". When a National CSS employee revealed the existence of his password cracker, which he had used on customer accounts, the company chastised him not for writing the software but for not disclosing it sooner. The letter of reprimand stated that "The Company realizes the benefit to NCSS and in fact encourages the efforts of employees to identify security weaknesses to the VP, the directory, and other sensitive software in files".


1981

*
Chaos Computer Club The Chaos Computer Club (CCC) is Europe's largest association of Hacker (computer security), hackers with 7,700 registered members. Founded in 1981, the association is incorporated as an ''eingetragener Verein'' in Germany, with local chapters ...
forms in Germany. * Ian Murphy, aka Captain Zap, was the first cracker to be tried and convicted as a felon. Murphy broke into AT&T's computers in 1981 and changed the internal clocks that metered billing rates. People were getting late-night discount rates when they called at midday. Of course, the bargain-seekers who waited until midnight to call long distance were hit with high bills.


1983

*
The 414s The 414s were a group of computer hackers from Milwaukee who broke into dozens of high-profile computer systems, including ones at Los Alamos National Laboratory, Sloan-Kettering Cancer Center, and Security Pacific National Bank, in 1982 and 1 ...
break into 60 computer systems at institutions ranging from the
Los Alamos National Laboratory Los Alamos National Laboratory (often shortened as Los Alamos and LANL) is one of the sixteen research and development Laboratory, laboratories of the United States Department of Energy National Laboratories, United States Department of Energy ...
to Manhattan's
Memorial Sloan-Kettering Cancer Center Memorial Sloan Kettering Cancer Center (MSK or MSKCC) is a oncology, cancer treatment and research institution in Manhattan in New York City. MSKCC is one of 72 National Cancer Institute–NCI-designated Cancer Center, designated Comprehen ...
. The incident appeared as the cover story of ''
Newsweek ''Newsweek'' is an American weekly news magazine based in New York City. Founded as a weekly print magazine in 1933, it was widely distributed during the 20th century and has had many notable editors-in-chief. It is currently co-owned by Dev P ...
'' with the title "Beware: Hackers at play". As a result, the U.S. House of Representatives held hearings on computer security and passed several laws. * The group KILOBAUD is formed in February, kicking off a series of other hacker groups that formed soon after. * The movie ''
WarGames ''WarGames'' is a 1983 American techno-thriller film directed by John Badham, written by Lawrence Lasker and Walter F. Parkes, and starring Matthew Broderick, Dabney Coleman, John Wood and Ally Sheedy. Broderick plays David Lightman, a ...
'' introduces the wider public to the phenomenon of hacking and creates a degree of mass paranoia about hackers and their supposed abilities to bring the world to a screeching halt by launching nuclear
ICBM An intercontinental ballistic missile (ICBM) is a ballistic missile with a range (aeronautics), range greater than , primarily designed for nuclear weapons delivery (delivering one or more Thermonuclear weapon, thermonuclear warheads). Conven ...
s. * The
U.S. House of Representatives The United States House of Representatives is a chamber of the bicameral United States Congress; it is the lower house, with the U.S. Senate being the upper house. Together, the House and Senate have the authority under Article One of th ...
begins hearings on computer security hacking. * In his
Turing Award The ACM A. M. Turing Award is an annual prize given by the Association for Computing Machinery (ACM) for contributions of lasting and major technical importance to computer science. It is generally recognized as the highest distinction in the fi ...
lecture,
Ken Thompson Kenneth Lane Thompson (born February 4, 1943) is an American pioneer of computer science. Thompson worked at Bell Labs for most of his career where he designed and implemented the original Unix operating system. He also invented the B (programmi ...
mentions "hacking" and describes a security exploit that he calls a "
Trojan horse In Greek mythology, the Trojan Horse () was a wooden horse said to have been used by the Greeks during the Trojan War to enter the city of Troy and win the war. The Trojan Horse is not mentioned in Homer, Homer's ''Iliad'', with the poem ending ...
".


1984

* Someone calling himself
Lex Luthor Alexander "Lex" Joseph Luthor () is a supervillain in American comic books published by DC Comics. Created by Jerry Siegel and Joe Shuster, the character first appeared in ''Action Comics'' #23 (published on February 22, 1940, with a cover d ...
founds the
Legion of Doom The Legion of Doom is a group of supervillains who originated in '' Challenge of the Superfriends'', an animated series from Hanna-Barbera based on DC Comics' Justice League. The Legion of Doom has since been incorporated into the main DC Univers ...
. Named after a Saturday morning cartoon, the LOD had the reputation of attracting "the best of the best"—until one of the most talented members called Phiber Optik feuded with Legion of Doomer
Erik Bloodaxe Eric Haraldsson ( , ; c.930−954), nicknamed Bloodaxe ( , ) and Brother-Slayer (), was a Norwegian king. He ruled as King of Norway from 932 to 934, and twice as King of Northumbria: from 947 to 948, and again from 952 to 954. Sources His ...
and got 'tossed out of the clubhouse'. Phiber's friends formed a rival group, the Masters of Deception. * The
Comprehensive Crime Control Act The Comprehensive Crime Control Act of 1984 () was the first comprehensive revision of the U.S. criminal code since the early 1900s. It was sponsored by Strom Thurmond James Strom Thurmond Sr. (December 5, 1902 – June 26, 2003) was an ...
gives the Secret Service jurisdiction over
computer fraud Computer fraud is the use of computers, the Internet, Internet devices, and Internet services to defraud people or organizations of resources. In the United States, computer fraud is specifically proscribed by the Computer Fraud and Abuse Act (CFAA ...
. *
Cult of the Dead Cow Cult of the Dead Cow, also known as cDc or cDc Communications, is a computer hacker and DIY media organization founded in 1984 in Lubbock, Texas. The group maintains a weblog on its site, also titled " ult of the Dead Cow. New media are relea ...
forms in
Lubbock, Texas Lubbock ( ) is a city in the U.S. state of Texas and the county seat of Lubbock County. With a population of 272,086 in 2024, Lubbock is the 10th-most populous city in Texas and the 84th-most populous in the United States. The city is in the ...
, and begins publishing its
ezine An online magazine is a magazine published on the Internet, through bulletin board systems and other forms of public computer networks. One of the first magazines to convert from a print magazine format to an online only magazine was the computer ...
. * The
hacker A hacker is a person skilled in information technology who achieves goals and solves problems by non-standard means. The term has become associated in popular culture with a security hackersomeone with knowledge of bug (computing), bugs or exp ...
magazine ''2600'' begins regular publication, right when TAP was putting out its final issue. The editor of ''2600'', "
Emmanuel Goldstein Emmanuel Goldstein is a fictional character and the principal enemy of the state of Oceania in George Orwell's 1949 dystopian novel ''Nineteen Eighty-Four''. The political propaganda of The Party portrays Goldstein as the leader of The Br ...
" (whose real name is Eric Corley), takes his handle from the leader of the resistance in
George Orwell Eric Arthur Blair (25 June 1903 – 21 January 1950) was an English novelist, poet, essayist, journalist, and critic who wrote under the pen name of George Orwell. His work is characterised by lucid prose, social criticism, opposition to a ...
's ''
Nineteen Eighty-Four ''Nineteen Eighty-Four'' (also published as ''1984'') is a dystopian novel and cautionary tale by the English writer George Orwell. It was published on 8 June 1949 by Secker & Warburg as Orwell's ninth and final completed book. Thematically ...
''. The publication provides tips for would-be hackers and phone phreaks, as well as commentary on the hacker issues of the day. Today, copies of ''2600'' are sold at most large retail bookstores. * The
Chaos Communication Congress The Chaos Communication Congress is an annual hacker conference organized by the Chaos Computer Club. The congress features a variety of lectures and workshops on technical and political issues related to security, cryptography, privacy and ...
, the annual European hacker conference organized by the
Chaos Computer Club The Chaos Computer Club (CCC) is Europe's largest association of Hacker (computer security), hackers with 7,700 registered members. Founded in 1981, the association is incorporated as an ''eingetragener Verein'' in Germany, with local chapters ...
, is held in
Hamburg Hamburg (, ; ), officially the Free and Hanseatic City of Hamburg,. is the List of cities in Germany by population, second-largest city in Germany after Berlin and List of cities in the European Union by population within city limits, 7th-lar ...
, Germany. *
William Gibson William Ford Gibson (born March 17, 1948) is an American-Canadian speculative fiction writer and essayist widely credited with pioneering the science fiction subgenre known as cyberpunk. Beginning his writing career in the late 1970s, his ear ...
's groundbreaking science fiction novel ''
Neuromancer ''Neuromancer'' is a 1984 science fiction novel by American-Canadian author William Gibson. Set in a near-future dystopia, the narrative follows Case, a computer hacker enlisted into a crew by a powerful artificial intelligence and a traumatis ...
'', about "Case", a futuristic computer hacker, is published. Considered the first major
cyberpunk Cyberpunk is a subgenre of science fiction in a dystopian futuristic setting said to focus on a combination of "low-life and high tech". It features futuristic technological and scientific achievements, such as artificial intelligence and cyberwa ...
novel, it brought into hacker jargon such terms as "
cyberspace Cyberspace is an interconnected digital environment. It is a type of virtual world popularized with the rise of the Internet. The term entered popular culture from science fiction and the arts but is now used by technology strategists, security ...
", "the matrix", "simstim", and "
ICE Ice is water that is frozen into a solid state, typically forming at or below temperatures of 0 ° C, 32 ° F, or 273.15 K. It occurs naturally on Earth, on other planets, in Oort cloud objects, and as interstellar ice. As a naturally oc ...
".


1985

* KILOBAUD is re-organized into The P.H.I.R.M. and begins
sysop A sysop (, an abbreviation of system operator) is an administrator of a multi-user computer system, such as a bulletin board system (BBS) or an online service virtual community.Jansen, E. & James, V. (2002). NetLingo: the Internet dictionary. Ne ...
ping hundreds of BBSs throughout the United States, Canada, and Europe. * The online 'zine ''
Phrack ''Phrack'' is an e-zine written by and for Hacker (computer security), hackers, first published November 17, 1985. It had a wide circulation which included both hackers and computer security professionals. Originally covering subjects related to ...
'' is established. * '' The Hacker's Handbook'' is published in the UK. * The FBI, Secret Service, Middlesex County NJ Prosecutor's Office and various local law enforcement agencies execute seven search warrants concurrently across New Jersey on July 12, 1985, seizing equipment from BBS operators and users alike for "complicity in computer theft", under a newly passed, and yet untested criminal statute. This is famously known as the Private Sector Bust, or the 2600 BBS Seizure, and implicated the Private Sector BBS sysop, Store Manager (also a BBS sysop), Beowulf, Red Barchetta, The Vampire, the NJ Hack Shack BBS sysop, and the Treasure Chest BBS sysop.


1986

* After more and more break-ins to
government A government is the system or group of people governing an organized community, generally a State (polity), state. In the case of its broad associative definition, government normally consists of legislature, executive (government), execu ...
and
corporate A corporation or body corporate is an individual or a group of people, such as an association or company, that has been authorized by the state to act as a single entity (a legal entity recognized by private and public law as "born out of s ...
computers, Congress passes the
Computer Fraud and Abuse Act The Computer Fraud and Abuse Act of 1986 (CFAA) is a United States cybersecurity bill that was enacted in 1986 as an amendment to existing computer fraud law (), which had been included in the Comprehensive Crime Control Act of 1984. Prior ...
, which makes it a crime to break into computer systems. The law, however, does not cover juveniles. * Robert Schifreen and Stephen Gold are convicted of accessing the Telecom Gold account belonging to the
Duke of Edinburgh Duke of Edinburgh, named after the capital city of Scotland, Edinburgh, is a substantive title that has been created four times since 1726 for members of the British royal family. It does not include any territorial landholdings and does not pr ...
under the
Forgery and Counterfeiting Act 1981 The Forgery and Counterfeiting Act 1981 (c. 45) is an Act of the Parliament of the United Kingdom which makes it illegal to make fake versions of many things, including legal documents, contracts, audio and visual recordings, and money of the U ...
in the United Kingdom, the first conviction for illegally accessing a computer system. On appeal, the conviction is overturned as hacking is not within the legal definition of forgery. * Arrest of a hacker who calls himself The Mentor. He published a now-famous treatise shortly after his arrest that came to be known as the
Hacker Manifesto __NOTOC__ ''The Conscience of a Hacker'' (also known as ''The Hacker Manifesto'') is a short essay written on March 18, 1986, by Loyd Blankenship, a computer security hacker who went by the handle The Mentor, and belonged to the second-generati ...
in the e-zine
Phrack ''Phrack'' is an e-zine written by and for Hacker (computer security), hackers, first published November 17, 1985. It had a wide circulation which included both hackers and computer security professionals. Originally covering subjects related to ...
. This still serves as the most famous piece of hacker literature and is frequently used to illustrate the mindset of hackers. * Astronomer
Clifford Stoll Clifford Paul "Cliff" Stoll (born June 4, 1950) is an American astronomer, author and teacher. He is best known for his investigation in 1986, while working as a system administrator at the Lawrence Berkeley National Laboratory, that led to th ...
plays a pivotal role in tracking down hacker
Markus Hess Markus Hess is a German hacker who was active in the 1980s. Alongside Dirk Brzezinski and Peter Carl, Hess hacked into networks of military and industrial computers based in the United States, Europe and East Asia, and sold the information to the ...
, events later covered in Stoll's 1990 book '' The Cuckoo's Egg''.


1987

* The
Christmas Tree EXEC Christmas Tree EXEC was the first widely disruptive computer worm, which paralyzed several international computer networks in December 1987. The virus ran on the IBM VM/CMS operating system. Written by a student at the Clausthal University of ...
"worm" causes major disruption to the VNET,
BITNET BITNET was a co-operative United States, U.S. university computer network founded in 1981 by Ira Fuchs at the City University of New York (CUNY) and Greydon Freeman at Yale University. The first network link was between CUNY and Yale. Backgrou ...
and EARN networks.


1988

* The ''
Morris Worm The Morris worm or Internet worm of November 2, 1988, is one of the oldest computer worms distributed via the Internet, and the first to gain significant mainstream media attention. It resulted in the first felony conviction in the US under the ...
''. Graduate student Robert T. Morris, Jr. of Cornell University launches a worm on the government's ARPAnet (precursor to the Internet). The worm spreads to 6,000 networked computers, clogging government and university systems. Robert Morris is dismissed from Cornell, sentenced to three years' probation, and fined $10,000. *
First National Bank of Chicago First Chicago Bank was a Chicago, United States-based retail and commercial bank tracing its roots to 1863, when it received one of the first charters under the then new National Bank Act. Over the years, the bank operated under several names inc ...
is the victim of $70 million computer theft. * The Computer Emergency Response Team (CERT) is created by
DARPA The Defense Advanced Research Projects Agency (DARPA) is a research and development agency of the United States Department of Defense responsible for the development of emerging technologies for use by the military. Originally known as the Adva ...
to address network security. * The Father Christmas (computer worm) spreads over
DECnet DECnet is a suite of network protocols created by Digital Equipment Corporation. Originally released in 1975 in order to connect two PDP-11 minicomputers, it evolved into one of the first peer-to-peer network architectures, thus transforming DEC ...
networks.


1989

*
Jude Milhon Judith Milhon (March 12, 1939 – July 19, 2003), best known by her pseudonym St. Jude, was a self-taught programmer, civil rights advocate, writer, editor, advocate for women in computing, hacker and author in the San Francisco Bay Area. Milho ...
(aka St Jude) and R. U. Sirius launch ''
MONDO 2000 ''Mondo 2000'' was a glossy cyberculture magazine published in California during the 1980s and 1990s. It covered cyberpunk topics such as virtual reality and smart drugs. It was a more anarchic and subversive prototype for the later-founded ''W ...
'', a major '90s tech-lifestyle magazine, in
Berkeley, California Berkeley ( ) is a city on the eastern shore of San Francisco Bay in northern Alameda County, California, United States. It is named after the 18th-century Anglo-Irish bishop and philosopher George Berkeley. It borders the cities of Oakland, Cali ...
. * The politically motivated WANK worm spreads over
DECnet DECnet is a suite of network protocols created by Digital Equipment Corporation. Originally released in 1975 in order to connect two PDP-11 minicomputers, it evolved into one of the first peer-to-peer network architectures, thus transforming DEC ...
. * Dutch magazine
Hack-Tic ''Hack-Tic'' was a Dutch Hacker (computer security), hacker magazine published between 1989 and 1994. It had a cult following and upset authorities beyond the Dutch borders. History In 1988, a small delegation from the Chaos Computer Club in Ha ...
begins. * The Cuckoo's Egg by Clifford Stoll is published. * The detection of
AIDS (Trojan horse) AIDS, also known as Aids Info Drive or PC Cyborg Trojan, is a DOS Trojan horse whose payload mungs and encrypts the names of all directories on drive C:. It was developed by Dr. Joseph Popp (1950-2006), an evolutionary biologist with a doctorat ...
is the first instance of a ransomware detection.


1990s


1990

*
Operation Sundevil Operation Sundevil was a 1990 nationwide United States Secret Service crackdown on "illegal computer hacking activities." It involved raids in approximately fifteen different cities and resulted in three arrests and the confiscation of computers, ...
introduced. After a prolonged sting investigation, Secret Service agents swoop down on organizers and prominent members of BBSs in 14 U.S. cities including the
Legion of Doom The Legion of Doom is a group of supervillains who originated in '' Challenge of the Superfriends'', an animated series from Hanna-Barbera based on DC Comics' Justice League. The Legion of Doom has since been incorporated into the main DC Univers ...
, conducting early-morning raids and arrests. The arrests involve and are aimed at cracking down on credit-card theft and telephone and wire fraud. The result is a breakdown in the hacking community, with members informing on each other in exchange for immunity. The offices of
Steve Jackson Games Steve Jackson Games (SJGames) is a game company, founded in 1980 by Steve Jackson, that creates and publishes role-playing, board, and card games, and (until 2019) the gaming magazine ''Pyramid''. History Founded in 1980, six years after the cr ...
are also raided, and the
role-playing Role-playing or roleplaying is the changing of one's behaviour to assume a role, either unconsciously to fill a social role, or consciously to act out an adopted role. While the ''Oxford English Dictionary'' offers a definition of role-playing ...
sourcebook
GURPS Cyberpunk ''GURPS Cyberpunk'' is a genre toolkit for cyberpunk-themed role-playing games set in a near-future dystopia, such as that envisioned by William Gibson in his influential novel ''Neuromancer''. It was published in 1990 after a significant dela ...
is confiscated, possibly because the government fears it is a "handbook for computer crime". Legal battles arise that prompt the formation of the
Electronic Frontier Foundation The Electronic Frontier Foundation (EFF) is an American international non-profit digital rights group based in San Francisco, California. It was founded in 1990 to promote Internet civil liberties. It provides funds for legal defense in court, ...
, including the trial of
Knight Lightning Craig Neidorf (born 1969), Knight Lightning, is an American editor. He was one of the founding editors of ''Phrack'' Magazine, an Online magazine, ezine. In 1990, he was charged for fraud, though later the charges were dropped. The case was a c ...
. * Australian federal police tracking ''Realm'' members '' Phoenix'', ''
Electron The electron (, or in nuclear reactions) is a subatomic particle with a negative one elementary charge, elementary electric charge. It is a fundamental particle that comprises the ordinary matter that makes up the universe, along with up qua ...
'' and ''Nom'' are the first in the world to use a remote data intercept to gain evidence for a computer crime prosecution. * The
Computer Misuse Act 1990 The Computer Misuse Act 1990 (c. 18) is an act of the Parliament of the United Kingdom, introduced partly in response to the decision in ''R v Gold & Schifreen'' (1988) 1 AC 1063. Critics of the bill complained that it was introduced hastily, w ...
is passed in the United Kingdom, criminalising any unauthorised access to computer systems.


1992

* Release of the movie ''
Sneakers Sneakers (American English, US) or trainers (British English, UK), also known by a #Names, wide variety of other names, are shoes primarily designed for sports or other forms of physical exercise, but are also widely used for everyday casual ...
'', in which security experts are blackmailed into stealing a universal decoder for
encryption In Cryptography law, cryptography, encryption (more specifically, Code, encoding) is the process of transforming information in a way that, ideally, only authorized parties can decode. This process converts the original representation of the inf ...
system A system is a group of interacting or interrelated elements that act according to a set of rules to form a unified whole. A system, surrounded and influenced by its open system (systems theory), environment, is described by its boundaries, str ...
s. * One of the first ISPs, MindVox, opens to the public. * Bulgarian virus writer
Dark Avenger Dark Avenger was the pseudonym of a computer virus writer from Sofia, Bulgaria. He gained considerable notoriety during the early 1990s when his viruses spread internationally. Background and origins During the Cold War, the Bulgarian govern ...
wrote
1260 Year 1260 ( MCCLX) was a leap year starting on Thursday of the Julian calendar. Events By place Africa * October 24 – Saif ad-Din Qutuz, Mamluk sultan of Egypt, is assassinated by Baibars, who seizes power for himself. * The civil se ...
, the first known use of
polymorphic code In computing, polymorphic code is code that uses a polymorphic engine to mutate while keeping the original algorithm intact - that is, the ''code'' changes itself every time it runs, but the ''function'' of the code (its semantics) stays the sam ...
, used to circumvent the type of pattern recognition used by
antivirus software Antivirus software (abbreviated to AV software), also known as anti-malware, is a computer program used to prevent, detect, and remove malware. Antivirus software was originally developed to detect and remove computer viruses, hence the name ...
, and nowadays also
intrusion detection system An intrusion detection system (IDS) is a device or software application that monitors a network or systems for malicious activity or policy violations. Any intrusion activity or violation is typically either reported to an administrator or collec ...
s. * Publication of a hacking instruction manual for penetrating TRW credit reporting agency by Infinite Possibilities Society (IPS) gets Dr. Ripco, the sysop of Ripco BBS mentioned in the IPS manual, arrested by the
United States Secret Service The United States Secret Service (USSS or Secret Service) is a federal law enforcement agency under the Department of Homeland Security tasked with conducting criminal investigations and providing protection to American political leaders, thei ...
.


1993

* The first
DEF CON DEF CON (also written as DEFCON, Defcon, or DC) is a Computer security conference, hacker convention held annually in Las Vegas Valley, Las Vegas, Nevada. The first DEF CON took place in June 1993 and today many attendees at DEF CON include comp ...
hacking conference takes place in
Las Vegas Las Vegas, colloquially referred to as Vegas, is the most populous city in the U.S. state of Nevada and the county seat of Clark County. The Las Vegas Valley metropolitan area is the largest within the greater Mojave Desert, and second-l ...
. The conference is meant to be a one-time party to say good-bye to BBSs (now replaced by the Web), but the gathering was so popular it became an annual event. *
AOL AOL (formerly a company known as AOL Inc. and originally known as America Online) is an American web portal and online service provider based in New York City, and a brand marketed by Yahoo! Inc. The service traces its history to an online ...
gives its users access to
Usenet Usenet (), a portmanteau of User's Network, is a worldwide distributed discussion system available on computers. It was developed from the general-purpose UUCP, Unix-to-Unix Copy (UUCP) dial-up network architecture. Tom Truscott and Jim Elli ...
, precipitating Eternal September.


1994

* Summer:
Russia Russia, or the Russian Federation, is a country spanning Eastern Europe and North Asia. It is the list of countries and dependencies by area, largest country in the world, and extends across Time in Russia, eleven time zones, sharing Borders ...
n crackers siphon $10 million from Citibank and transfer the money to bank accounts around the world. Vladimir Levin, the 30-year-old ringleader, used his work laptop after hours to transfer the funds to accounts in Finland and
Israel Israel, officially the State of Israel, is a country in West Asia. It Borders of Israel, shares borders with Lebanon to the north, Syria to the north-east, Jordan to the east, Egypt to the south-west, and the Mediterranean Sea to the west. Isr ...
. Levin stands trial in the United States and is sentenced to three years in prison. Authorities recover all but $400,000 of the stolen money. * Hackers adapt to emergence of the
World Wide Web The World Wide Web (WWW or simply the Web) is an information system that enables Content (media), content sharing over the Internet through user-friendly ways meant to appeal to users beyond Information technology, IT specialists and hobbyis ...
quickly, moving all their how-to information and hacking programs from the old BBSs to new hacker
web site A website (also written as a web site) is any web page whose content is identified by a common domain name and is published on at least one web server. Websites are typically dedicated to a particular topic or purpose, such as news, education, ...
s. *
AOHell AOHell was a Windows application that was used to simplify ' cracking' (computer hacking) using AOL. The program contained a very early use of the term phishing. It was created by a teenager under the pseudonym Da Chronic, whose expressed motiv ...
is released, a
freeware Freeware is software, often proprietary, that is distributed at no monetary cost to the end user. There is no agreed-upon set of rights, license, or EULA that defines ''freeware'' unambiguously; every publisher defines its own rules for the free ...
application that allows a burgeoning community of unskilled
script kiddie A script kiddie, skript kiddie, skiddie, kiddie, or skid is a pejorative term used to describe an unskilled individual who uses malicious scripts or programs developed by others or LLMs. Characteristics The term script kiddie was first used in ...
s to wreak havoc on
America Online AOL (formerly a company known as AOL Inc. and originally known as America Online) is an American web portal and online service provider based in New York City, and a brand marketed by Yahoo! Inc. (2017–present), Yahoo! Inc. The service tra ...
. For days, hundreds of thousands of AOL users find their mailboxes flooded with multi-megabyte
email bomb On Internet usage, an email bomb is a form of net abuse that sends large volumes of email to an address to overflow the mailbox, overwhelm the server where the email address is hosted in a denial-of-service attack or as a smoke screen to distrac ...
s and their chat rooms disrupted with
spam Spam most often refers to: * Spam (food), a consumer brand product of canned processed pork of the Hormel Foods Corporation * Spamming, unsolicited or undesired electronic messages ** Email spam, unsolicited, undesired, or illegal email messages ...
messages. * December 27: After experiencing an IP spoofing attack by
Kevin Mitnick Kevin David Mitnick (August 6, 1963 – July 16, 2023) was an American computer security consultant, author, and convicted hacker. In 1995, he was arrested for various computer and communications-related crimes, and spent five years in prison ...
, computer security expert Tsutomu Shimomura started to receive prank calls that popularized the phrase " My kung fu is stronger than yours".


1995

* The movies '' The Net'' and ''
Hackers A hacker is a person skilled in information technology who achieves goals and solves problems by non-standard means. The term has become associated in popular culture with a security hackersomeone with knowledge of bugs or exploits to break ...
'' are released. * The Canadian ISP dlcwest.com is hacked and website replaced with a graphic and the caption "You've been hacked MOFO" * The US Secret Service raid 12 and arrest 6 cellular phone hackers in Operation Cybersnare * February 22: The
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
raids the "Phone Masters".


1996

* Hackers alter Web sites of the
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the U.S. government that oversees the domestic enforcement of Law of the Unite ...
(August), the
CIA The Central Intelligence Agency (CIA; ) is a civilian foreign intelligence service of the federal government of the United States tasked with advancing national security through collecting and analyzing intelligence from around the world and ...
(October), and the
U.S. Air Force The United States Air Force (USAF) is the air service branch of the United States Department of Defense. It is one of the six United States Armed Forces and one of the eight uniformed services of the United States. Tracing its origins to 1 ...
(December). * Canadian hacker group, Brotherhood, breaks into the
Canadian Broadcasting Corporation The Canadian Broadcasting Corporation (), branded as CBC/Radio-Canada, is the Canadian Public broadcasting, public broadcaster for both radio and television. It is a Crown corporation that serves as the national public broadcaster, with its E ...
. * Arizona hacker, John Sabo A.K.A FizzleB/Peanut, was arrested for hacking Canadian ISP dlcwest.com claiming the company was defrauding customers through over billing. * The US general accounting office reports that hackers attempted to break into Defense Department computer files some 250,000 times in 1995 alone with a success rate of about 65% and doubling annually. *
Cryptovirology Cryptovirology refers to the study of cryptography use in malware, such as ransomware and asymmetric backdoors. Traditionally, cryptography and its applications are defensive in nature, and provide privacy, authentication, and security to users. ...
is born with the invention of the cryptoviral extortion protocol that would later form the basis of modern
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
.IEEEExplore: Cryptovirology: extortion-based security threats and countermeasures
/ref>


1997

* The greatest AOL hack program ever written, Lucifer-X by NailZ, is released. In a matter of days AOL is being used for free by hundreds of thousands of users. * A 16-year-old
Croatia Croatia, officially the Republic of Croatia, is a country in Central Europe, Central and Southeast Europe, on the coast of the Adriatic Sea. It borders Slovenia to the northwest, Hungary to the northeast, Serbia to the east, Bosnia and Herze ...
n youth penetrates computers at a U.S. Air Force base in
Guam Guam ( ; ) is an island that is an Territories of the United States, organized, unincorporated territory of the United States in the Micronesia subregion of the western Pacific Ocean. Guam's capital is Hagåtña, Guam, Hagåtña, and the most ...
. * June: Eligible Receiver 97 tests the American government's readiness against
cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
s. * December
Information Security
publishes first issue. * First high-profile attacks on Microsoft's
Windows NT Windows NT is a Proprietary software, proprietary Graphical user interface, graphical operating system produced by Microsoft as part of its Windows product line, the first version of which, Windows NT 3.1, was released on July 27, 1993. Original ...
operating system An operating system (OS) is system software that manages computer hardware and software resources, and provides common daemon (computing), services for computer programs. Time-sharing operating systems scheduler (computing), schedule tasks for ...


1998

* January:
Yahoo! Yahoo (, styled yahoo''!'' in its logo) is an American web portal that provides the search engine Yahoo Search and related services including My Yahoo, Yahoo Mail, Yahoo News, Yahoo Finance, Yahoo Sports, y!entertainment, yahoo!life, and its a ...
notifies Internet users that anyone visiting its site in the past month might have downloaded a
logic bomb A logic bomb is a piece of code intentionally inserted into a software system that will set off a malicious function when specified conditions are met. For example, a programmer may hide a piece of code that starts deleting files (such as a salar ...
and
worm Worms are many different distantly related bilateria, bilateral animals that typically have a long cylindrical tube-like body, no limb (anatomy), limbs, and usually no eyes. Worms vary in size from microscopic to over in length for marine ...
planted by hackers claiming a "logic bomb" will go off if computer hacker
Kevin Mitnick Kevin David Mitnick (August 6, 1963 – July 16, 2023) was an American computer security consultant, author, and convicted hacker. In 1995, he was arrested for various computer and communications-related crimes, and spent five years in prison ...
is not released from prison. * February: The
Internet Software Consortium Internet Systems Consortium, Inc., also known as ISC, is an American non-profit corporation that supports the infrastructure of the universal, self-organizing Internet by developing and maintaining core production-quality software, protocols, and ...
proposes the use of DNSSEC (
Domain Name System Security Extensions The Domain Name System Security Extensions (DNSSEC) is a suite of Extension Mechanisms for DNS, extension specifications by the Internet Engineering Task Force (IETF) for securing data exchanged in the Domain Name System (DNS hijacking, DNS) in In ...
) to secure
DNS server A name server is a computer application that implements a network service for providing responses to queries against a directory service. It translates an often humanly meaningful, text-based identifier to a system-internal, often numeric identi ...
s. * May 19: The seven members of the hacker think tank known as
L0pht L0pht Heavy Industries (pronounced "loft") was a hacker collective active between 1992 and 2000 and located in the Boston, Massachusetts area. The L0pht was one of the first viable hackerspaces in the US, and a pioneer of responsible disclosure. ...
testify in front of the US congressional Government Affairs committee on "Weak Computer Security in Government". * June: Information Security publishes its first annual Industry Survey, finding that nearly three-quarters of organizations suffered a security incident in the previous year. * September:
Electronic Disturbance Theater The Electronic Disturbance Theater (EDT), established in 1997 by performance artist and writer Ricardo Dominguez, is an electronic company of cyber activists, critical theorists, and performance artists. History The Electronic Disturbance Theat ...
, an online political performance-
art group An artist collective or art group or artist group is an initiative that is the result of a group of artists working together, usually under their own management, towards shared aims. The aims of an artist collective can include almost anything t ...
, attacks the websites of
The Pentagon The Pentagon is the headquarters building of the United States Department of Defense, in Arlington County, Virginia, across the Potomac River from Washington, D.C. The building was constructed on an accelerated schedule during World War II. As ...
, Mexican president
Ernesto Zedillo Ernesto Zedillo Ponce de León (; born 27 December 1951) is a Mexican economist and politician. He was the 61st president of Mexico from 1994 to 2000, as the last of the uninterrupted 71-year line of Mexican presidents from the Institutional Re ...
, and the
Frankfurt Stock Exchange The Frankfurt Stock Exchange (, former German name: , ''FWB'') is the world's 3rd oldest and 12th largest stock exchange by market capitalization. It has operations from 8:00 am to 10:00 pm ( German time). Organisation Located in Frankfurt, ...
, calling it conceptual art and claiming it to be a protest against the suppression of the
Zapatista Army of National Liberation The Zapatista Army of National Liberation (, EZLN), often referred to as the Zapatistas (), is a far-left political and militant group that controls a substantial amount of territory in Chiapas, the southernmost state of Mexico. Since 1994, t ...
in southern Mexico. EDT uses the FloodNet software to bombard its opponents with access requests. * October: "
U.S. Attorney General The United States attorney general is the head of the United States Department of Justice and serves as the chief law enforcement officer of the federal government. The attorney general acts as the principal legal advisor to the president of the ...
Janet Reno Janet Wood Reno (July 21, 1938 – November 7, 2016) was an American lawyer and public official who served as the 78th United States Attorney General, United States attorney general from 1993 to 2001 under President Bill Clinton. A member of ...
announces
National Infrastructure Protection Center The National Infrastructure Protection Center (NIPC) was a unit of the United States federal government A federation (also called a federal state) is an entity characterized by a political union, union of partially federated state, self-go ...
."


1999

*
Software security Application security (short AppSec) includes all tasks that introduce a secure software development life cycle to development teams. Its final goal is to improve security practices and, through that, to find, fix and preferably prevent security is ...
goes mainstream In the wake of Microsoft's
Windows 98 Windows 98 is a consumer-oriented operating system developed by Microsoft as part of its Windows 9x family of Microsoft Windows operating systems. It was the second operating system in the 9x line, as the successor to Windows 95. It was Software ...
release, 1999 becomes a banner year for security (and hacking). Hundreds of advisories and patches are released in response to newfound (and widely publicized) bugs in Windows and other commercial software products. A host of security software vendors release anti-hacking products for use on home computers. * U.S. President
Bill Clinton William Jefferson Clinton (né Blythe III; born August 19, 1946) is an American politician and lawyer who was the 42nd president of the United States from 1993 to 2001. A member of the Democratic Party (United States), Democratic Party, ...
announces a $1.46 billion initiative to improve government
computer security Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and computer network, n ...
. The plan would establish a network of intrusion detection monitors for certain federal agencies and encourage the private sector to do the same. * January 7: The "Legion of the Underground" (LoU) declares "war" against the governments of Iraq and the People's Republic of China. An international coalition of hackers (including
Cult of the Dead Cow Cult of the Dead Cow, also known as cDc or cDc Communications, is a computer hacker and DIY media organization founded in 1984 in Lubbock, Texas. The group maintains a weblog on its site, also titled " ult of the Dead Cow. New media are relea ...
, ''2600''s staff, ''
Phrack ''Phrack'' is an e-zine written by and for Hacker (computer security), hackers, first published November 17, 1985. It had a wide circulation which included both hackers and computer security professionals. Originally covering subjects related to ...
''s staff,
L0pht L0pht Heavy Industries (pronounced "loft") was a hacker collective active between 1992 and 2000 and located in the Boston, Massachusetts area. The L0pht was one of the first viable hackerspaces in the US, and a pioneer of responsible disclosure. ...
, and the
Chaos Computer Club The Chaos Computer Club (CCC) is Europe's largest association of Hacker (computer security), hackers with 7,700 registered members. Founded in 1981, the association is incorporated as an ''eingetragener Verein'' in Germany, with local chapters ...
) issued a joint statement
CRD 990107 - Hackers on planet earth against infowar
condemning the LoU's declaration of war. The LoU responded by withdrawing its declaration. * March: The Melissa worm is released and quickly becomes the most costly malware outbreak to date. * July:
Cult of the Dead Cow Cult of the Dead Cow, also known as cDc or cDc Communications, is a computer hacker and DIY media organization founded in 1984 in Lubbock, Texas. The group maintains a weblog on its site, also titled " ult of the Dead Cow. New media are relea ...
releases Back Orifice 2000 at
DEF CON DEF CON (also written as DEFCON, Defcon, or DC) is a Computer security conference, hacker convention held annually in Las Vegas Valley, Las Vegas, Nevada. The first DEF CON took place in June 1993 and today many attendees at DEF CON include comp ...
. * August:
Kevin Mitnick Kevin David Mitnick (August 6, 1963 – July 16, 2023) was an American computer security consultant, author, and convicted hacker. In 1995, he was arrested for various computer and communications-related crimes, and spent five years in prison ...
, is sentenced to 5 years, of which over 4 years had already been spent pre-trial including 8 months' solitary confinement. * September: Level Seven Crew hacks the U.S. Embassy in China's website and places racist, anti-government slogans on embassy site in regards to 1998 U.S. embassy bombings. * September 16: The
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the U.S. government that oversees the domestic enforcement of Law of the Unite ...
sentences the "Phone Masters". * October:
American Express American Express Company or Amex is an American bank holding company and multinational financial services corporation that specializes in payment card industry, payment cards. It is headquartered at 200 Vesey Street, also known as American Expr ...
introduces the "Blue"
smart card A smart card (SC), chip card, or integrated circuit card (ICC or IC card), is a card used to control access to a resource. It is typically a plastic credit card-sized card with an Embedded system, embedded integrated circuit (IC) chip. Many smart ...
, the industry's first chip-based credit card in the US. * November 17: A hacker interviewed by Hilly Rose during the radio show ''
Coast to Coast AM ''Coast to Coast AM'' is an American late-night radio talk show that deals with a variety of topics. Most frequently the topics relate to either the paranormal or conspiracy theories. It was hosted by creator Art Bell from its inception in 198 ...
'' (then hosted by
Art Bell Arthur William Bell III (June 17, 1945 – April 13, 2018) was an American broadcaster and author. He was the founder and the original host of the paranormal-themed radio program '' Coast to Coast AM'', which is syndicated on hundreds ...
) exposes a plot by al-Qaeda to derail
Amtrak The National Railroad Passenger Corporation, Trade name, doing business as Amtrak (; ), is the national Passenger train, passenger railroad company of the United States. It operates intercity rail service in 46 of the 48 contiguous United Stat ...
trains. This results in all trains being forcibly stopped over Y2K as a safety measure.


2000s


2000

* May: The
ILOVEYOU ILOVEYOU, sometimes referred to as the Love Bug or Loveletter, was a computer worm that infected over ten million Windows personal computers on 4 May 2000 and after 5 May 2000. It started spreading as an email message with the subject line "ILO ...
worm, also known as VBS/Loveletter and Love Bug worm, is a computer worm written in VBScript. It infected millions of computers worldwide within a few hours of its release. It is considered to be one of the most damaging worms ever. It originated in the Philippines; made by an
AMA Computer College AMA University, also known as AMA Computer University (AMACU) or simply AMA, is a private, nonsectarian, for-profit university in Quezon City, Philippines. History AMA Institute of Computer Studies AMA University and its sister school AMA Comp ...
student Onel de Guzman for his thesis. * September: Computer hacker Jonathan James became the first juvenile to serve jail time for hacking.


2001

* Microsoft becomes the prominent victim of a new type of hack that attacks the domain name server. In these
denial-of-service attack In computing, a denial-of-service attack (DoS attack) is a cyberattack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host co ...
s, the DNS paths that take users to Microsoft's websites are corrupted. * February: A Dutch cracker releases the
Anna Kournikova Anna Sergeyevna Kournikova Iglesias (née Kournikova; ; ; born 7 June 1981) is a Russian model and television personality, and former professional tennis player. Her appearance and celebrity status made her one of the best known tennis stars ...
virus A virus is a submicroscopic infectious agent that replicates only inside the living Cell (biology), cells of an organism. Viruses infect all life forms, from animals and plants to microorganisms, including bacteria and archaea. Viruses are ...
, initiating a wave of viruses that tempts users to open the infected attachment by promising a sexy picture of the Russian
tennis Tennis is a List of racket sports, racket sport that is played either individually against a single opponent (singles (tennis), singles) or between two teams of two players each (doubles (tennis), doubles). Each player uses a tennis racket st ...
star. * April: FBI agents trick two Russian crackers into coming to the U.S. and revealing how they were hacking U.S. banks. * July: Russian programmer Dmitry Sklyarov is arrested at the annual
DEF CON DEF CON (also written as DEFCON, Defcon, or DC) is a Computer security conference, hacker convention held annually in Las Vegas Valley, Las Vegas, Nevada. The first DEF CON took place in June 1993 and today many attendees at DEF CON include comp ...
hacker convention. He was the first person criminally charged with violating the
Digital Millennium Copyright Act The Digital Millennium Copyright Act (DMCA) is a 1998 United States copyright law that implements two 1996 treaties of the World Intellectual Property Organization (WIPO). It criminalizes production and dissemination of technology, devices, or ...
(DMCA). * August: Code Red worm, infects tens of thousands of machines. * The National Cyber Security Alliance (NCSA) is established in response to the September 11 attacks on the World Trade Center.


2002

* January:
Bill Gates William Henry Gates III (born October 28, 1955) is an American businessman and philanthropist. A pioneer of the microcomputer revolution of the 1970s and 1980s, he co-founded the software company Microsoft in 1975 with his childhood friend ...
decrees that Microsoft will secure its products and services, and kicks off a massive internal
training Training is teaching, or developing in oneself or others, any skills and knowledge or fitness that relate to specific useful competencies. Training has specific goals of improving one's capability, capacity, productivity and performance. I ...
and
quality control Quality control (QC) is a process by which entities review the quality of all factors involved in production. ISO 9000 defines quality control as "a part of quality management focused on fulfilling quality requirements". This approach plac ...
campaign. * March: Gary McKinnon is arrested following unauthorized access to US military and NASA computers. * May: Klez.H, a variant of the worm discovered in November 2001, becomes the biggest
malware Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
outbreak in terms of machines infected, but causes little monetary damage. * June: The Bush administration files a bill to create the
Department of Homeland Security The United States Department of Homeland Security (DHS) is the U.S. federal executive department responsible for public security, roughly comparable to the interior, home, or public security ministries in other countries. Its missions invol ...
, which, among other things, will be responsible for protecting the nation's critical IT
infrastructure Infrastructure is the set of facilities and systems that serve a country, city, or other area, and encompasses the services and facilities necessary for its economy, households and firms to function. Infrastructure is composed of public and pri ...
. * August: Researcher Chris Paget publishes a paper describing " shatter attacks", detailing how Windows' unauthenticated messaging system can be used to take over a machine. The paper raises questions about how securable Windows could ever be. It is however largely derided as irrelevant as the vulnerabilities it described are caused by vulnerable applications (placing windows on the desktop with inappropriate privileges) rather than an inherent flaw within the Operating System. * October: The International Information Systems Security Certification Consortium—(ISC)²—confers its 10,000th
CISSP CISSP (Certified Information Systems Security Professional) is an independent information security certification granted by the International Information System Security Certification Consortium, also known as ISC2. As of July 2022, there were 1 ...
certification.


2003

* The hacktivist group
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
was formed. * March:
Cult of the Dead Cow Cult of the Dead Cow, also known as cDc or cDc Communications, is a computer hacker and DIY media organization founded in 1984 in Lubbock, Texas. The group maintains a weblog on its site, also titled " ult of the Dead Cow. New media are relea ...
and Hacktivismo are given permission by the
United States Department of Commerce The United States Department of Commerce (DOC) is an executive department of the U.S. federal government. It is responsible for gathering data for business and governmental decision making, establishing industrial standards, catalyzing econ ...
to export software utilizing strong encryption.


2004

* March:
New Zealand New Zealand () is an island country in the southwestern Pacific Ocean. It consists of two main landmasses—the North Island () and the South Island ()—and List of islands of New Zealand, over 600 smaller islands. It is the List of isla ...
's Government (National Party) website defaced by hacktivist group BlackMask * July:
North Korea North Korea, officially the Democratic People's Republic of Korea (DPRK), is a country in East Asia. It constitutes the northern half of the Korea, Korean Peninsula and borders China and Russia to the north at the Yalu River, Yalu (Amnok) an ...
claims to have trained 500 hackers who successfully crack South Korean, Japanese, and their allies' computer systems. * October: National Cyber Security Awareness Month was launched by the National Cyber Security Alliance and U.S. Department of Homeland Security.


2005

* April 2: Rafael Núñez (aka RaFa), a notorious member of the hacking group World of Hell, is arrested following his arrival at Miami International Airport for breaking into the
Defense Information Systems Agency The Defense Information Systems Agency (DISA), known as the Defense Communications Agency (DCA) until 1991, is a United States Department of Defense (DoD) combat support agency. It is composed of military, federal civilians, and contractors. D ...
computer system in June 2001. * September 13: Cameron Lacroix is sentenced to 11 months for gaining access to
T-Mobile T-Mobile is the brand of telecommunications by Deutsche Telekom Deutsche Telekom AG (, ; often just Telekom, DTAG or DT; stylised as ·T·) is a partially state-owned German telecommunications company headquartered in Bonn and the largest telec ...
's network and exploiting
Paris Hilton Paris Whitney Hilton (born February 17, 1981) is an American media personality, businesswoman, and socialite. Hilton was born in New York City and raised there partially; shuttling between Los Angeles and New York City; she is a great-grandda ...
's
Sidekick A sidekick is a close companion or colleague who is, or is generally regarded as, subordinate to those whom they accompany. Origins The first recorded use of the term dates from 1896. It is believed to have originated in pickpocket slang of ...
. * November 3: Jeanson James Ancheta, whom prosecutors say was a member of the "Botmaster Underground", a group of
script kiddie A script kiddie, skript kiddie, skiddie, kiddie, or skid is a pejorative term used to describe an unskilled individual who uses malicious scripts or programs developed by others or LLMs. Characteristics The term script kiddie was first used in ...
s mostly noted for their excessive use of bot attacks and propagating vast amounts of
spam Spam most often refers to: * Spam (food), a consumer brand product of canned processed pork of the Hormel Foods Corporation * Spamming, unsolicited or undesired electronic messages ** Email spam, unsolicited, undesired, or illegal email messages ...
, was taken into custody after being lured to FBI offices in Los Angeles.


2006

* January: One of the few worms to take after the old form of malware, destruction of data rather than the accumulation of zombie networks to launch attacks from, is discovered. It had various names, including
Kama Sutra The ''Kama Sutra'' (; , , ; ) is an ancient Indian Hindu Sanskrit text on sexuality, eroticism and emotional fulfillment. Attributed to Vātsyāyana, the ''Kamasutra'' is neither exclusively nor predominantly a sex manual on sex positions ...
(used by most media reports), Black Worm, Mywife, Blackmal, Nyxem version D, Kapser, KillAV, Grew and CME-24. The worm would spread through e-mail client address books, and would search for documents and fill them with garbage, instead of deleting them to confuse the user. It would also hit a web page counter when it took control, allowing the programmer who created it as well as the world to track the progress of the worm. It would replace documents with random garbage on the third of every month. It was hyped by the media but actually affected relatively few computers, and was not a real threat for most users. * May: Jeanson James Ancheta receives a 57-month prison sentence, and is ordered to pay damages amounting to $15,000 to the Naval Air Warfare Center in China Lake and the Defense Information Systems Agency, for damage done due to DDoS attacks and hacking. Ancheta also had to forfeit his gains to the government, which include $60,000 in cash, a BMW, and computer equipment. * May: The largest defacement in Web History as of that time is performed by the Turkish hacker iSKORPiTX who successfully hacked 21,549 websites in one shot. * July: Robert Moore and Edwin Pena were the first people to be charged by U.S. authorities for VoIP hacking. Robert Moore served 2 years in federal prison and was given $152,000 restitution. Once Edwin Pena was caught after fleeing the country, evading authorities for almost 2 years, he was sentenced to 10 years and given $1 million restitution. * September: Viodentia releases FairUse4WM tool which would remove
DRM DRM may refer to: Government, military and politics * Defense reform movement, U.S. campaign inspired by Col. John Boyd * Democratic Republic of Madagascar, a former socialist state (1975–1992) on Madagascar * Direction du renseignement militair ...
information off
Windows Media Audio Windows Media Audio (WMA) is a series of audio codecs and their corresponding audio coding formats developed by Microsoft. It is a proprietary technology that forms part of the Windows Media framework. Audio encoded in WMA is stored in a digi ...
(WMA) files downloaded from music services such as Yahoo! Unlimited, Napster, Rhapsody Music and Urge.


2007

* May 17:
Estonia Estonia, officially the Republic of Estonia, is a country in Northern Europe. It is bordered to the north by the Gulf of Finland across from Finland, to the west by the Baltic Sea across from Sweden, to the south by Latvia, and to the east by Ru ...
recovers from massive denial-of-service attack * June 13: FBI Operation Bot Roast finds over 1 million botnet victims * June 21: A
spear phishing Phishing is a form of Social engineering (security), social engineering and a scam where attackers deceive people into revealing Information sensitivity, sensitive information or installing malware such as Computer virus, viruses, Computer worm, ...
incident at the
Office of the Secretary of Defense The Office of the Secretary of Defense (OSD) is a headquarters-level staff of the United States Department of Defense. It is the principal civilian staff element of the U.S. Secretary of Defense, and it assists the Secretary in carrying out au ...
steals sensitive U.S. defense information, leading to significant changes in identity and message-source verification at OSD. * August 11:
United Nations The United Nations (UN) is the Earth, global intergovernmental organization established by the signing of the Charter of the United Nations, UN Charter on 26 June 1945 with the stated purpose of maintaining international peace and internationa ...
website hacked by Indian Hacker Pankaj Kumar Singh. *November 14: Panda Burning Incense which is known by several other names, including Fujacks and Radoppan.T lead to the arrest of eight people in China. Panda Burning Incense was a parasitic virus that infected executable files on a PC. When infected, the icon of the executable file changes to an image of a panda holding three sticks of incense. The arrests were the first for virus writing in China.


2008

* January 17:
Project Chanology Project Chanology (also called Operation Chanology) was a protest movement against the practices of the Church of Scientology by members of Anonymous (group), Anonymous, a leaderless Internet-based group. "Chanology" is a portmanteau of "4chan" ...
;
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
attacks Scientology website servers around the world. Private documents are stolen from Scientology computers and distributed over the Internet. * March 7: Around 20 Chinese hackers claim to have gained access to the world's most sensitive sites, including
the Pentagon The Pentagon is the headquarters building of the United States Department of Defense, in Arlington County, Virginia, across the Potomac River from Washington, D.C. The building was constructed on an accelerated schedule during World War II. As ...
. They operated from an apartment on a Chinese Island. * March 14:
Trend Micro is an American-Japanese cyber security software company. The company has globally dispersed R&D in 16 locations across every continent excluding Antarctica. The company develops enterprise security software for servers, containers, and cloud ...
website successfully hacked by Turkish hacker Janizary (aka Utku).


2009

* April 4:
Conficker Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 2008. It uses flaws in Windows OS software (MS08-067 / CVE-2008-4250) and dictionary atta ...
worm infiltrated millions of PCs worldwide including many government-level top-security computer networks.


2010s


2010

* January 12:
Operation Aurora Operation Aurora was a series of cyber attacks performed by advanced persistent threats such as the Elderwood Group based in Beijing, China, with associations with the People's Liberation Army. First disclosed publicly by Google (one of the vic ...
Google publicly reveals that it has been on the receiving end of a ''"highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google"'' * June:
Stuxnet Stuxnet is a Malware, malicious computer worm first uncovered on June 17, 2010, and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsibl ...
The Stuxnet worm is found by VirusBlokAda. Stuxnet was unusual in that while it spread via Windows computers, its payload targeted just one specific model and type of
SCADA SCADA (an acronym for supervisory control and data acquisition) is a control system architecture comprising computers, networked data communications and graphical user interfaces for high-level supervision of machines and processes. It also cove ...
systems. It slowly became clear that it was a cyber attack on Iran's nuclear facilities—with most experts believing that Israel was behind it—perhaps with US help. * December 3: The first Malware Conference, MALCON took place in India. Founded by Rajshekhar Murthy, malware coders are invited to showcase their skills at this annual event supported by the Government of India.


2011

* The hacker group Lulz Security is formed. * April 9:
Bank of America The Bank of America Corporation (Bank of America) (often abbreviated BofA or BoA) is an American multinational investment banking, investment bank and financial services holding company headquartered at the Bank of America Corporate Center in ...
website got hacked by a Turkish hacker named JeOPaRDY. An estimated 85,000 credit card numbers and accounts were reported to have been stolen due to the hack. Bank officials say no personal customer bank information is available on that web-page. Investigations are being conducted by the FBI to trace down the incriminated hacker. * April 17: An " external intrusion" sends the
PlayStation Network PlayStation Network (PSN) is a digital media entertainment service provided by Sony Interactive Entertainment. Launched in November 2006, PSN was originally conceived for the PlayStation video game consoles, but soon extended to encompass smartp ...
offline, and compromises personally identifying information (possibly including credit card details) of its 77 million accounts, in what is claimed to be one of the five largest
data breach A data breach, also known as data leakage, is "the unauthorized exposure, disclosure, or loss of personal information". Attackers have a variety of motives, from financial gain to political activism, political repression, and espionage. There ...
es ever. * Computer hacker sl1nk releases information of his penetration in the servers of the Department of Defense (DoD), Pentagon, NASA, NSA, US Military, Department of the Navy, Space and Naval Warfare System Command and other UK/US government websites. * September: Bangladeshi hacker TiGER-M@TE made a world record in defacement history by hacking 700,000 websites in a single shot. * October 16: The
YouTube YouTube is an American social media and online video sharing platform owned by Google. YouTube was founded on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim who were three former employees of PayPal. Headquartered in ...
channel of ''
Sesame Street ''Sesame Street'' is an American educational television, educational children's television series that combines live-action, sketch comedy, animation, and puppetry. It is produced by Sesame Workshop (known as the Children's Television Worksh ...
'' was hacked, streaming pornographic content for about 22 minutes. * November 1: The main phone and Internet networks of the
Palestinian territories The occupied Palestinian territories, also referred to as the Palestinian territories, consist of the West Bank (including East Jerusalem) and the Gaza Strip—two regions of the former Mandate for Palestine, British Mandate for Palestine ...
sustained a hacker attack from multiple locations worldwide. * November 7: The forums for
Valve A valve is a device or natural object that regulates, directs or controls the flow of a fluid (gases, liquids, fluidized solids, or Slurry, slurries) by opening, closing, or partially obstructing various passageways. Valves are technically Pip ...
's
Steam Steam is water vapor, often mixed with air or an aerosol of liquid water droplets. This may occur due to evaporation or due to boiling, where heat is applied until water reaches the enthalpy of vaporization. Saturated or superheated steam is inv ...
service were hacked. Redirects for a hacking website, Fkn0wned, appeared on the Steam users' forums, offering "hacking tutorials and tools, porn, free giveaways and much more." * December 14: Five members of the Norwegian hacker group, Noria, were arrested, allegedly suspected for hacking into the email account of the militant extremist
Anders Behring Breivik Anders Behring Breivik (; born 13 February 1979), officially named Fjotolf Hansen from 2017 to 2025, and Far Skaldigrimmr Rauskjoldr av Northriki since March 2025, is a Norwegian neo-Nazi terrorist and mass murderer. He carried out the 2011 No ...
(who perpetrated the 2011 attacks in the country).


2012

* A hacker published over 400,000 credit cards online, and threatened
Israel Israel, officially the State of Israel, is a country in West Asia. It Borders of Israel, shares borders with Lebanon to the north, Syria to the north-east, Jordan to the east, Egypt to the south-west, and the Mediterranean Sea to the west. Isr ...
to release 1 million credit cards in the future. In response to that incident, an Israeli hacker published over 200 Albanian' credit cards online. * Gottfrid Svartholm Warg, the co-founder of
Pirate Bay The Pirate Bay, commonly abbreviated as TPB, is a free searchable online index of Film, movies, music, video games, Pornographic film, pornography and software. Founded in 2003 by Swedish think tank , The Pirate Bay facilitates the connection ...
, was convicted in Denmark of hacking a mainframe computer, what was then Denmark's biggest hacking case. *January 7: "Team Appunity", a group of Norwegian hackers, were arrested for breaking into Norway's largest prostitution website then publishing the user database online. *February 3: Marriott was hacked by a
New Age New Age is a range of Spirituality, spiritual or Religion, religious practices and beliefs that rapidly grew in Western world, Western society during the early 1970s. Its highly eclecticism, eclectic and unsystematic structure makes a precise d ...
ideologist, Attila Nemeth who was resisting against the New World Order where he said that corporations are allegedly controlling the world. As a response Marriott reported him to the United States Secret Service. *February 8:
Foxconn Hon Hai Precision Industry Co., Ltd. (), Trade name, doing business as Hon Hai Technology Group () in Taiwan, Foxconn Technology Group () in China, and Foxconn () internationally, is a Taiwanese multinational corporation, multinational electron ...
is hacked by a hacker group, "Swagg Security", releasing a massive amount of data including email and server logins, and even more alarming—bank account credentials of large companies like Apple and Microsoft. Swagg Security stages the attack just as a Foxconn protest ignites against terrible working conditions in southern China. *May 4: The websites of several Turkish representative offices of international IT-companies are defaced within the same day by F0RTYS3V3N (Turkish Hacker), including the websites of
Google Google LLC (, ) is an American multinational corporation and technology company focusing on online advertising, search engine technology, cloud computing, computer software, quantum computing, e-commerce, consumer electronics, and artificial ...
,
Yandex Yandex LLC ( rus, Яндекс, r=Yandeks, p=ˈjandəks) is a Russian technology company that provides Internet-related products and services including a web browser, search engine, cloud computing, web mapping, online food ordering, streaming ...
,
Microsoft Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
,
Gmail Gmail is the email service provided by Google. it had 1.5 billion active user (computing), users worldwide, making it the largest email service in the world. It also provides a webmail interface, accessible through a web browser, and is also ...
,
MSN MSN is a web portal and related collection of Internet services and apps provided by Microsoft. The main webpage provides news, weather, sports, finance and other content curated from hundreds of different sources that Microsoft has partnere ...
,
Hotmail Outlook.com, formerly Hotmail, is a free personal email service offered by Microsoft. It also provides a webmail interface accessible via web browser or mobile apps featuring mail, Calendaring software, calendaring, Address book, contacts, and ...
,
PayPal PayPal Holdings, Inc. is an American multinational financial technology company operating an online payments system in the majority of countries that support E-commerce payment system, online money transfers; it serves as an electronic alter ...
. *May 24: WHMCS is hacked by UGNazi, they claim that the reason for this is because of the illegal sites that are using their software. *May 31:
MyBB MyBB, formerly MyBBoard and originally MyBulletinBoard, is a free and open-source forum software developed by the MyBB Group. It is written in PHP, supports MariaDB, MySQL, PostgreSQL and SQLite as database systems and, in addition, has databas ...
is hacked by newly founded hacker group, UGNazi, the website was defaced for about a day, they claim their reasoning for this was because they were upset that the forum board Hackforums.net uses their software. *June 5: The social networking website
LinkedIn LinkedIn () is an American business and employment-oriented Social networking service, social network. It was launched on May 5, 2003 by Reid Hoffman and Eric Ly. Since December 2016, LinkedIn has been a wholly owned subsidiary of Microsoft. ...
has been hacked and the passwords for nearly 6.5 million user accounts are stolen by cybercriminals. As a result, a United States grand jury indicted Nikulin and three unnamed co-conspirators on charges of aggravated identity theft and computer intrusion. *August 15:
Saudi Aramco Saudi Aramco ( ') or Aramco (formerly Arabian-American Oil Company), officially the Saudi Arabian Oil Company, is a majority state-owned petroleum and natural gas company that is the national oil company of Saudi Arabia. , it is the fourth- l ...
is crippled by a cyber warfare attack for months by malware called
Shamoon Shamoon (), also known as W32.DistTrack, is a modular computer virus that was discovered in 2012, targeting then-recent 32-bit architecture of Windows NT, NT kernel versions of Microsoft Windows. The virus was notable due to the destructive nature ...
. Considered the biggest hack in history in terms of cost and destructiveness. Carried out by an Iranian attacker group called Cutting Sword of Justice. Iranian hackers retaliated against Stuxnet by releasing Shamoon. The malware destroyed over 35,000 Saudi Aramco computers, affecting business operations for months. *December 17: Computer hacker sl1nk announced that he has hacked a total of 9 countries'
SCADA SCADA (an acronym for supervisory control and data acquisition) is a control system architecture comprising computers, networked data communications and graphical user interfaces for high-level supervision of machines and processes. It also cove ...
systems. The proof includes 6 countries: France, Norway, Russia, Spain, Sweden and the United States.


2013

* The social networking website
Tumblr Tumblr (pronounced "tumbler") is a microblogging and Social networking service, social networking website founded by David Karp in 2007 and is owned by American company Automattic. The service allows users to post multimedia and other content ...
is attacked by hackers. Consequently, 65,469,298 unique emails and passwords were leaked from Tumblr. The data breach's legitimacy is confirmed by computer security researcher Troy Hunt. * August: Yahoo! data breaches occurred. More than 3 billion users data are being leaked.


2014

* February 7: The
bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
exchange Mt. Gox filed for bankruptcy after $460million was apparently stolen by hackers due to "weaknesses in
heir Inheritance is the practice of receiving private property, titles, debts, entitlements, privileges, rights, and obligations upon the death of an individual. The rules of inheritance differ among societies and have changed over time. Offi ...
system" and another $27.4million went missing from its bank accounts. * October: The White House computer system was hacked. It was said that the FBI, the Secret Service, and other U.S. intelligence agencies categorized the attacks "among the most sophisticated attacks ever launched against U.S. government systems." * November 24: In response to the release of the film ''
The Interview ''The Interview'' is a 2014 American political satire action comedy film produced and directed by Seth Rogen and Evan Goldberg in their second directorial work, following '' This Is the End'' (2013). The screenplay was written by Dan Sterling ...
'', the servers of
Sony Pictures Sony Pictures Entertainment Inc. is an American diversified multinational mass media and entertainment studio conglomerate that produces, acquires, and distributes filmed entertainment (theatrical motion pictures, television programs, and rec ...
are hacked by a hacker group calling itself "Guardian of Peace". * November 28: The website of the Philippine telecommunications company
Globe Telecom Globe Telecom, Inc., commonly shortened as Globe, is a major provider of telecommunications services in the Philippines. The company operates one of the largest mobile, fixed-line and broadband networks in the Philippines. As of November 2023, ...
was hacked in response to the poor internet service they were distributing.


2015

* June: the records of 21.5 million people, including social security numbers, dates of birth, addresses, fingerprints, and security clearance-related information, are stolen from the United States Office of Personnel Management (OPM). Most of the victims are employees of the United States government and unsuccessful applicants to it. ''
The Wall Street Journal ''The Wall Street Journal'' (''WSJ''), also referred to simply as the ''Journal,'' is an American newspaper based in New York City. The newspaper provides extensive coverage of news, especially business and finance. It operates on a subscriptio ...
'' and ''
The Washington Post ''The Washington Post'', locally known as ''The'' ''Post'' and, informally, ''WaPo'' or ''WP'', is an American daily newspaper published in Washington, D.C., the national capital. It is the most widely circulated newspaper in the Washington m ...
'' report that government sources believe the hacker is the government of China. *July: The servers of extramarital affairs website Ashley Madison were
breached Breached was a Canadians, Canadian rock band from Toronto, Ontario, active from 2010 to 2015. Its members were Bobby Noakes (vocals), Age of Days, Mike Diesel (guitar/vocals), Ryan Alexander (bass), and Dear Jane, I..., Neil Uppal (drums). Mike ...
.


2016

* February: The 2016 Bangladesh Bank heist attempted to steal US$951 million from a
Bangladesh Bank Bangladesh Bank (BB; ) is the central bank of Bangladesh and is a member of the Asian Clearing Union. It is fully owned by the Bangladesh, Government of Bangladesh. The bank is active in developing green banking. and financial inclusion poli ...
, and succeeded in getting $101 million—although some of this was later recovered. * July 22:
WikiLeaks WikiLeaks () is a non-profit media organisation and publisher of leaked documents. It is funded by donations and media partnerships. It has published classified documents and other media provided by anonymous sources. It was founded in 2006 by ...
published the documents from the
2016 Democratic National Committee email leak The 2016 Democratic National Committee email leak is a collection of Democratic National Committee (DNC) emails Democratic National Committee cyber attacks, stolen by one or more hackers operating under the pseudonym "Guccifer 2.0" who are allege ...
. * July 29: a group suspected coming from China launched hacker attacks on the website of Vietnam Airlines. * August 13: The Shadow Brokers (TSB) started publishing several leaks containing hacking tools from the
National Security Agency The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
(NSA), including several zero-day exploits. Ongoing leaks until April 2017 ( The Shadow Brokers) * September: Hacker Ardit Ferizi is sentenced to 20 years in prison after being arrested for hacking U.S. servers and passing the leaked information to members of
ISIL The Islamic State (IS), also known as the Islamic State of Iraq and the Levant (ISIL), the Islamic State of Iraq and Syria (ISIS) and Daesh, is a transnational Salafi jihadist organization and unrecognized quasi-state. IS occupied signif ...
terrorist group back in 2015. * October: The
2016 Dyn cyberattack On October 21, 2016, three consecutive distributed denial-of-service attacks were launched against the Domain Name System (DNS) provider Dyn. The attack caused major Internet platforms and services to be unavailable to large swathes of users in ...
is being conducted with a botnet consisting of IOTs infected with Mirai by the hacktivist groups SpainSquad, Anonymous, and New World Hackers, reportedly in retaliation for
Ecuador Ecuador, officially the Republic of Ecuador, is a country in northwestern South America, bordered by Colombia on the north, Peru on the east and south, and the Pacific Ocean on the west. It also includes the Galápagos Province which contain ...
's rescinding Internet access to
WikiLeaks WikiLeaks () is a non-profit media organisation and publisher of leaked documents. It is funded by donations and media partnerships. It has published classified documents and other media provided by anonymous sources. It was founded in 2006 by ...
founder
Julian Assange Julian Paul Assange ( ; Hawkins; born 3 July 1971) is an Australian editor, publisher, and activist who founded WikiLeaks in 2006. He came to international attention in 2010 after WikiLeaks published a series of News leak, leaks from Chels ...
at their embassy in London, where he has been granted asylum. *Late 2016: Hackers steal international personal user data from the company
Uber Uber Technologies, Inc. is an American multinational transportation company that provides Ridesharing company, ride-hailing services, courier services, food delivery, and freight transport. It is headquartered in San Francisco, California, a ...
, including phone numbers, email addresses, and names, of 57 million people and 600,000 driver's license numbers of drivers for the company. Uber's
GitHub GitHub () is a Proprietary software, proprietary developer platform that allows developers to create, store, manage, and share their code. It uses Git to provide distributed version control and GitHub itself provides access control, bug trackin ...
account was accessed through Amazon's cloud-based service. Uber paid the hackers $100,000 for assurances the data was destroyed. * December 2016: Yahoo! data breaches reported and affected more than 1 billion users. The data leakage includes user names, email addresses, telephone numbers, encrypted or unencrypted security questions and answers, dates of birth, and hashed passwords


2017

* April: A hacker group calling itself "The Dark Overlord" posted unreleased episodes of ''
Orange Is the New Black ''Orange Is the New Black'' (sometimes abbreviated to ''OITNB'') is an American comedy-drama television series created by Jenji Kohan for Netflix. The series is based on Piper Kerman's memoir '' Orange Is the New Black: My Year in a Women's Pr ...
'' TV series online after failing to extort the online entertainment company
Netflix Netflix is an American subscription video on-demand over-the-top streaming service. The service primarily distributes original and acquired films and television shows from various genres, and it is available internationally in multiple lang ...
. * May:
WannaCry ransomware attack The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the form ...
started on Friday, May 12, 2017, and has been described as unprecedented in scale, infecting more than 230,000 computers in over 150 countries. A version of the unreleased
Disney The Walt Disney Company, commonly referred to as simply Disney, is an American multinational mass media and entertainment industry, entertainment conglomerate (company), conglomerate headquartered at the Walt Disney Studios (Burbank), Walt Di ...
film '' Pirates of the Caribbean: Dead Men Tell No Tales'' is held for ransom, with the attackers threatening its release to the public unless a ransom is paid in Bitcoin. * May: 25,000 digital photos and ID scans relating to patients of the Grozio Chirurgija cosmetic surgery clinic in
Lithuania Lithuania, officially the Republic of Lithuania, is a country in the Baltic region of Europe. It is one of three Baltic states and lies on the eastern shore of the Baltic Sea, bordered by Latvia to the north, Belarus to the east and south, P ...
were obtained and published without consent by an unknown group demanding ransoms. Thousands of clients from more than 60 countries were affected. The breach brought attention to weaknesses in Lithuania's information security. *June: 2017 Petya cyberattack. *June: TRITON (TRISIS), a malware framework designed to reprogram Triconex
safety instrumented system In functional safety a safety instrumented system (SIS) is an engineered set of hardware and software controls which provides a protection layer that shuts down a chemical, nuclear, electrical, or mechanical system, or part of it, if a hazardous co ...
s (SIS) of
industrial control system An industrial control system (ICS) is an electronic control system and associated instrumentation used for industrial process control. Control systems can range in size from a few modular panel-mounted controllers to large interconnected and in ...
s (ICS), discovered in Saudi Arabian Petrochemical plant. *August: Hackers demand $7.5 million in
Bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
to stop pre-releasing
HBO Home Box Office (HBO) is an American pay television service, which is the flagship property of namesake parent-subsidiary Home Box Office, Inc., itself a unit owned by Warner Bros. Discovery. The overall Home Box Office business unit is based a ...
shows and scripts, including ''
Ballers ''Ballers'' is an American sports comedy-drama series created by Stephen Levinson that aired for five seasons on HBO from June 21, 2015, to October 13, 2019. It stars Dwayne Johnson as a retired NFL player who must navigate his new career as th ...
'', '' Room 104'' and ''
Game of Thrones ''Game of Thrones'' is an American Fantasy television, fantasy Drama (film and television), drama television series created by David Benioff and for HBO. It is an adaptation of ''A Song of Ice and Fire'', a series of high fantasy novels by ...
''. * May–July 2017: The Equifax breach. * September 2017: Deloitte breach. *December: Mecklenburg County, North Carolina computer systems were hacked. They did not pay the ransom.


2018

* March: Computer systems in the city of
Atlanta Atlanta ( ) is the List of capitals in the United States, capital and List of municipalities in Georgia (U.S. state), most populous city in the U.S. state of Georgia (U.S. state), Georgia. It is the county seat, seat of Fulton County, Georg ...
, in the U.S. state of Georgia, are seized by hackers with
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
. They did not pay the ransom, and two Iranians were indicted by the
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
on cyber crime charges for the breach. * The town of
Wasaga Beach Wasaga Beach (or simply Wasaga) is a town in Simcoe County, Ontario, Canada. Situated along the longest freshwater beach in the world, it is a popular summer tourist destination. It is located along the southern end of Georgian Bay, approximatel ...
in Ontario, Canada computer systems are seized by hackers with ransomware. *September:
Facebook Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
was hacked, exposing to hackers the personal information of an estimated 30 million Facebook users (initially estimated at 50 million) when the hackers "stole" the "access tokens" of 400,000 Facebook users. The information accessible to the hackers included users' email addresses, phone numbers, their lists of friends, Groups they are members of, users' search information, posts on their timelines, and names of recent Messenger conversations."Facebook Was Hacked. 3 Things You Should Do After the Breach. The social networking giant said attackers had exploited a weakness that enabled them to hijack the accounts of nearly 50 million users. Here are some tips for securing your account,"
September 28, 2018,
New York Times ''The New York Times'' (''NYT'') is an American daily newspaper based in New York City. ''The New York Times'' covers domestic, national, and international news, and publishes opinion pieces, investigative reports, and reviews. As one of ...
, retrieved April 15, 2021
"Facebook says hackers accessed phone numbers, email addresses as part of latest breach,"
October 12, 2018,
Fox News The Fox News Channel (FNC), commonly known as Fox News, is an American Multinational corporation, multinational Conservatism in the United States, conservative List of news television channels, news and political commentary Television stati ...
, retrieved April 15, 2021
*October: West Haven, Connecticut USA computer systems are seized by hackers with ransomware, they paid $2,000 in ransom. *November: **The first U.S. indictment of individual people for
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
attacks occurs. The
U.S. Justice Department The United States Department of Justice (DOJ), also known as the Justice Department, is a United States federal executive departments, federal executive department of the U.S. government that oversees the domestic enforcement of Law of the Unite ...
indicted two men Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri who allegedly used the SamSam ransomware for extortion, netting them more than $6 million in ransom payments. The companies infected with the
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
included
Allscripts Veradigm Inc. (formerly Allscripts Healthcare Solutions, Inc.) is a publicly traded American company that provides physician practices, hospitals, and other healthcare providers with practice management and electronic health record (EHR) tech ...
,
Medstar Health MedStar Health is a not-for-profit healthcare organization. It operates more than 120 entities, including ten hospitals in the Baltimore–Washington metropolitan area of the United States. In 2011 it was ranked as the private sector employer ...
, and
Hollywood Presbyterian Medical Center CHA Hollywood Presbyterian Medical Center, formerly known as Queen of Angels – Hollywood Presbyterian Medical Center, is a private hospital located at 1300 North Vermont Avenue in Los Angeles, California. The hospital has 434 beds and is owned b ...
. Altogether, the attacks caused victims to lose more than $30 million, in addition to the ransom payments. **Marriott disclosed that its Starwood Hotel brand had been subject to a security breach.


2019

*March: Jackson County computer systems in the U.S. state of Georgia are seized by hackers with
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
, they paid $400,000 in ransom. The city of Albany in the U.S. state of New York experiences a ransomware cyber attack. *April: Computer systems in the city of Augusta, in the U.S. state of Maine, are seized by hackers using ransomware. The City of Greenville (North Carolina)'s computer systems are seized by hackers using ransomware known as RobbinHood.
Imperial County Imperial County is a county located on the southeast border of the U.S. state of California. As of the 2020 census, the population was 179,702, ranking as the least populous county in Southern California. The county seat and largest city is ...
, in the U.S. state of California, computer systems are seized by hackers using Ryuk ransomware. * May: computer systems belonging to the City of Baltimore are seized by hackers using ransomware known as RobbinHood that encrypts files with a "file-locking" virus, as well as the tool EternalBlue. *June: The city of
Riviera Beach, Florida Riviera Beach is a city in Palm Beach County, Florida, United States, which was incorporated on September 29, 1922. Due to the location of its eastern boundary, it is also the easternmost municipality in the Miami metropolitan area. In the 2020 ...
, paid roughly $600,000 ransom in
Bitcoin Bitcoin (abbreviation: BTC; Currency symbol, sign: ₿) is the first Decentralized application, decentralized cryptocurrency. Based on a free-market ideology, bitcoin was invented in 2008 when an unknown entity published a white paper under ...
to hackers who seized their computers using ransomware. Hackers stole 18 hours of unreleased music from the band
Radiohead Radiohead are an English rock band formed in Abingdon-on-Thames, Abingdon, Oxfordshire, in 1985. The band members are Thom Yorke (vocals, guitar, piano, keyboards); brothers Jonny Greenwood (guitar, keyboards, other instruments) and Colin Gre ...
demanding $150,000 ransom. Radiohead released the music to the public anyway and did not pay the ransom. *November: The
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
hacktivist collective announced that they have hacked into four Chinese computer databases and donated those to data breach indexing/notification service vigilante.pw. The hack was conducted in order to support the
2019 Hong Kong protests Nineteen or 19 may refer to: * 19 (number) * One of the years 19 BC, AD 19, 1919, 2019 Films * ''19'' (film), a 2001 Japanese film * ''Nineteen'' (1987 film), a 1987 science fiction film * '' 19-Nineteen'', a 2009 South Korean film * '' D ...
, amidst the Hong Kong police's siege of the city's Polytechnic University. They also brought up a possible peace plan first proposed by a professor at
Inha University Inha University () is a private research university located in Incheon, South Korea. Known traditionally for research and education in the engineering and physical sciences, the university was established by the first president of South Korea, S ...
in hopes of having the
Korean reunification Korean reunification is the hypothetical unification of North Korea and South Korea into a singular Korean sovereign state. The process towards reunification of the peninsula while still maintaining two opposing regimes was started by the Ju ...
and the five key demands of the Hong Kong protest being fulfilled at once.


2020s


2020

* May: Anonymous declared a large hack on May 28, three days after the
murder of George Floyd On May 25, 2020, George Floyd, a 46-year-old Black American man, was murdered in Minneapolis by Derek Chauvin, a 44-year-old White police officer. Floyd had been arrested after a store clerk reported that he made a purchase using a c ...
. An individual claiming to represent Anonymous stated that "We are Legion. We do not forgive. We do not forget. Expect us." in a now-deleted video. Anonymous addressed police brutality and said they "will be exposing
heir Inheritance is the practice of receiving private property, titles, debts, entitlements, privileges, rights, and obligations upon the death of an individual. The rules of inheritance differ among societies and have changed over time. Offi ...
many crimes to the world". It was suspected that Anonymous were the cause for the downtime and public suspension of the
Minneapolis Police Department The Minneapolis Police Department (MPD) is the primary law enforcement agency in Minneapolis, Minnesota, United States. It is also the largest police department in Minnesota. Formed in 1867, it is the second-oldest police department in Minnesota ...
website and its parent site, the website of the City of Minneapolis. * May: Indian national Shubham Upadhyay posed as Superintendent of Police and, using social engineering, used a free caller identification app to call up the in-charge of the Kotwali police station, K. K. Gupta, in order to threaten him to get his phone repaired amidst the
COVID-19 lockdown During the early stages of the COVID-19 pandemic, a number of non-pharmaceutical interventions, particularly lockdowns (encompassing stay-at-home orders, curfews, quarantines, and similar societal restrictions), were implemented in numero ...
. The attempt was foiled. * June: Anonymous claimed responsibility for stealing and leaking a trove of documents collectively nicknamed '
BlueLeaks BlueLeaks, sometimes referred to by the Twitter hashtag #BlueLeaks, refers to 269.21 gibibytes of internal U.S. law enforcement data obtained by the hacker collective Anonymous and released on June 19, 2020, by the activist group Distrib ...
'. The 269-gigabyte collection was published by a leak-focused activist group known as
Distributed Denial of Secrets Distributed Denial of Secrets, abbreviated DDoSecrets, is a nonprofit whistleblower site founded in 2018 for news leaks. The site is a frequent source for other news outlets and has worked on investigations including Cyprus Confidential with o ...
. Furthermore, the collective took down
Atlanta Police Department The Atlanta Police Department (APD) is a law enforcement agency in the city of Atlanta, Georgia (U.S. state), Georgia, United States. The city shifted from its rural-based Marshal and Deputy Marshal model at the end of the 19th century. In 1873, ...
's website via
DDoS In computing, a denial-of-service attack (DoS attack) is a cyberattack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host co ...
, and defaced websites such as a Filipino governmental webpage and that of Brookhaven National Labs. They expressed support for
Julian Assange Julian Paul Assange ( ; Hawkins; born 3 July 1971) is an Australian editor, publisher, and activist who founded WikiLeaks in 2006. He came to international attention in 2010 after WikiLeaks published a series of News leak, leaks from Chels ...
and press freedom, while briefly "taking a swing" against
Facebook Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
,
Reddit Reddit ( ) is an American Proprietary software, proprietary social news news aggregator, aggregation and Internet forum, forum Social media, social media platform. Registered users (commonly referred to as "redditors") submit content to the ...
and
Wikipedia Wikipedia is a free content, free Online content, online encyclopedia that is written and maintained by a community of volunteers, known as Wikipedians, through open collaboration and the wiki software MediaWiki. Founded by Jimmy Wales and La ...
for having 'engaged in shady practices behind our prying eyes'. In the case of Reddit, they posted a link to a court document describing the possible involvement of a moderator of a large traffic subreddit (/r/news) in an online harassment-related case. * June: The
Buffalo, NY Buffalo is a city in the U.S. state of New York and county seat of Erie County. It lies in Western New York at the eastern end of Lake Erie, at the head of the Niagara River on the Canadian border. With a population of 278,349 according to ...
police department's website was supposedly hacked by Anonymous. While the website was up and running after a few minutes, Anonymous tweeted again on Twitter urging that it be taken down. A few minutes later, the Buffalo NY website was brought down again. They also hacked
Chicago Chicago is the List of municipalities in Illinois, most populous city in the U.S. state of Illinois and in the Midwestern United States. With a population of 2,746,388, as of the 2020 United States census, 2020 census, it is the List of Unite ...
police radios to play
N.W.A N.W.A (an abbreviation for Niggaz Wit Attitudes) was an American hip-hop group formed in Compton, California in 1987. Among the earliest and most significant figures of the gangsta rap subgenre, the group is widely considered one of the great ...
's "
Fuck tha Police "Fuck tha Police" is a protest song by American hip hop group N.W.A that appears on the 1989 album ''Straight Outta Compton'' as well as on the ''N.W.A's Greatest Hits'' compilation. The lyrics protest police brutality and racial profiling ...
". * June: Over 1,000 accounts on multiplayer online game
Roblox Roblox (, ) is an online game platform and game creation system developed by Roblox Corporation that allows users to program and play games created by themselves or other users. It was created by David Baszucki and Erik Cassel in 200 ...
were hacked to display that they supported U.S. President
Donald Trump Donald John Trump (born June 14, 1946) is an American politician, media personality, and businessman who is the 47th president of the United States. A member of the Republican Party (United States), Republican Party, he served as the 45 ...
. * July: The 2020 Twitter bitcoin scam occurred. * July: User credentials of writing website
Wattpad Wattpad is a website for reading and publishing originally written fiction and connecting with fellow writers and readers. Its most popular genres are romance, teen fiction, and fan fiction. As of November 2021, Wattpad had more than 90 mill ...
were stolen and leaked on a hacker forum. The database contained over 200 million records. * August: Indian hackers hacked
Pakistani Pakistanis (, ) are the citizens and nationals of the Islamic Republic of Pakistan. Pakistan is the fifth-most populous country, with a population of over 241.5 million, having the second-largest Muslim population as of 2023. As much as ...
television channel '
Dawn News Dawn News HD is a Pakistani 24-hour Urdu news channel. Based in Karachi, the station is a subsidiary of Pakistan Herald Publications Limited (PHPL), Pakistan's largest English-language media group. The test transmission of the station occurr ...
' and displayed India's national flag with the message “Happy Independence Day” (referring to 15 August, Independence Day of India) written on it, at around 3:30 pm IST. Dawn News issued a statement saying they are investigating the matter. * August: A large number of
subreddits Reddit ( ) is an American Proprietary software, proprietary social news news aggregator, aggregation and Internet forum, forum Social media, social media platform. Registered users (commonly referred to as "redditors") submit content to the ...
were hacked to post materials endorsing
Donald Trump Donald John Trump (born June 14, 1946) is an American politician, media personality, and businessman who is the 47th president of the United States. A member of the Republican Party (United States), Republican Party, he served as the 45 ...
. The affected subreddits included r/BlackPeopleTwitter, r/3amJokes, r/NFL, r/PhotoshopBattles. An entity with the name of "calvin goh and Melvern" had purportedly claimed responsibility for the massive defacement, and also made violent threats against a Chinese embassy. * August: The US Air Force's Hack-A-Sat event was hosted at DEF CON's virtual conference where groups such as Poland Can Into Space, FluxRepeatRocket, AddVulcan, Samurai, Solar Wine, PFS, 15 Fitty Tree, and 1064CBread competed in order to control a satellite in space. The Poland Can Into Space team stood out for having successfully manipulated a satellite to take a picture of the
Moon The Moon is Earth's only natural satellite. It Orbit of the Moon, orbits around Earth at Lunar distance, an average distance of (; about 30 times Earth diameter, Earth's diameter). The Moon rotation, rotates, with a rotation period (lunar ...
. * August: The website of Belarusian company "BrestTorgTeknika" was defaced by a hacker nicknaming herself " Queen Elsa", in order to support the 2020–21 Belarusian protests. In it, the page hacker exclaimed "Get Iced Iced already" and "Free Belarus, revolution of our times" with the latter alluding to the famous slogan used by
2019 Hong Kong protests Nineteen or 19 may refer to: * 19 (number) * One of the years 19 BC, AD 19, 1919, 2019 Films * ''19'' (film), a 2001 Japanese film * ''Nineteen'' (1987 film), a 1987 science fiction film * '' 19-Nineteen'', a 2009 South Korean film * '' D ...
. The results of the hack were then announced on Reddit's /r/Belarus subreddit by a poster under the username "Socookre". * August: Multiple DDoS attacks forced
New Zealand New Zealand () is an island country in the southwestern Pacific Ocean. It consists of two main landmasses—the North Island () and the South Island ()—and List of islands of New Zealand, over 600 smaller islands. It is the List of isla ...
's stock market to temporarily shut down. * September: The first suspected death from a cyberattack was reported after cybercriminals hit a hospital in
Düsseldorf Düsseldorf is the capital city of North Rhine-Westphalia, the most populous state of Germany. It is the second-largest city in the state after Cologne and the List of cities in Germany with more than 100,000 inhabitants, seventh-largest city ...
,
Germany Germany, officially the Federal Republic of Germany, is a country in Central Europe. It lies between the Baltic Sea and the North Sea to the north and the Alps to the south. Its sixteen States of Germany, constituent states have a total popu ...
, with
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
. * October: A wave of
botnet A botnet is a group of Internet-connected devices, each of which runs one or more Internet bot, bots. Botnets can be used to perform distributed denial-of-service attack, distributed denial-of-service (DDoS) attacks, steal data, send Spamming, sp ...
-coordinated
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
attacks against hospital infrastructure occurred in the United States, identified as . State security officials and American corporate security officers were concerned that these attacks might be a prelude to hacking of election infrastructure during the elections of the subsequent month, like similar incidents during the
2016 United States elections Elections in the United States, Elections were held in the United States on November 8, 2016. Republican Party (United States), Republican nominee Donald Trump defeated Democratic Party (United States), Democratic former Secretary of State (Uni ...
and other attacks; there was, however, no evidence that they performed attacks on election infrastructure in 2020. * December: A
supply chain attack A supply chain attack is a cyber-attack that seeks to damage an organization by targeting less secure elements in the supply chain. A supply chain attack can occur in any industry, from the financial sector, oil industry, to a government sector. ...
targeting upstream dependencies from Texas IT service provider "SolarWinds" results in serious, wide-ranging security breaches at the
U.S. Treasury The Department of the Treasury (USDT) is the Treasury, national treasury and finance department of the federal government of the United States. It is one of 15 current United States federal executive departments, U.S. government departments. ...
and
Commerce Commerce is the organized Complex system, system of activities, functions, procedures and institutions that directly or indirectly contribute to the smooth, unhindered large-scale exchange (distribution through Financial transaction, transactiona ...
departments. White House officials did not immediately publicly identify a culprit;
Reuters Reuters ( ) is a news agency owned by Thomson Reuters. It employs around 2,500 journalists and 600 photojournalists in about 200 locations worldwide writing in 16 languages. Reuters is one of the largest news agencies in the world. The agency ...
, citing sources "familiar with the investigation", pointed toward the Russian government. An official statement shared by Senate Finance Committee ranking member,
Ron Wyden Ronald Lee Wyden ( ; born May 3, 1949) is an American politician serving as the Seniority in the United States Senate, senior United States Senate, United States senator from Oregon, a seat he has held since 1996 United States Senate special el ...
said: "Hackers broke into systems in the Departmental Offices division of Treasury, home to the department’s highest-ranking officials." * December: A bomb threat posted from a
Twitter Twitter, officially known as X since 2023, is an American microblogging and social networking service. It is one of the world's largest social media platforms and one of the most-visited websites. Users can share short text messages, image ...
account that was seemingly hacked by persons with the aliases of "Omnipotent" and "choonkeat", against the
Aeroflot PJSC AeroflotRussian Airlines (, ), commonly known as Aeroflot ( or ; , , ), is the flag carrier and the largest airline of Russia. Aeroflot is headquartered in the Central Administrative Okrug, Moscow, with its hub being Sheremetyevo Interna ...
Flight 102, a passenger flight with the plane tail number of VQ-BIL coming from
Moscow Moscow is the Capital city, capital and List of cities and towns in Russia by population, largest city of Russia, standing on the Moskva (river), Moskva River in Central Russia. It has a population estimated at over 13 million residents with ...
to
New York City New York, often called New York City (NYC), is the most populous city in the United States, located at the southern tip of New York State on one of the world's largest natural harbors. The city comprises five boroughs, each coextensive w ...
. Due to that, a runway of New York's
John F. Kennedy International Airport John F. Kennedy International Airport is a major international airport serving New York City and its metropolitan area. JFK Airport is located on the southwestern shore of Long Island, in Queens, New York City, bordering Jamaica Bay. It is ...
was temporarily closed and resulted in the delay of Aeroflot Flight 103, a return flight back to Moscow. * December: The
Anonymous Anonymous may refer to: * Anonymity, the state of an individual's identity, or personally identifiable information, being publicly unknown ** Anonymous work, a work of art or literature that has an unnamed or unknown creator or author * Anonym ...
group initiated 'Christmas gift' defacements against multiple Russian portals including a municipal website in
Tomsk Tomsk (, ) is a types of inhabited localities in Russia, city and the administrative center of Tomsk Oblast in Russia, on the Tom (river), Tom River. Population: Founded in 1604, Tomsk is one of the oldest cities in Siberia. It has six univers ...
and that of a regional football club. Inside the defacements, they made multiple references such as Russian opposition activist
Alexei Navalny Alexei Anatolyevich Navalny (, ; 4 June 197616 February 2024) was a Russian Opposition to Vladimir Putin in Russia, opposition leader, anti-corruption in Russia, corruption activist and political prisoner. He founded the Anti-Corruption Found ...
, freedom protests in
Thailand Thailand, officially the Kingdom of Thailand and historically known as Siam (the official name until 1939), is a country in Southeast Asia on the Mainland Southeast Asia, Indochinese Peninsula. With a population of almost 66 million, it spa ...
and
Belarus Belarus, officially the Republic of Belarus, is a landlocked country in Eastern Europe. It is bordered by Russia to the east and northeast, Ukraine to the south, Poland to the west, and Lithuania and Latvia to the northwest. Belarus spans an a ...
, and opposition to the
Chinese Communist Party The Communist Party of China (CPC), also translated into English as Chinese Communist Party (CCP), is the founding and One-party state, sole ruling party of the People's Republic of China (PRC). Founded in 1921, the CCP emerged victorious in the ...
. They also held a mock award based on an event on the game platform
Roblox Roblox (, ) is an online game platform and game creation system developed by Roblox Corporation that allows users to program and play games created by themselves or other users. It was created by David Baszucki and Erik Cassel in 200 ...
that was called "RB Battles" where YouTubers Tanqr and KreekCraft, the winner and the runner up of the actual game event, were compared to both Taiwan and
New Zealand New Zealand () is an island country in the southwestern Pacific Ocean. It consists of two main landmasses—the North Island () and the South Island ()—and List of islands of New Zealand, over 600 smaller islands. It is the List of isla ...
respectively due to the latter's reportedly stellar performance in fighting the
COVID-19 pandemic The COVID-19 pandemic (also known as the coronavirus pandemic and COVID pandemic), caused by severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2), began with an disease outbreak, outbreak of COVID-19 in Wuhan, China, in December ...
.


2021

* January: Microsoft Exchange Server data breach * February: Anonymous announced cyber-attacks of at least five
Malaysia Malaysia is a country in Southeast Asia. Featuring the Tanjung Piai, southernmost point of continental Eurasia, it is a federation, federal constitutional monarchy consisting of States and federal territories of Malaysia, 13 states and thre ...
n websites. As a result, eleven individuals were nabbed as suspects. * February: The group "Myanmar Hackers" attacked several websites belonging to
Myanmar Myanmar, officially the Republic of the Union of Myanmar; and also referred to as Burma (the official English name until 1989), is a country in northwest Southeast Asia. It is the largest country by area in Mainland Southeast Asia and has ...
government agencies such as the Central Bank of Myanmar and the military-run ''
Tatmadaw The Tatmadaw, also known as the Sit-Tat, is the armed forces of Myanmar (formerly Burma). It is administered by the Ministry of Defence and composed of the Myanmar Army, the Myanmar Navy and the Myanmar Air Force. Auxiliary services include ...
True News Information Team''. The group also targeted the Directorate of Investment and Company Administration, Trade Department, Customs Department, Ministry of Commerce, Myawady TV and state-owned broadcaster Myanmar Radio and Television and some private media outlets. A computer technician in Yangon found that the hacks were denial-of-service attacks, while the group's motive is to protest the 2021 Myanmar coup. *March: Cyber insurer
CNA Financial CNA Financial Corporation is a financial corporation based in Chicago, Illinois, United States. Its principal subsidiary, Continental Casualty Company (CCC), was founded in 1897, and The Continental Insurance Company (CIC) was organized in 1853. ...
, one of the largest insurance companies based in the US, was attacked with ransomware, causing the company to lose control over its network. The company paid $40 million to regain network control. CNA had, at first, ignored the hackers, attempting to solve the problem independently; remaining locked out, however, CNA paid the ransom within a week. CNA's investigation reported that
cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
group Phoenix had used Phoenix Locker malware, a variant of the Hades ransomware used by Russian criminal hacking group Evil Corp. Phoenix Locker malware encrypted 15,000 devices on the network, as well as the computers of employees working remotely while logged into the company's VPN during the attack. * April: Over 500 million
Facebook Facebook is a social media and social networking service owned by the American technology conglomerate Meta Platforms, Meta. Created in 2004 by Mark Zuckerberg with four other Harvard College students and roommates, Eduardo Saverin, Andre ...
users' personal info—including info on 32 million in the United States—was discovered posted on a hackers' website, though Facebook claimed that the information was from a 2019 hack, and that the company had already taken mitigation measures; however, the company declined to say whether it had notified the affected users of the breach."Cybersecurity: Millions of Facebook accounts hacked,"
April 5, 2021,
KTNV-TV KTNV-TV (channel 13) is a television station in Las Vegas, Nevada, United States, affiliated with ABC. It is owned by the E. W. Scripps Company alongside Laughlin-licensed independent station KMCC (channel 34). The two stations share studi ...
,
Las Vegas, Nevada Las Vegas, colloquially referred to as Vegas, is the most populous city in the U.S. state of Nevada and the county seat of Clark County. The Las Vegas Valley metropolitan area is the largest within the greater Mojave Desert, and second-l ...
, retrieved April 15, 2021
"Facebook hack How to find out if you were one of the 533 million Facebook users hacked,"
Fox5 TV,
San Diego, California San Diego ( , ) is a city on the Pacific coast of Southern California, adjacent to the Mexico–United States border. With a population of over 1.4 million, it is the List of United States cities by population, eighth-most populous city in t ...
, retrieved April 15, 2021
"2021-04-13 Facebook data breach explained: How the world’s largest social media platform got hacked,"
April 13, 2021, ''
Times of India ''The Times of India'' (''TOI'') is an Indian English-language daily newspaper and digital news media owned and managed by the Times Group. It is the List of newspapers in India by circulation, third-largest newspaper in India by circulation an ...
,'' retrieved April 15, 2021
* April: The Ivanti Pulse Connect Secure data breach of unauthorized access to the networks of high-value targets since at least June 2020 via across the U.S. and some E.U. nations due to their use of vulnerable,
proprietary {{Short pages monitor