The 2000s: Love Bug, Estonia & the Card Heists (2000–2008)
← Back to the full list · Previous: Part 1 — The Early Era
The World in 2000
Between 2000 and 2008, the Internet stopped being a research curiosity and became the world’s nervous system. Dial-up gave way to broadband; webmail, online banking, and e-commerce exploded; Windows PCs landed in a majority of homes in the developed world. And in a twist that would define the decade, this enormous new economy ran on a fragile monoculture: Windows, Outlook, and Internet Explorer everywhere — largely unpatched, rarely firewalled, with antivirus that could only recognize yesterday’s threats.
Three forces emerged in this decade that still run the show today: social-engineering malware at internet scale (email worms), state-sponsored espionage against Western industry and government (the campaigns that would be named APTs), and organized financial cybercrime (professional carding rings). The decade also hosted the first full-scale cyber campaign against an entire nation — and the birth of modern data-breach law.
3. The ILOVEYOU Worm / Love Bug (2000) — Ten Percent of the World’s Computers
| Attacker | Onel de Guzman, a computer-science dropout from Manila, Philippines |
| Target | Windows PCs running Outlook email |
| Method | Email worm disguised as a love letter (VBScript attachment); self-mailing via address books |
| Damage | Tens of millions of machines — by some counts ~10% of internet-connected computers |
| Cost | Estimated $5.5–15 billion; among the costliest malware outbreaks ever |
How the attack unfolded
At the dawn of May 4, 2000, emails began landing across Asia and Europe with a subject line no flirt-deprived office worker could resist: “ILOVEYOU.” The body read: “kindly check the attached LOVELETTER coming from me.” The attachment — LOVE-LETTER-FOR-YOU.TXT.vbs — looked like a harmless text file because Windows, by default, hid the real file extension. It was not a text file. It was a Visual Basic script, and double-clicking it handed the machine to the most rapidly spreading piece of malware the world had yet seen.
Its author was 23/24-year-old Onel de Guzman, a struggling computer-science student in Manila. In an almost poetic detail, his rejected undergraduate thesis proposal had described a program that steals internet passwords so users could get online for free — a scheme his school deemed illegal. Months later, a devastatingly more capable version of that idea went global.
Once opened, the worm executed a brutal sequence:
- Copied itself across the system and into startup locations, so it ran on every boot.
- Mailed itself to every contact in the victim’s Outlook address book — including, in many corporate settings, distribution lists containing thousands of recipients. This single design choice was the engine of the outbreak: each infection spawned hundreds of new emails within minutes.
- Overwrote files — documents, scripts, and images (it hid MP3s and JPEGs rather than destroying them immediately, a quirk of the code) — destroying data with no possibility of recovery.
- Stole passwords — it downloaded a trojan (from a Philippine web host) that harvested dial-up credentials and Windows-cached passwords and mailed them back to the author.
- Spread further through IRC channels and shared network drives.
Within hours, the worm had circled the planet. Corporate mail servers collapsed under their own outgoing traffic. The UK Parliament shut its email network; Ford Motor Company took its email offline; Microsoft, the Pentagon, and Denmark’s parliament were all hit. The majority of damage occurred within the first 24 hours — a speed that made human incident response impossible. Estimates eventually put the toll at tens of millions of infected machines in dozens of countries, with damages from $5.5 billion to as high as $15 billion — for years afterward cited as the costliest virus outbreak in history.
The damage
The Love Bug was the first mass demonstration of several ideas now central to security:
- Human curiosity is a remote-code-execution vector. No exploit of Windows was needed — just a message people wanted to open. Modern phishing is ILOVEYOU’s direct descendant.
- Monoculture is fuel. The worm’s dependence on Outlook worked only because one email client dominated the world; the same equation would repeat with Windows worms and later with Android/IoT.
- Signature antivirus is always behind. The industry issued fixes within hours, but the worm had already circled the earth; signature scanning was structurally a step too slow.
Aftermath & lessons
The most consequential fact about the Love Bug is what didn’t happen to its author. Philippine investigators traced the worm to de Guzman’s apartment and arrested him — but were forced to release him within months because Philippine law, incredibly, contained no statute criminalizing the release of malware. The scandal embarrassed the government into passing the E-Commerce Act (RA 8792) in June 2000, which criminalized hacking and virus release.
Globally, the worm accelerated: default extension-viewing changes, attachment blocking in mail gateways, the rise of gateway content filtering, and the first serious corporate email-attachment policies. The Love Bug remains the reference point every subsequent “don’t click that” policy is measured against — and de Guzman’s near-anonymity today (he reportedly shunned publicity and never faced justice) is a standing reminder that in the early days, crime paid.
4. Titan Rain (2003–2008) — China’s Silent Campaign Against the US Military
| Attacker | China-based hackers, widely linked to state sponsorship (later reporting associated them with PLA-linked units) |
| Targets | Lockheed Martin, Sandia National Laboratories, Redstone Arsenal, NASA, and other US defense/government networks |
| Method | Automated vulnerability scanning, known exploits, web shells, rapid smash-and-grab exfiltration |
| Damage | Years of stolen sensitive military and technology data; never fully quantified |
| Cost | Classified; indirectly drove billions in subsequent US cyber-defense spending |
How the attack unfolded
In 2003–2004, US defense contractors and military labs began noticing something unnerving: analysts would watch intruders sweep their networks in bursts of activity that started predictably — weekdays, on Chinese working hours — probing every server for known, unpatched vulnerabilities. When one opened, the attackers were inside within minutes: a web shell here, a compressed archive there, gigabytes of data moving out, then silence. Then they came back for more, through the same holes, weeks later. The FBI gave the campaign a codename that leaked into public legend: Titan Rain.
The intruders’ tradecraft was initially unglamorous — no zero-days, mostly public exploits against unpatched Windows and IIS systems — but their discipline, scale, and persistence were new. They hopped through compromised machines in South Korea, Taiwan, and elsewhere to obscure their origin, and evidence pointed to China’s Guangdong province. Time magazine broke the story in 2005, and US officials began quietly briefing allies; by 2007, German and UK intelligence were publicly warning about similar PLA-linked intrusions into their own government systems.
The scope was extraordinary for its time: among the named victims were Lockheed Martin (the Pentagon’s largest supplier), Sandia National Laboratories (nuclear weapons research), Redstone Arsenal (Army missile commands), and NASA. What was taken has never been fully disclosed — but it sat at the intersection of US military technology and Chinese strategic interest.
The campaign’s most famous subplot belonged to Shawn Carpenter, a security analyst working for Sandia. Tracking intrusions on his own initiative — and on his own time, using his own resources — Carpenter followed the attackers across intermediate servers all the way back to China. When his unauthorized investigation surfaced, Sandia fired him for exceeding his authorization. Public opinion sided overwhelmingly with the analyst; a jury later vindicated him in a wrongful-termination suit and awarded him millions in damages. “Carpenter v. Sandia” became a morality tale about organizational security culture: punish the messenger, and the intruders keep the message.
The damage
Titan Rain’s significance was strategic rather than a single number. It marked the moment the US defense establishment internalized that a peer adversary was systematically inside its supply chain, harvesting not money but design data, research, and strategic insight. It normalized a condition the industry would eventually accept as permanent: sophisticated adversaries don’t break in once; they live there.
Aftermath & lessons
- The campaign catalyzed the term “Advanced Persistent Threat” (APT) — coined within the US Air Force in 2006 largely to describe exactly this pattern: advanced techniques, persistent presence, threat actors with state backing.
- It began two decades of Western attributions and, eventually, indictments against Chinese military units — culminating in the 2014 US indictment of five PLA officers and 2020’s indictment of four PLA officers for Equifax (covered in Part 4 of this series).
- It forced defense contractors to build insider-grade monitoring of their own networks, decades before commercial firms took the same lesson.
The core lesson: Titan Rain established the operating model of every state hack since — patient, quiet, repeated, and aimed at information rather than destruction. The APT era began here.
5. The Estonia Cyberattacks (2007) — The First War Fought Against a Country’s Internet
| Attacker | Russian state-linked actors and “patriotic” hacker groups (never formally proven) |
| Target | The nation of Estonia — banks, ministries, media, ISPs |
| Method | Massive coordinated DDoS: botnets, ping floods, HTTP floods, defacements |
| Damage | Weeks of disruption to the online services of the world’s most digital society |
| Cost | Direct losses comparatively modest; strategic consequences enormous |
How the attack unfolded
By 2007, Estonia was arguably the most digitally advanced society on Earth: internet banking used by 97–98% of the population, government services online, cabinet meetings paperless. That made it uniquely vulnerable to what began on the night of April 27, 2007, after the government relocated a Soviet-era war memorial — the Bronze Soldier of Tallinn — from the city center to a military cemetery. To Estonia’s ethnic-Russian minority it was an insult; to Russian nationalists and the Kremlin-aligned media, a casus belli. Rioting followed in the capital, along with a diplomatic siege — and then came the digital one.
Over three weeks, Estonia absorbed wave after wave of distributed denial-of-service attacks coordinated with almost military timing: they intensified on Estonian holidays and Russian commemorative dates, peaked around May 8–9 (the Russian victory over Nazi Germany), and targeted the country’s connective tissue — the websites of the presidency, parliament, and ministries; the Hansabank banking group (the Baltic’s largest); newspapers; and ISPs themselves. At times attack traffic, sourced from botnets rented around the world and from coordinated volunteer “patriotic hackers,” equaled many times Estonia’s total international bandwidth. Bank websites flickered for days; online services slowed for weeks.
Estonian officials, including ministers, publicly accused Russia of state involvement, noting some attack traffic had originated from Russian government IP addresses, including systems tied to the presidential administration. Russia denied everything, no smoking gun of state command ever emerged, and the most convincing reconstruction blends the two theories: state-tolerated or state-encouraged nationalist hackers, amplified by rented criminal botnets — a deniable hybrid of the kind that would become Russia’s signature. The only convictions were small: an ethnic-Russian Estonian student was convicted and fined in 2008 for participating in a portion of the attacks; other participants sat beyond Estonian jurisdiction in Russia, untouchable.
The damage
Measured in dollars, Estonia got off lightly — services were degraded, not destroyed. Measured in history, it was a watershed: the first time an entire nation’s digital infrastructure was targeted as such, and the first time a country formally invoked NATO’s collective-defense consultations over a cyber campaign. NATO dispatched technical experts to Tallinn and absorbed an uncomfortable lesson: Article 5 obligations were written for tanks, not traffic floods.
Aftermath & lessons
- NATO’s cyber awakening. The attacks led directly to the establishment of the NATO Cooperative Cyber Defence Centre of Excellence in Tallinn (2008) — Estonia’s humiliation became its crown. The Centre later produced the Tallinn Manual on how international law applies to cyber operations.
- Cyberspace as a warfighting domain. In 2014, NATO formally recognized cyberspace as a domain of operations alongside land, sea, and air — a doctrinal shift with a straight line back to April 2007.
- Estonia rebuilt into a cyber power. The country invested aggressively in resilience, backup registries, and the “data embassies” concept, becoming the model for digital-state defense.
- The hybrid-war template. Estonia previewed how cyber operations pair with information operations and deniability — a template refined against Georgia (2008) and Ukraine (ever since).
The core lesson: when a society runs on the internet, the internet is national infrastructure. Estonia’s response — resilience, allies, doctrine — is the playbook every digital nation has since copied.
6. The TJX Breach (2005–2007) — The Biggest Card Heist of Its Era
| Attacker | Carding ring led by Albert Gonzalez — a former paid Secret Service informant |
| Target | TJX Companies (TJ Maxx, Marshalls, and other retail chains) |
| Method | Wardriving: cracking weak WEP Wi-Fi from store parking lots, then network intrusion and sniffing |
| Damage | Up to 94 million payment cards by banking estimates |
| Cost | Hundreds of millions in fraud, settlements, and remediation; 20-year prison sentence for the ringleader |
How the attack unfolded
In the mid-2000s, retail networks were held together with wireless tape: stores connected registers and inventory systems over Wi-Fi protected with WEP, an encryption standard already demonstrably broken. The attackers behind the TJX breach simply drove to a Marshalls store in St. Paul, Minnesota, in 2005, and cracked the store’s WEP key from the parking lot. That parking-lot foothold bridged into TJX’s corporate network — where the intruders installed sniffer software to capture payment card data flowing between stores and banks, unencrypted, for months.
The ring’s leader was Albert Gonzalez, and his story remains the strangest in cybercrime. While running these intrusions, he was simultaneously a paid informant for the Secret Service, feeding agents information about the very underground he was robbing. From 2003 he had access to agents, warnings, even reimbursement — and used it as cover, tipping off co-conspirators about investigations and targeting companies with the confidence of a man being paid to hunt himself. The globe-spanning operation moved millions of card numbers through fences, with Ukrainian card broker Maksym Yastremskiy among the key resellers; cloned cards were used for fraud from Asia to Latin America.
TJX noticed anomalous network traffic in December 2006 and disclosed the breach in January 2007. The numbers were unprecedented: TJX admitted 45.6 million cards compromised; banking officials calculated the exposure could reach 94 million, based on card-brand forensic counts of unique accounts seen in the intrusion window. Fraud losses cascaded worldwide.
The damage
Beyond the card numbers, TJX established the modern breach-industrial playbook: class actions, state-AG multistate investigations, card-network fines, and regulatory cascade. TJX took charges exceeding $100 million and paid roughly $9.75 million in a multistate settlement (then a record) plus tens of millions more to banks and card brands. It also directly spurred Massachusetts’ first-in-the-nation data-security regulations (201 CMR 17.00) and accelerated enforcement of the PCI DSS payment-card standard — suddenly retailers discovered that “we store card data over unencrypted Wi-Fi” was going to be an audit failure, not just a risk.
Aftermath & lessons
Gonzalez’s double life unraveled in 2008 when investigators caught his crew mid-operation in Miami; the resulting indictment read like a confession of the decade: TJX, Dave & Buster’s, BJ’s Wholesale, OfficeMax, Sports Authority, Barnes & Noble — and, foreshadowing the next entry, Heartland. In March 2010 he was sentenced to 20 years in prison — two concurrent 20-year terms, the longest US computer-crime sentence at the time. Prosecutors quoted his instruction to an accomplice about a new target, which doubles as the era’s epitaph: “Get all you can, get as much as you can and let’s try to sell it.”
The core lesson: an organization’s security is set by its least-secured connection — a $60 store router in a parking lot reached a multinational’s payment backbone. And Gonzalez’s career taught defenders an uncomfortable truth: insider-threat logic must extend to the people helping you.
7. The Heartland Payment Systems Breach (2008) — 130 Million Cards in One Shot
| Attacker | The Gonzalez ring (US and Eastern European collaborators) |
| Target | Heartland Payment Systems, a major US card processor handling ~100M transactions/month |
| Method | SQL injection into a web application, then sniffers planted on the payment-processing network |
| Damage | ~130 million card numbers — the largest criminal breach ever prosecuted at the time |
| Cost | Over $110 million in settlements and fines; a concurrent 20-year sentence for Gonzalez |
How the attack unfolded
If TJX was the warm-up, Heartland was the same crew playing the final level. Heartland Payment Systems was a card processor — the middleman that moved transactions between merchants and banks for 175,000 businesses. In 2008, the Gonzalez ring breached it through an almost insultingly simple door: SQL injection against a web-facing application. From that foothold they moved laterally into the payment-processing environment and planted sniffer malware that siphoned card data — magnetic-track data with everything needed to clone cards — as it flowed through the network in transit, before encryption applied at other stages.
Because the data was captured in motion on internal systems, and because Heartland had passed its PCI DSS compliance validation shortly before, the intrusion survived undetected for many months. When Heartland went public in January 2009 — with CEO Robert Carr making unusually candid statements including notifying card brands and the public quickly — the company conceded the exposure was breathtaking: the August 2009 federal indictment put it at ~130 million card numbers, the largest criminal data breach ever charged. Gonzalez, already facing 20 years for TJX, had been instruсted by his own accomplices’ arrest records; captured chat records showed him casing Heartland with the message: “[I’m] going to get all you can… this is the biggest one yet.” (Paraphrased by prosecutors as “Get all you can.”)
The damage
Heartland paid dearly: more than $110 million in settlements to Visa ($60M), Mastercard, and American Express, plus legal costs; the stock lost most of its value in days; and the company endured years of litigation. But the breach’s largest legacy was conceptual. Heartland had been certified PCI compliant at the time of the intrusion — and said so publicly. The security industry acquired its most-cited slogan: compliance is not security. Passing an audit of documented controls, it turned out, told you nothing about whether a sniffer was already watching your traffic.
Aftermath & lessons
- Heartland responded by championing end-to-end encryption (“E3”) of card data from the terminal onward — an architecture shift the payment industry at large adopted over the following decade, alongside the accelerated rollout of EMV chip cards in the US, which finally arrived years after Europe largely because magnetic-track data remained so lootable.
- The Gonzalez prosecutions (TJX, Heartland, and the ring’s other victims) effectively broke the first great era of organized carding — before new markets (carding forums, then cryptocurrency) rebuilt it.
- For processors everywhere, Heartland ended the era of assuming the internal network was safe. Traffic between “trusted” internal systems got encrypted, segmented, and monitored — the beginning of zero-trust thinking.
The core lesson: data in transit inside your network is data in the clear on the internet. And the moment you treat an audit pass as proof of safety is the moment you’re most exposed.
