The Early Era: Morris Worm & Kevin Mitnick (1988–1999)
← Back to the full list · Next: Part 2 — The 2000s →
The World in 1988
To understand why the Morris Worm mattered, you have to understand what the “Internet” was in November 1988: roughly 60,000 to 80,000 machines, mostly Unix workstations and servers at universities, government labs, and defense contractors, connected through ARPANET and the young NSFNET. There was no World Wide Web (Tim Berners-Lee would propose it a year later). No commercial traffic. No firewalls. No antivirus industry worth the name. Email was for researchers.
The machines trusted each other because the people trusted each other. Network services ran with debugging conveniences left enabled; passwords were short and often dictionary words; security was, in the words of the era, “someone else’s problem.” The community was so small and so open that when a Cornell graduate student wanted to measure its size, the community assumed he could just ask.
What follows are the two foundational stories of cybersecurity: the first automated attack that broke the Internet, and the man who proved the strongest system is only as strong as the weakest person who runs it.
1. The Morris Worm (1988) — The Attack That Created Internet Security
| Attacker | Robert Tappan Morris, 23, Cornell graduate student |
| Target | Unix machines on the early Internet (universities, NASA, military labs) |
| Method | Self-replicating worm exploiting sendmail, fingerd, and weak passwords |
| Damage | ~6,000 machines infected — ~10% of the entire Internet |
| Cost | Cleanup estimated by the US GAO at $100,000–$10 million |
How the attack unfolded
At about 8:30 PM on November 2, 1988, a small program was launched from a machine at MIT — deliberately disguised, since its author was actually dialing in from Cornell. It was written by Robert Tappan Morris, a first-year graduate student and the son of the NSA’s chief computer scientist. Morris later claimed it was an experiment to gauge the size of the Internet. If so, it succeeded beyond anything he imagined.
The program — soon nicknamed the “Internet worm” or “Morris Worm” — was elegant, compact (about 3,000 lines of C), and armed with three ways into every machine it touched:
- A buffer overflow in
fingerd— the service that let users look up each other’s real names. The worm overflowed an input buffer and injected its own code. On VAX machines it simply fed the service a chain of instructions longer than it could hold. - A debug mode in
sendmail— the mail server. Administrators almost never turned off the DEBUG command, which was meant for diagnosing mail problems. The worm sent mail composed as a debug command that executed a copy of itself. - Password cracking — once inside one account on a machine, the worm read the encrypted password file and tried to break other users’ passwords using a built-in dictionary of the 432 most common choices, the system dictionary, and clever permutations (capitalizing the first letter, adding digits). Every cracked password meant new front doors into other machines, because users reused passwords across systems.
Each infected machine then silently scanned for new targets and launched copies of the worm. And here Morris made the mistake that turned an experiment into a catastrophe. Worried that a smart administrator might defeat the worm by having machines falsely answer “I’m already infected,” he built in a safeguard: even if a target claimed infection, the worm would infect it anyway one time in seven. But real machines didn’t lie — so most machines were infected not once but over, and over, and over. Dozens of worm processes multiplied into hundreds. Computers slowed to a crawl and crashed, and crashed again on restart.
By the next morning, significant chunks of the research Internet were dark. System administrators at MIT, Berkeley, Purdue, NASA, and military labs — many of whom had never spoken to each other — were suddenly on emergency conference calls, pulling network cables, and disassembling an unknown program together. Teams at Berkeley and Purdue worked through decompiling the worm to understand (and later patch) its tricks; Clifford Stoll, the astronomer famous for tracking a KGB hacker two years earlier, watched it spread in real time and raised early alarms. Many sites simply stayed disconnected for days while they cleaned up.
Estimates of the damage settled around 6,000 infected machines — roughly 10% of the Internet — with cleanup costs the General Accounting Office later put between $100,000 and $10 million. Nothing was stolen. Nothing was encrypted. No one profited. The damage was pure congestion: the first proof that the network itself could be a casualty.
The damage
Beyond the downtime, the real damage was conceptual. The worm demonstrated, in one night, that:
- Autonomous, self-propagating code could outpace any human response. The worm spread internationally in hours; humans needed days to even understand it.
- Default configurations are attack surface. Debug modes and unhardened services, considered harmless conveniences, became the worm’s highways.
- Password hygiene is network security. One weak password on one machine endangered every machine that user touched.
Aftermath & lessons
The response shaped the industry permanently:
- CERT/CC was born. In November 1988, DARPA funded the Computer Emergency Response Team Coordination Center at Carnegie Mellon University — the world’s first institutional cyber first-responder, still operating today.
- The first CFAA felony conviction. Morris was indicted under the 1986 Computer Fraud and Abuse Act — a law few imagined would be tested so soon — and convicted in 1990 in a landmark jury trial. He received three years’ probation, 400 hours of community service, and a $10,050 fine. His appeal (United States v. Morris) became foundational case law on what “unauthorized access” means.
- A security culture began. Universities started password audits; vendors shipped patches at a new pace; “firewalls” moved from research concept to product within a few years.
The epilogue is a peculiar slice of internet history: Morris went on to co-found Viaweb (one of the first web stores, built with Paul Graham and later sold to Yahoo), earned a Ph.D. from Harvard, and became a tenured professor at MIT — one of the most respectably employed former felons in computing.
The core lesson: the Morris Worm still defines the deepest truth of network security — the Internet is a single organism. Code that can spread by itself will find every weak node you forgot about. Every worm since (Code Red, Slammer, Blaster, WannaCry) is a direct descendant.
2. Kevin Mitnick’s Hacking Spree (1980s–1995) — The World’s Most Wanted Hacker
| Attacker | Kevin Mitnick, US hacker (later security consultant and author) |
| Targets | DEC, Motorola, Nokia, Sun Microsystems, Novell, Pacific Bell, USC, and many more |
| Method | Predominantly social engineering — impersonation, deception, and phone manipulation — plus insider knowledge of phone systems |
| Damage | Prosecutors claimed losses in the hundreds of millions; largely copied source code and explored systems; figures fiercely disputed |
| Cost | ~5 years in prison (mostly pre-trial); his career as “the world’s most famous hacker” |
How the attack unfolded
Kevin Mitnick’s story is the founding legend of social engineering — and a mirror held up to every organization that spends millions on technology and nothing on people.
He started young. As a teenager in Los Angeles in the late 1970s he learned “phone phreaking” — manipulating the analog phone network into free calls — from older hackers, and soon a bus punch trick morphed into a life philosophy: every system has a person in front of it somewhere, and people can be talked to. By his early twenties he had been arrested for stealing Pacific Bell technical manuals and for breaking into a university computer system; a 1988 intrusion into Digital Equipment Corporation, where he copied the source code of the VMS operating system over the network, earned him a year in prison and probation.
Then came the mistake everyone paid for. In 1992, wanted for questioning by the FBI, Mitnick disappeared. For two and a half years he lived under aliases, moving through the underground while breaching, by his own later account, some of the biggest names in technology: he copied cell-phone source code from Motorola, operating system source from Sun, NetWare source from Novell, software from Nokia, and wandered through Pacific Bell, universities, and networks of every kind. To stay ahead of trackers he cloned cellular phones — the analog cell network of the era could be spoofed almost trivially with the right codes — and, in a flourish worthy of a spy novel, reportedly pulled his own FBI file just to read what they knew about him.
He almost never stole money, and he never sold what he took. His motive, everyone on all sides eventually agreed, was obsession: the puzzle, the power, the proof of access. “I was so good at hacking,” he later wrote, “that I could get into almost any system — and I wanted to.”
What made him nearly unstoppable was that his primary exploit wasn’t a program. It was a phone call. He would ring an office, pose as a colleague, a technician, or an executive, manufacture a small emergency, and simply ask for what he needed: a password “just to test something,” a modem number “the tech guys gave me last week,” a favor from someone whose job was to be helpful. His canonical examples are now taught in every security-awareness class on Earth: “Hi, this is Bob from the phone company — we’re testing your line and need you to read me the number off your modem”; a call to a receptionist that yields a dial tone into the corporate network; a dumpster dived for printouts that reveal the org chart needed to impersonate the right person.
The endgame began on Christmas Day, 1994, when Mitnick — flush with success, perhaps careless — broke into the home computers of Tsutomu Shimomura, a computational physicist at the San Diego Supercomputer Center, stealing files and taunting his voicemail. Shimomura took it personally. He joined the hunt, and over the following weeks tracked Mitnick’s cloned cell phones and network intrusions with a scientist’s rigor. On February 15, 1995, the FBI arrested Mitnick in his apartment in Raleigh, North Carolina. The pursuit had made him a media supernova: “the most wanted computer criminal in United States history.”
What followed was itself a scandal of its era. Mitnick was held for over four years — much of it without trial, including stretches in solitary confinement. At a bail hearing, prosecutors argued he was so dangerous he should be denied phone access because he could allegedly “start a nuclear war by whistling into a pay phone” — a claim that echoed through the press and was later mercilessly mocked (there was no such capability). In 1999 he pleaded guilty to four counts of fraud (admitting, among other things, to the DEC intrusion and to intercepting electronic communications), was sentenced to time served plus supervised release, and walked out in January 2000 — initially barred from touching computers, cell phones, or the internet for years (the cell phone restriction was lifted early in 2002 after a public campaign and a persuasive court filing).
The damage
Financially, the case was always murky. Prosecutors and victim companies floated damage figures from $80 million (DEC’s contested estimate) to “hundreds of millions” across all victims — numbers Mitnick and many observers disputed as wildly inflated accounting of what was essentially copied code that was never sold or leaked. The lasting damage — and value — of the Mitnick era was educational: no incident before or since has demonstrated so vividly that the human being is the attack surface. Companies could deploy the best technology of the age; a confident voice on the phone walked straight past all of it.
Aftermath & lessons
- The consultant era. Upon release, Mitnick flipped sides: he became a celebrated security consultant, speaker, and author — The Art of Deception (2002), The Art of Intrusion (2005), and his memoir Ghost in the Wires (2011) are canonical texts on social engineering. For years, companies paid the world’s most famous hacker to try to talk his way past their receptionists — and he usually could.
- The media war. The chase spawned dueling books — Shimomura and John Markoff’s Takedown versus Jonathan Littman’s more sympathetic The Fugitive Game — and a permanent debate about how law enforcement and journalism treat hackers.
- Security awareness training as a discipline owes its existence largely to Mitnick; “your employees are your weakest link” entered the corporate vocabulary because of him.
- Mitnick died in July 2023 at 59, remembered fondly across the industry — a trickster who exposed the soft center of an increasingly technological world.
The core lesson: Mitnick’s techniques are more effective today, not less — every phishing email, every vishing call to a help desk, every Lapsus$ teenager and MGM Resorts attacker in this series is running the Mitnick playbook with newer tools. Technology changes; persuasion doesn’t.
