You are currently viewing The 33 Biggest Cyberattacks & Hacks in History (1988–2024)

The 33 Biggest Cyberattacks & Hacks in History (1988–2024)

  • Post author:
  • Post category:Security
📋 Key Takeaways
  • The Complete Timeline
  • The Five Most Expensive Attacks Ever
  • The Largest Data Breaches Ever (by people affected)
  • The Eight Patterns That Explain 35 Years of Hacking
  • Frequently Asked Questions
7 min read · 1,317 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

The 33 Biggest Cyberattacks & Hacks in History (1988–2024)

Every era of computing has one attack that ended the innocence. This is the complete list.

Cybercrime today is one of the largest economies on Earth — annual damages are estimated in the trillions of dollars, larger than the GDP of most countries. But it didn’t appear fully formed. It was built, attack by attack, over nearly four decades. Each incident on this list taught criminals a new technique, forced governments to write new laws, and pushed defenders to invent the security industry we have today.

This pillar page is the complete master list — all 33 attacks, ranked by chronology, with the headline facts for each. Every entry links to the deep-dive in the series where you’ll find the full story: how the attack actually worked, who did it, what it cost, who went to prison, and what it permanently changed.

Read the series:


The Complete Timeline

# Year Attack Attacker Headline damage
1 1988 Morris Worm Robert Tappan Morris 10% of the entire Internet knocked offline
2 1980s–95 Kevin Mitnick Kevin Mitnick Breached DEC, Motorola, Nokia, Sun via social engineering
3 2000 ILOVEYOU / Love Bug Onel de Guzman (Philippines) ~10% of world’s PCs infected; up to $15B damage
4 2003–08 Titan Rain China-linked state hackers Years of stolen US defense data
5 2007 Estonia cyberattacks Russia-linked actors First nation-wide DDoS assault; NATO wakes up
6 2005–07 TJX breach Albert Gonzalez ring Up to 94M payment cards
7 2008 Heartland Payment Systems Gonzalez ring ~130M cards — largest criminal card theft then known
8 2009 Operation Aurora Chinese state hackers Google & ~30 firms breached; Google exits China
9 2010 Stuxnet US & Israel (reported) ~1,000 Iranian centrifuges physically destroyed
10 2011 RSA SecurID breach China-linked hackers Two-factor tokens compromised; defense contractors hit
11 2011 DigiNotar collapse Iranian hacker 300K Gmail users in Iran spied on; CA bankrupted
12 2012 Shamoon / Saudi Aramco Iran-linked actors 30,000 PCs wiped at world’s largest oil company
13 2014 Sony Pictures hack North Korea ~100TB leaked; first state attack on a company over a movie
14 2013–14 Yahoo breaches Russian FSB + criminals All 3 billion accounts — largest breach ever
15 2015 OPM breach Chinese state hackers 22.7M US security-clearance files stolen
16 2015–16 Ukraine power grid Russian GRU (Sandworm) First hacker-caused blackouts (~230K people)
17 2016 Bangladesh Bank heist North Korea (Lazarus) $81M stolen from a central bank via SWIFT
18 2016 Mirai botnet Jha, White & Norman IoT botnet knocked Twitter/Netflix/Reddit offline (US East)
19 2017 WannaCry North Korea (Lazarus) 230K+ PCs in 150+ countries; UK NHS operations canceled
20 2017 NotPetya Russian GRU (Sandworm) ~$10 billion — costliest cyberattack in history
21 2017 Equifax breach Chinese PLA officers (indicted) 147M Americans’ financial identities
22 2014–18 Marriott/Starwood breach China’s MSS (attributed) ~383M guest records incl. millions of passports
23 2020 SolarWinds supply-chain attack Russia’s SVR (APT29) ~18,000 orgs exposed; US government deeply penetrated
24 2021 Colonial Pipeline ransomware DarkSide 45% of East Coast fuel supply shut; $4.4M ransom
25 2021 JBS ransomware REvil World’s largest meat processor; $11M ransom
26 2021 Kaseya / REvil REvil ~1,500 businesses encrypted in one weekend
27 2022 Lapsus$ rampage Mostly teenagers Nvidia, Microsoft, Okta, Uber, Rockstar (GTA VI leak)
28 2022 Medibank breach Russia-linked extortionists 9.7M Australians’ health data dumped online
29 2023 MOVEit / CL0P CL0P extortion gang 2,000+ orgs; ~93–96M people; up to $12B
30 2023 MGM Resorts hack Scattered Spider + ALPHV ~$100M loss; casinos dark; one phone call to enter
31 2024 Change Healthcare ransomware ALPHV/BlackCat + RansomHub US pharmacy system frozen weeks; ~190M people; ~$3B
32 2024 Snowflake customer breaches UNC5537 Ticketmaster 560M + AT&T 109M call records
33 2024 XZ Utils backdoor Unknown (“Jia Tan”) Near-miss: backdoor in Linux’s foundations caught by luck

The Five Most Expensive Attacks Ever

Rank Attack Year Estimated cost
1 NotPetya 2017 ~$10 billion (White House estimate)
2 MOVEit / CL0P 2023 up to ~$12B in total losses by some estimates
3 ILOVEYOU 2000 $5.5–15 billion
4 WannaCry 2017 ~$4 billion
5 Change Healthcare 2024 ~$3 billion+ direct costs to UnitedHealth alone
data-hmmnm-seam="2">

The Largest Data Breaches Ever (by people affected)

Rank Attack Year People affected
1 Yahoo 2013–2016 3 billion (every account)
2 Marriott/Starwood 2014–2018 up to ~383M records (~339M guests)
3 Change Healthcare 2024 ~190 million
4 Ticketmaster (Snowflake) 2024 ~560 million records
5 Equifax 2017 147 million
data-hmmnm-seam="3">

The Eight Patterns That Explain 35 Years of Hacking

Reading all 33 stories back-to-back reveals the same failures again and again. Every modern security standard exists because one of these attacks proved it necessary.

  1. Humans are the #1 attack surface. Mitnick in 1995, Lapsus$ in 2022, MGM in 2023 — a phone call beats a zero-day.
  2. A password without MFA is an open door. Colonial Pipeline, Change Healthcare, Snowflake, MGM — four of the biggest recent attacks needed nothing more.
  3. Patch what you know exists — and know what exists. Equifax and WannaCry were failures of inventory and patch discipline, not exotic genius.
  4. Your vendors are your attack surface. SolarWinds, Kaseya, MOVEit, XZ: compromise one supplier, own a thousand customers.
  5. Ransomware now targets infrastructure, not just data. Fuel (Colonial), meat (JBS), healthcare (Change) — extortion has merged with national security.
  6. States hack companies for money, sabotage, and espionage. North Korea robs banks; Russia cuts power; China harvests clearance files.
  7. Concentration creates catastrophe. One clearinghouse (Change), one file-transfer product (MOVEit), one DNS provider (Dyn/Mirai) — single points of failure now have national blast radii.
  8. Assume you’re already compromised. Marriott was breached for four years before discovery; Equifax for 76 days; Yahoo for three years. Detection, not prevention, decides the damage.

data-hmmnm-seam="4">

Frequently Asked Questions

What was the biggest cyberattack in history?

By financial damage: NotPetya (2017), a Russia-attributed destructive attack on Ukraine that spread worldwide, causing an estimated $10 billion in losses. By data stolen: the Yahoo breach, which compromised all 3 billion user accounts. By physical impact: Stuxnet, which destroyed nuclear centrifuges.

What was the first major cyberattack?

The Morris Worm (November 2, 1988) is generally considered the first major attack on the Internet, infectating ~10% of all connected machines and leading to the creation of CERT. (Earlier notable incidents include the 1986 Cuckoo’s Egg espionage case tracked by Clifford Stoll.)

Which country has committed the most state-sponsored cyberattacks?

No definitive count exists, but public attributions by the US, UK, and EU most frequently name Russia, China, North Korea, and Iran. Each has a signature: Russia (sabotage & espionage — Sandworm), China (mass intellectual-property espionage), North Korea (revenue generation — Lazarus), Iran (disruptive retaliation — Shamoon).

What is the largest ransomware attack ever?

WannaCry (2017) by raw machine count (230,000+ computers in 150+ countries), NotPetya (2017) by damage (~$10B), and MOVEit (2023) by number of victim organizations (2,000+).

Do companies get their ransom money back?

Rarely. The FBI recovered part of Colonial Pipeline’s ransom (~$2.3M of $4.4M), but most payments — JBS’s $11M, Change Healthcare’s $22M — are gone. This is why the debate over banning ransom payments continues.

Has anyone ever gone to jail for these attacks?

Yes: Morris (probation), Mitnick (years in pre-trial custody), Gonzalez (20 years), members of REvil (13+ years), Lapsus$ hackers (hospital/rehab orders), a Yahoo accomplice (5 years), and indictments remain open against North Korean, Chinese, and Russian state hackers who will likely never stand trial.

What attack almost ended the internet?

The XZ Utils backdoor (2024) — a nearly undetectable backdoor planted in a core Linux library after a 2.5-year social-engineering campaign, discovered by one engineer’s curiosity weeks before it could ship inside major distributions.

What do all these attacks have in common?

Almost none required genius. A reused password, an unpatched server, a trusting help desk, an exhausted open-source maintainer. The biggest hacks in history were ordinary failures exploited at extraordinary scale — which is why the defenses are ordinary too: MFA everywhere, patch discipline, least privilege, backups, and rehearsed incident response.


data-hmmnm-seam="5">

Where to Start Reading

Last updated: rolling. Damage figures are best-available public estimates; nation-state attributions reflect formal government attributions and indictments, not convictions.

data-hmmnm-seam="end">