The 33 Biggest Cyberattacks & Hacks in History (1988–2024)
Every era of computing has one attack that ended the innocence. This is the complete list.
Cybercrime today is one of the largest economies on Earth — annual damages are estimated in the trillions of dollars, larger than the GDP of most countries. But it didn’t appear fully formed. It was built, attack by attack, over nearly four decades. Each incident on this list taught criminals a new technique, forced governments to write new laws, and pushed defenders to invent the security industry we have today.
This pillar page is the complete master list — all 33 attacks, ranked by chronology, with the headline facts for each. Every entry links to the deep-dive in the series where you’ll find the full story: how the attack actually worked, who did it, what it cost, who went to prison, and what it permanently changed.
Read the series:
- Part 1 — The Early Era (1988–1999): Morris Worm & Kevin Mitnick
- Part 2 — The 2000s (2000–2008): Love Bug, Estonia & the Card Heists
- Part 3 — 2009–2015: Stuxnet, Sony & the Age of Cyber Weapons
- Part 4 — 2016–2019: WannaCry, NotPetya & Mirai
- Part 5 — 2020–2021: SolarWinds, Colonial Pipeline & the Ransomware Wave
- Part 6 — 2022–2024: Lapsus$, Change Healthcare & the XZ Backdoor
The Complete Timeline
| # | Year | Attack | Attacker | Headline damage |
|---|---|---|---|---|
| 1 | 1988 | Morris Worm | Robert Tappan Morris | 10% of the entire Internet knocked offline |
| 2 | 1980s–95 | Kevin Mitnick | Kevin Mitnick | Breached DEC, Motorola, Nokia, Sun via social engineering |
| 3 | 2000 | ILOVEYOU / Love Bug | Onel de Guzman (Philippines) | ~10% of world’s PCs infected; up to $15B damage |
| 4 | 2003–08 | Titan Rain | China-linked state hackers | Years of stolen US defense data |
| 5 | 2007 | Estonia cyberattacks | Russia-linked actors | First nation-wide DDoS assault; NATO wakes up |
| 6 | 2005–07 | TJX breach | Albert Gonzalez ring | Up to 94M payment cards |
| 7 | 2008 | Heartland Payment Systems | Gonzalez ring | ~130M cards — largest criminal card theft then known |
| 8 | 2009 | Operation Aurora | Chinese state hackers | Google & ~30 firms breached; Google exits China |
| 9 | 2010 | Stuxnet | US & Israel (reported) | ~1,000 Iranian centrifuges physically destroyed |
| 10 | 2011 | RSA SecurID breach | China-linked hackers | Two-factor tokens compromised; defense contractors hit |
| 11 | 2011 | DigiNotar collapse | Iranian hacker | 300K Gmail users in Iran spied on; CA bankrupted |
| 12 | 2012 | Shamoon / Saudi Aramco | Iran-linked actors | 30,000 PCs wiped at world’s largest oil company |
| 13 | 2014 | Sony Pictures hack | North Korea | ~100TB leaked; first state attack on a company over a movie |
| 14 | 2013–14 | Yahoo breaches | Russian FSB + criminals | All 3 billion accounts — largest breach ever |
| 15 | 2015 | OPM breach | Chinese state hackers | 22.7M US security-clearance files stolen |
| 16 | 2015–16 | Ukraine power grid | Russian GRU (Sandworm) | First hacker-caused blackouts (~230K people) |
| 17 | 2016 | Bangladesh Bank heist | North Korea (Lazarus) | $81M stolen from a central bank via SWIFT |
| 18 | 2016 | Mirai botnet | Jha, White & Norman | IoT botnet knocked Twitter/Netflix/Reddit offline (US East) |
| 19 | 2017 | WannaCry | North Korea (Lazarus) | 230K+ PCs in 150+ countries; UK NHS operations canceled |
| 20 | 2017 | NotPetya | Russian GRU (Sandworm) | ~$10 billion — costliest cyberattack in history |
| 21 | 2017 | Equifax breach | Chinese PLA officers (indicted) | 147M Americans’ financial identities |
| 22 | 2014–18 | Marriott/Starwood breach | China’s MSS (attributed) | ~383M guest records incl. millions of passports |
| 23 | 2020 | SolarWinds supply-chain attack | Russia’s SVR (APT29) | ~18,000 orgs exposed; US government deeply penetrated |
| 24 | 2021 | Colonial Pipeline ransomware | DarkSide | 45% of East Coast fuel supply shut; $4.4M ransom |
| 25 | 2021 | JBS ransomware | REvil | World’s largest meat processor; $11M ransom |
| 26 | 2021 | Kaseya / REvil | REvil | ~1,500 businesses encrypted in one weekend |
| 27 | 2022 | Lapsus$ rampage | Mostly teenagers | Nvidia, Microsoft, Okta, Uber, Rockstar (GTA VI leak) |
| 28 | 2022 | Medibank breach | Russia-linked extortionists | 9.7M Australians’ health data dumped online |
| 29 | 2023 | MOVEit / CL0P | CL0P extortion gang | 2,000+ orgs; ~93–96M people; up to $12B |
| 30 | 2023 | MGM Resorts hack | Scattered Spider + ALPHV | ~$100M loss; casinos dark; one phone call to enter |
| 31 | 2024 | Change Healthcare ransomware | ALPHV/BlackCat + RansomHub | US pharmacy system frozen weeks; ~190M people; ~$3B |
| 32 | 2024 | Snowflake customer breaches | UNC5537 | Ticketmaster 560M + AT&T 109M call records |
| 33 | 2024 | XZ Utils backdoor | Unknown (“Jia Tan”) | Near-miss: backdoor in Linux’s foundations caught by luck |
The Five Most Expensive Attacks Ever
| Rank | Attack | Year | Estimated cost |
|---|---|---|---|
| 1 | NotPetya | 2017 | ~$10 billion (White House estimate) |
| 2 | MOVEit / CL0P | 2023 | up to ~$12B in total losses by some estimates |
| 3 | ILOVEYOU | 2000 | $5.5–15 billion |
| 4 | WannaCry | 2017 | ~$4 billion |
| 5 | Change Healthcare | 2024 | ~$3 billion+ direct costs to UnitedHealth alone |
The Largest Data Breaches Ever (by people affected)
| Rank | Attack | Year | People affected |
|---|---|---|---|
| 1 | Yahoo | 2013–2016 | 3 billion (every account) |
| 2 | Marriott/Starwood | 2014–2018 | up to ~383M records (~339M guests) |
| 3 | Change Healthcare | 2024 | ~190 million |
| 4 | Ticketmaster (Snowflake) | 2024 | ~560 million records |
| 5 | Equifax | 2017 | 147 million |
The Eight Patterns That Explain 35 Years of Hacking
Reading all 33 stories back-to-back reveals the same failures again and again. Every modern security standard exists because one of these attacks proved it necessary.
- Humans are the #1 attack surface. Mitnick in 1995, Lapsus$ in 2022, MGM in 2023 — a phone call beats a zero-day.
- A password without MFA is an open door. Colonial Pipeline, Change Healthcare, Snowflake, MGM — four of the biggest recent attacks needed nothing more.
- Patch what you know exists — and know what exists. Equifax and WannaCry were failures of inventory and patch discipline, not exotic genius.
- Your vendors are your attack surface. SolarWinds, Kaseya, MOVEit, XZ: compromise one supplier, own a thousand customers.
- Ransomware now targets infrastructure, not just data. Fuel (Colonial), meat (JBS), healthcare (Change) — extortion has merged with national security.
- States hack companies for money, sabotage, and espionage. North Korea robs banks; Russia cuts power; China harvests clearance files.
- Concentration creates catastrophe. One clearinghouse (Change), one file-transfer product (MOVEit), one DNS provider (Dyn/Mirai) — single points of failure now have national blast radii.
- Assume you’re already compromised. Marriott was breached for four years before discovery; Equifax for 76 days; Yahoo for three years. Detection, not prevention, decides the damage.
Frequently Asked Questions
What was the biggest cyberattack in history?
By financial damage: NotPetya (2017), a Russia-attributed destructive attack on Ukraine that spread worldwide, causing an estimated $10 billion in losses. By data stolen: the Yahoo breach, which compromised all 3 billion user accounts. By physical impact: Stuxnet, which destroyed nuclear centrifuges.
What was the first major cyberattack?
The Morris Worm (November 2, 1988) is generally considered the first major attack on the Internet, infectating ~10% of all connected machines and leading to the creation of CERT. (Earlier notable incidents include the 1986 Cuckoo’s Egg espionage case tracked by Clifford Stoll.)
Which country has committed the most state-sponsored cyberattacks?
No definitive count exists, but public attributions by the US, UK, and EU most frequently name Russia, China, North Korea, and Iran. Each has a signature: Russia (sabotage & espionage — Sandworm), China (mass intellectual-property espionage), North Korea (revenue generation — Lazarus), Iran (disruptive retaliation — Shamoon).
What is the largest ransomware attack ever?
WannaCry (2017) by raw machine count (230,000+ computers in 150+ countries), NotPetya (2017) by damage (~$10B), and MOVEit (2023) by number of victim organizations (2,000+).
Do companies get their ransom money back?
Rarely. The FBI recovered part of Colonial Pipeline’s ransom (~$2.3M of $4.4M), but most payments — JBS’s $11M, Change Healthcare’s $22M — are gone. This is why the debate over banning ransom payments continues.
Has anyone ever gone to jail for these attacks?
Yes: Morris (probation), Mitnick (years in pre-trial custody), Gonzalez (20 years), members of REvil (13+ years), Lapsus$ hackers (hospital/rehab orders), a Yahoo accomplice (5 years), and indictments remain open against North Korean, Chinese, and Russian state hackers who will likely never stand trial.
What attack almost ended the internet?
The XZ Utils backdoor (2024) — a nearly undetectable backdoor planted in a core Linux library after a 2.5-year social-engineering campaign, discovered by one engineer’s curiosity weeks before it could ship inside major distributions.
What do all these attacks have in common?
Almost none required genius. A reused password, an unpatched server, a trusting help desk, an exhausted open-source maintainer. The biggest hacks in history were ordinary failures exploited at extraordinary scale — which is why the defenses are ordinary too: MFA everywhere, patch discipline, least privilege, backups, and rehearsed incident response.
Where to Start Reading
- New to security history? Start with Part 1 — the Morris Worm and Kevin Mitnick.
- Want the wildest stories? Part 4 (2016–2019) has WannaCry, NotPetya and Mirai.
- Want what’s relevant today? Part 6 (2022–2024) is practically a current-affairs briefing.
Last updated: rolling. Damage figures are best-available public estimates; nation-state attributions reflect formal government attributions and indictments, not convictions.
