What "hacker" originally meant

The word hacker originally had nothing to do with criminal activity. In the 1960s, members of the Tech Model Railroad Club at MIT used it to describe someone who could get a system — at the time literally a model railroad — to do something it wasn't originally designed for, elegantly and cleverly. The meaning gradually carried over to computers and stayed positive: a hacker was a curious experimenter, not a criminal. The community later introduced a more precise distinction — white hat (an ethical hacker who reports flaws), black hat (attacks with malicious intent), and grey hat (somewhere in between, often breaking the law without malicious intent). But from the 1980s onward, the media adopted the narrower meaning — "hacker" as computer criminal — and that's the (imprecise but widely used) sense this article uses too.

The precursor to computer hacking was phone phreaking — exploring and exploiting telephone infrastructure in the 1960s and 70s. The most famous phreaker was John Draper, nicknamed "Captain Crunch" after the toy whistle from the cereal box of the same name, which happened to produce exactly the 2600 Hz tone used by AT&T's long-distance signaling system — allowing free calls anywhere in the world. Among the early phreakers were also Apple's future founders, Steve Wozniak and Steve Jobs, who as students built and sold illegal "blue boxes" for phreaking before founding the company that changed personal computers.

1988: Robert Tappan Morris and the worm that nearly took down the internet

Robert Tappan Morris, a graduate student at Cornell University, launched a program from MIT on November 2, 1988, that, according to his later defense, was only meant to quietly spread across the network and measure its size. Due to a coding error it replicated uncontrollably instead — chaining vulnerabilities in the sendmail, fingerd, and rsh services and reinfecting the same machine repeatedly until it completely overloaded it. The result was roughly 6,000 affected hosts out of the roughly 60,000 then connected to the internet — about 10% of the entire network at the time, which slowed to a crawl or froze entirely.

Morris became the first person indicted under the American Computer Fraud and Abuse Act (CFAA) of 1986, and in 1990 was sentenced to three years of probation, a $10,050 fine, and 400 hours of community service — no prison time. The "Morris Worm" case is still taught today as the first major proof that network software needs security testing, not just functional testing. Morris later became an MIT professor and co-founded the startup accelerator Y Combinator.

Kevin Mitnick: the most famous hacker of all time

Kevin Mitnick is arguably the most famous name in the history of hacking — not for technical sophistication, but for mastery of social engineering. Instead of breaking encryption, he convinced people to voluntarily hand over access credentials or internal information — posing over the phone as an IT department employee, a phone company technician, or a colleague from another office. In the 1990s he broke into the systems of companies like Nokia, Motorola, Sun Microsystems, and Digital Equipment Corporation, and facing arrest, evaded the FBI for two years before being tracked down in 1995 with help from security expert Tsutomu Shimomura, whose systems he had also attacked.

Mitnick spent nearly five years in prison, part of it in isolation — the court feared he could launch a nuclear attack by voice alone from a prison payphone, which still stands today as an example of the panic hackers could trigger in the 1990s. After his release he became a legitimate security consultant, co-founded the firm Mitnick Security, and wrote several books including the bestseller The Art of Deception about social engineering techniques. He died on July 16, 2023, at age 59, from complications of pancreatic cancer, which he had battled for 14 months.

Kevin Poulsen: the hack that won a Porsche

Kevin Poulsen, nicknamed "Dark Dante", became famous in 1990 when he decided to win a contest run by Los Angeles radio station KIIS-FM, which promised a Porsche 944 S2 to exactly the 102nd caller. Poulsen took control of the station's phone lines so that all other calls were blocked, guaranteeing himself the win. He was also investigated for other intrusions into phone carrier systems, including cases tied to wiretapping and sensitive federal databases; he went on the run for a while and was arrested in 1991. After his release from prison, he unusually transformed into an investigative journalist — becoming senior editor of Wired News and covering exactly the computer security and crime beat he had once embodied himself.

Vladimir Levin and the "theft" of $10 million from Citibank

In 1994, reports emerged that Russian mathematician Vladimir Levin had orchestrated a series of unauthorized transfers totaling roughly $10.7 million from Citibank client accounts via remote access to its systems. Levin was arrested in the UK in 1995, extradited to the US, and sentenced to three years in prison. The case was presented in the media as one of the first major bank hacks, but later testimony from other hackers involved suggests Levin likely didn't carry out the actual intrusion into Citibank's systems himself — he reportedly bought the access credentials from another group of Russian hackers who had broken in first. Whatever his real role, the Citibank case alerted the banking sector that remote access to financial systems was a real risk, not a theoretical one.

Teenagers inside military and government systems

The late 1990s and early 2000s brought a wave of cases in which the perpetrators were surprisingly young people with a home internet connection.

Jonathan James, operating under the handle "c0mrade", broke into the systems of NASA's Marshall Space Flight Center unit as a 15-year-old from Florida and obtained the source code for a program controlling critical life-support elements of the International Space Station; he also penetrated the systems of the Defense Threat Reduction Agency, which monitors nuclear, biological, and chemical threats for the US Department of Defense. He became the first juvenile in the US to serve prison time for a computer crime. In 2008, during the investigation into the massive TJX data breach, James was questioned as a possible suspect — though no direct link to that case was ultimately found. On May 18, 2008, he took his own life; in his note he wrote that he had nothing to do with the TJX case.

Gary McKinnon of the United Kingdom broke into roughly a hundred US Army, NASA, and Pentagon computer networks between 2001 and 2002 — his stated motivation was searching for evidence of classified government records on alien technology and UFOs. US authorities called the case the "biggest military computer hack of all time" and sought his extradition. McKinnon fought a decade-long legal battle against being extradited; in October 2012, UK Home Secretary Theresa May blocked the extradition on human rights grounds, since McKinnon had Asperger syndrome and depression and faced a high risk of suicide. It was the first extradition blocked since the UK-US extradition treaty was signed in 2003.

MafiaBoy: the 15-year-old who stopped half the internet for a week

In February 2000, Canadian teenager Michael Calce, operating under the handle "MafiaBoy", launched a series of distributed denial-of-service (DDoS) attacks codenamed "Rivolta" against some of the biggest websites in the world. In a single week he successively took down Yahoo! (then the most visited site in the world), eBay, Dell, Amazon, and CNN — he targeted CNN specifically after another hacker told him its security was too strong to break. The case made front-page news around the world and alerted the public to the fact that DDoS attacks could cripple even the internet's biggest companies without the attacker needing to "break in" to anything at all — just flood the infrastructure with requests. Calce pleaded guilty to 56 counts and in September 2001 received eight months in juvenile detention, a year of probation, restricted internet access, and a $1,000 fine.

Albert Gonzalez: the largest payment card theft in history

Albert Gonzalez led a group that, between 2005 and 2007, broke into the networks of TJX (owner of TJ Maxx and Marshalls), 7-Eleven, Hannaford Bros., and payment processor Heartland Payment Systems, stealing tens of millions of payment and credit card numbers — at the time the largest financial data theft cases in history. Gonzalez originally worked with the US Secret Service as an informant following an earlier arrest, but continued his own criminal activity in parallel. He received two concurrent 20-year sentences for the two cases (20 years total in prison), three years of supervised release, and an order to pay restitution.

Sven Jaschan: the teenager whose worm stopped airports and hospitals

In 2004, eighteen-year-old German Sven Jaschan (he wrote the code while still 17) created two widespread computer worms — Sasser and Netsky. Sasser exploited a vulnerability in the Windows LSASS system service and, unlike most threats at the time, spread without any user interaction at all — simply being connected to the internet was enough. It infected millions of computers worldwide and caused outages at airlines, hospitals, and news agencies. Jaschan was caught after a friend turned him in for the $250,000 bounty Microsoft had offered for the Sasser author's capture. Since he had written most of the code as a minor, the court ultimately gave him only a suspended sentence.

Hacktivism: Anonymous and LulzSec

Anonymous emerged in the mid-2000s on the discussion forum 4chan as a loose, leaderless collective with no formal organization — anyone who chose to act under that name. Its first major public campaign was Project Chanology in 2008, against the Church of Scientology after the organization tried to remove a leaked internal video featuring Tom Cruise from the internet. In 2010 came Operation Payback — a series of DDoS attacks against PayPal, Visa, and Mastercard after those companies blocked payments to WikiLeaks following the release of diplomatic cables (the so-called Cablegate). The Guy Fawkes mask from the film V for Vendetta became the collective's symbol.

In 2011, a smaller, more technically focused group called LulzSec split off from Anonymous, and over roughly 50 days of "showmanship" broke into the systems of Sony Pictures and public broadcaster PBS (where it published a fake story about rapper Tupac being alive, in retaliation for a documentary about WikiLeaks), and briefly took down the CIA.gov website. The group disbanded itself after 50 days, announcing that their "50 days of lulz" had come to an end. Its co-founder Hector Monsegur, operating as "Sabu", became an FBI informant after his arrest and, over more than ten months of cooperation, helped identify the group's other members — according to the FBI, contributing to thwarting more than 300 planned attacks on Congress, the US military, and private companies. He originally faced up to 124 years in prison; he ultimately received a sentence equal to time already served (seven months) and a year of supervision.

A different league: state-sponsored attackers

From the mid-2010s onward, the center of gravity for the most serious attacks shifted from individuals and collectives to groups funded directly by states — so-called Advanced Persistent Threats (APTs). US intelligence and security firms attributed, for example, the 2016 Democratic National Committee data breach to APT28 (Fancy Bear), linked to Russia's GRU military intelligence service, and both the 2014 Sony Pictures attack and the 2017 global WannaCry ransomware outbreak to North Korea's Lazarus Group. Unlike the earlier cases in this article, these are organizations with budgets, long-term objectives, and often diplomatic protection — a category fundamentally different in scale and motivation from an individual seeking fame or money.

1988 Morris Worm 1995 Mitnick arrested 2000 MafiaBoy DDoS 2004 Sasser / Netsky 2009 Gonzalez sentenced 2011 LulzSec 2016+ nation-state APT groups
How the center of gravity in hacking shifted over nearly four decades — from individual curiosity, through organized financial crime, to state-sponsored groups.

Overview

Name / groupYearWhat they didOutcome
Robert T. Morris1988First major internet worm, unintentionally overloaded ~10% of the network3 years probation, fine, no prison
Kevin Mitnick1995Social engineering, intrusions at Nokia, Motorola, SunNearly 5 years in prison, later a security consultant
Kevin Poulsen1990Took over a radio station's phone lines to win a Porsche~51 months in prison, later a Wired journalist
Vladimir Levin1994Unauthorized transfers from Citibank (~$10.7M)3 years in prison
Jonathan James1999Broke into NASA and the DTRA at age 15Juvenile prison time; died in 2008
Gary McKinnon2001–02Broke into NASA, the Army, and the Pentagon searching for UFO evidenceExtradition to the US blocked (2012)
MafiaBoy2000DDoS attacks on Yahoo!, eBay, CNN, Amazon, Dell at age 158 months in juvenile detention
Albert Gonzalez2005–07Stole tens of millions of payment card numbers (TJX, Heartland)20 years in prison
Sven Jaschan2004Sasser and Netsky worms, millions of computers infectedSuspended sentence (minor at time of offense)
Anonymous / LulzSec2008–11Hacktivism, DDoS, breaches at Sony, PBS, CIA.govSeveral members convicted; Sabu cooperated with the FBI

What's changed

The stories in this article trace a clear trend: from a curious individual (Morris, Mitnick), through teenagers seeking a thrill or attention (James, McKinnon, MafiaBoy, Jaschan), organized financial crime (Gonzalez, Levin) and ideologically motivated collectives (Anonymous, LulzSec), to today's reality, where the most serious attacks are led by states with budgets comparable to small armies. This exact escalation — from an individual's curiosity to state-funded, specialized teams — is why modern defense looks the way we've described in previous articles: a single firewall or antivirus isn't enough today, and companies need a layered combination of EDR and XDR for endpoint detection, SIEM for central correlation across the whole infrastructure, and an architecture like SASE that combines prevention and visibility into a single platform.

Hacker isn't a synonym for criminal

Many of the people in this article became legitimate security experts after serving their sentences — Mitnick and Poulsen are the most striking examples. Today's bug bounty industry and certifications like OSCP exist precisely so that the same curiosity and technical skill that once led to crime has a legal, well-paid outlet instead — finding and reporting vulnerabilities before someone with bad intentions does.

Summary

The history of hacking isn't just a series of technical tricks — it's a story of how attackers' motivations changed, and what companies and governments had to face as a result. The Morris Worm showed that network software needs security testing. Mitnick proved that the weakest link is often a person, not technology. MafiaBoy and Gonzalez showed that the damage can be measured in millions of dollars and millions of victims at once. Anonymous and LulzSec turned hacking into public theater with a political edge. And today's state-funded APT groups prove that the most serious threats haven't come from individuals at a keyboard in a bedroom for a long time now — they come from organizations with budgets equal to small armies, which is exactly why modern cybersecurity has to defend in layers, not with a single tool.