08/31/2026
In August 1986, Clifford Stoll was new to the job. An astronomer by training, he'd been designing telescope optics for Lawrence Berkeley National Laboratory when his grant funding dried up. The lab transferred him to the basement—to the computer center, where he'd manage their systems. He'd been there two days when his boss walked in with a problem. The lab's monthly accounting reports showed a 75-cent discrepancy between two billing programs. Nine seconds of computer time. Nothing. But it bothered Stoll. He started digging through the logs. Someone had used an account without paying for it. An unauthorized user. And that user had somehow changed the password—which meant they'd need superuser privileges, the same access level as a system administrator. That was weird. Stoll could have just disabled the account and moved on. But now he was curious. On a Friday evening, he built a trap. He rounded up fifty terminals and physically attached them to the lab's fifty incoming phone lines. When the hacker dialed in that weekend, he'd see exactly which line they were using. It worked. But what Stoll discovered sent him down a rabbit hole that would consume the next ten months of his life. The hacker wasn't local. The connection was coming through multiple systems across the United States. And Stoll watched in real-time as the hacker used Berkeley's computers as a launching pad to break into military bases across the country, searching for files containing words like "nuclear" and "SDI"—Strategic Defense Initiative, Reagan's proposed missile defense system. Stoll called the FBI. "They're breaking into my computer! They're stealing military stuff!" The FBI wanted to know how much money had been lost. Seventy-five cents. They weren't interested. He tried the NSA. Then the CIA. Then the Air Force. Same response. Computer hacking was so new that law enforcement didn't even know whose jurisdiction it fell under. So Stoll kept investigating on his own. He spent countless nights at the lab, monitoring the hacker's activity. He watched as the intruder copied password files, planted Trojan horses, and methodically probed military computers. With help from phone company officials, Stoll traced the calls across the United States and eventually found the source: West Germany, specifically Hanover, via satellite. Now Stoll had a problem. He needed to keep the hacker online long enough for German authorities to trace the exact location. But the hacker was cautious, rarely staying connected more than a few minutes. So Stoll created a honeypot. He built a fake department at Berkeley claiming to conduct SDI research. He filled it with large files full of impressive-sounding bureaucratese about missile defense systems. All fake, but it looked real. The hacker took the bait. Intrigued by the "classified" SDI files, they stayed connected longer, downloading the fake documents. It was enough time. The West German postal service traced the call to a house in Hanover. The hacker's name was Markus Hess. And he wasn't working alone. Hess was part of a ring of German hackers who'd been selling stolen American military and industrial data to the KGB for cash. During his time working for Soviet intelligence, Hess had broken into 400 U.S. military computers, stealing sensitive information about semiconductors, satellites, space technology, and aircraft. The group had received about $54,000 over more than two years from a KGB agent at a Soviet trade mission in East Berlin. German authorities arrested Hess on June 29, 1987. In 1990, he went to trial. Stoll flew to Germany and testified for three days. Hess and two co-conspirators were convicted of espionage and received suspended sentences. A fourth member of the ring, Karl Koch, never made it to trial. He was found burned to death in a forest. Authorities ruled it a su***de, though questions remained. Stoll wrote about his investigation in "The Cuckoo's Egg," which became a bestseller. PBS's NOVA turned it into a documentary in 1990 called "The KGB, the Computer, and Me." Stoll's investigation became one of the first major cybersecurity cases ever documented. His techniques—monitoring logs, tracing network connections, creating honeypots—helped establish the foundations of modern computer forensics. And all of it started because an astronomer-turned-systems-administrator refused to ignore 75 cents. The lesson? Sometimes the smallest anomaly is a thread. And if you pull it long enough, you might unravel something huge.