A 75-cent accounting error unmasked a Cold War spy ring
In 1986, astronomer Clifford Stoll investigated a 75-cent billing discrepancy in the mainframe accounting system at Lawrence Berkeley Laboratory. Rather than dismiss the tiny rounding error, Stoll traced it to an unauthorized user hijacking network accounts. Over ten months, he tracked the intruder through phone switches and satellite links, eventually exposing Markus Hess, a German hacker selling stolen military software and network data to the Soviet KGB.
The Missing Seventy-Five Cents
In August 1986, Clifford Stoll was an astronomer whose research funding had lapsed, prompting him to take a temporary position as a systems manager at the Lawrence Berkeley Laboratory in California. One of his earliest assignments was mundane: resolving a seventy-five-cent accounting discrepancy generated by the laboratory's computer billing software. Mainframe systems at the time charged departments according to the exact amount of processor time used. Stoll noticed that the accounting records showed a microscopic imbalance between the billed time and the logged usage across the system's users.
Rather than writing off the seventy-five cents as an insignificant rounding error or minor software glitch, Stoll dug into the audit logs to find the source. He discovered that a user named Sventek had logged in and consumed a fraction of processor time without being linked to an active billing account. When Stoll contacted the real programmer named Sventek, he learned that the individual had left the laboratory months earlier and had not used the system. An unauthorized individual had revived an inactive profile to slip onto the mainframe unnoticed.
An Intruder Inside the Unix Shell
Further investigation revealed that the intruder was not merely browsing. Once inside the laboratory's Unix systems, the attacker exploited a known vulnerability in the GNU Emacs editor—specifically within its movemail utility—to escalate privileges and obtain superuser, or root, access. With root access secured, the hacker possessed full administrative control, allowing him to alter system logs, install trojan horse programs, and create concealed backdoors that ensured future entry even if individual accounts were secured.
The Lawrence Berkeley Laboratory was not the hacker's ultimate target; it was an open transit point. The laboratory's computers were connected to the ARPANET and MILNET, early packet-switching networks that linked universities, research facilities, and military bases across the United States. From his perch at Berkeley, the intruder systematically scanned the connected networks for unpatched vulnerabilities, searching for military databases, government research installations, and defense contractors while attempting to harvest passwords and sensitive technical files.
Building a Physical Wiretap
Because modern intrusion detection software and network monitoring suites did not yet exist, Stoll had to invent tracking techniques using physical hardware. He gathered spare teleprinters, monitors, and serial cables, wiring them directly to the laboratory's incoming modem lines and network switches. Every character sent across the communication channels was simultaneously printed onto rolls of paper, creating a tangible, unalterable log of the intruder's keystrokes in real time.
To catch the hacker in the act, Stoll set up an alarm system connected to his phone line and a pocket beeper, allowing him to know the instant the intruder dialed into the lab. For months, Stoll slept beneath his desk or rushed to the laboratory at all hours to monitor live sessions. Through keystroke logs, Stoll watched as the intruder searched military networks for keywords such as nuclear, SDI, NORAD, and Stealth, attempting to break into computers operated by the United States Air Force, Navy, and defense laboratories.
The Transatlantic Trace and the Honeypot
Tracking the physical location of the intruder proved exceptionally difficult. The hacker entered the Berkeley system through Tymnet, a commercial data communications network, routing signals through multiple intermediate telephone switches and satellite links. Tracing an analog telephone call across international boundaries required the connection to remain active for an extended period, but the hacker typically executed short, focused sessions before disconnecting.
To keep the intruder connected long enough for telecommunications authorities to complete a trace, Stoll and his associates devised an early version of what is now called a honeypot. They fabricated an elaborate set of fake documents detailing a fictitious government contract involving the Strategic Defense Initiative (SDI), commonly known as Star Wars. They populated a new directory with dense, bureaucratic reports and created a bogus contact persona named Martha Matthews, complete with a physical mailing address.
The strategy succeeded. When the intruder discovered the simulated SDI repository, he remained logged on for more than an hour, systematically downloading the extensive collection of fake technical documents. The prolonged connection gave the German postal and telecommunications agency, the Deutsche Bundespost, sufficient time to trace the incoming satellite link back through switches in Bremen to a dial-in modem located in Hannover, West Germany.
The KGB Espionage Ring
West German authorities identified the hacker as Markus Hess, a programmer operating out of Hannover. Hess was not acting as a solitary prankster; he was part of a small espionage ring that included Karl Koch, Dirk-Otto Brezinski, and Peter Carl. The group had been systematically infiltrating Western computer networks and selling stolen operating system source code, computer security manuals, and technical research data to the Soviet Union's intelligence agency, the KGB, in exchange for cash and drugs.
Hess was eventually arrested by German authorities and brought to trial alongside his co-conspirators. The investigation demonstrated that even unclassified networks could be leveraged to map military infrastructure and gather actionable intelligence. Stoll's detailed hardware logs and forensic records provided the primary technical evidence that established how Hess entered American networks, escalated his system privileges, and extracted data.
Foundations of Digital Forensics
When Stoll initially attempted to report the intrusions, established intelligence and law enforcement agencies—including the FBI, CIA, and NSA—were uncertain how to respond. Because the Lawrence Berkeley Laboratory did not house classified military secrets, jurisdictional boundaries were unclear, and few officials grasped the threat posed by network-based espionage across interconnected systems.
Stoll published his findings in a detailed 1988 technical paper titled 'Stalking the Wily Hacker' in the Communications of the ACM, followed by his 1989 book *The Cuckoo's Egg*. The incident is now recognized as a landmark case in computer security history. It documented the first major international cyber espionage investigation, introduced the concept of digital honeypots, and demonstrated the critical importance of rigorous audit trails, password security, and prompt software patching.
Key takeaways
•A 75-cent billing imbalance on a Unix mainframe at Lawrence Berkeley Laboratory uncovered an unauthorized user exploiting an Emacs vulnerability to gain superuser privileges.
•Astronomer Clifford Stoll monitored the intruder by physically wiring teleprinters and modems to dial-in lines, recording all keystrokes in real time.
•Stoll and his colleagues created an early honeypot—a fake military project regarding the Strategic Defense Initiative—to keep the hacker connected long enough to trace the call.
•The trace led to Markus Hess in Hannover, West Germany, exposing an international espionage ring selling stolen Western computer data to the Soviet KGB.