In August 1986, Clifford Stoll was a freshly unemployed astrophysicist who had taken a temporary position managing computers at Lawrence Berkeley National Laboratory. His first task was to resolve a 75-cent accounting discrepancy in the computer usage logs. The discrepancy was caused by someone who had broken into the lab's computers and was using them for free. Stoll's investigation of that 75-cent error consumed the next ten months and led to the identification and arrest of a West German hacker selling stolen US military secrets to the KGB.
The story - later published in Stoll's 1989 book "The Cuckoo's Egg" - is the founding document of intrusion detection, incident response, and cyber counterintelligence. Stoll was doing all of it before those disciplines had names.
The 75-Cent Discrepancy
Berkeley Lab charged for computer time. Users were billed by the second. Stoll's accounting audit found that one user's logged time did not match their billed time - 75 cents' worth of seconds had been used but not attributed to any valid account. The anomaly pointed to an unauthorized user who had created a fake account with superuser privileges.
Stoll could have simply closed the unauthorized account and moved on. Instead, he wanted to understand how the intrusion had occurred. He began watching the hacker's activity in real time. What he found was that the intruder was not just using Berkeley Lab's computers - they were using them as a stepping stone to other computers, specifically US military and defense-related systems on ARPANET.
Building the Honeypot
Stoll's central insight was that to identify and catch the intruder, he needed to keep them connected long enough for their communications to be traced. Phone call traces in 1986 required the call to remain active for several minutes - much longer than the intruder's typical connection duration. Stoll needed to slow them down.
He created what would now be called a honeypot: a fabricated directory of files about a nonexistent "SDInet" project - Strategic Defense Initiative (Star Wars missile defense) network - filled with plausible-sounding but entirely fictional documents about SDI research, personnel, and classified projects. The intruder spent hours exploring and downloading files from the fake directory, giving phone company technicians time to trace the connection.
The trace required multiple steps across multiple jurisdictions. Berkeley to a data network in Oakland. Oakland to a gateway in Virginia. Virginia to a transatlantic cable. The transatlantic connection ended at Hannover, West Germany. The trace took months of coordination between Berkeley Lab, the FBI, the CIA, the NSA, West German authorities, and the phone companies at each hop.
The Bureaucratic Wall
Stoll's account of his interactions with US government agencies is as significant as the technical investigation. The FBI initially declined interest because the intrusion had caused less than $1 million in losses - below the threshold that triggered federal jurisdiction at the time. The CIA was interested but said they couldn't act on domestic networks. The NSA was interested but wouldn't share what they knew. The Air Force Office of Special Investigations was interested but had no jurisdiction over civilian networks.
For months, Stoll was essentially conducting a solo counterintelligence operation from a cramped office at a national laboratory, with sporadic and uncoordinated assistance from intelligence and law enforcement agencies who were each limited by jurisdiction and classification concerns. The lack of any coordinated mechanism for responding to computer intrusions - even those with clear national security implications - was a fundamental gap that the Morris Worm would expose again two years later.
The Hannover Group
The investigation ultimately identified a group of five West German hackers based in Hannover. The primary actor was Markus Hess, who had broken into hundreds of US military computers and was selling the access and stolen files to the KGB through an intermediary, Peter Carl, who was also involved in drug dealing. The KGB contact was based in East Germany.
The files stolen included documents from US military bases in Europe, Space Command, the Army Intelligence and Security Command, and numerous other defense installations. Much of it was low-classification material - Stoll's fake SDInet files notwithstanding - but the breadth of access represented a significant intelligence collection operation. The Soviets were paying approximately $54,000 in cash and cocaine for the material.
West German authorities arrested Hess and his associates in June 1987. Hess was convicted of espionage and computer fraud and sentenced to one year and eight months, suspended. The light sentence reflected both West German laws that had not anticipated computer espionage and the difficulty of attributing specific damages to specific intrusions. Carl, the intermediary, received a stiffer sentence related to the drug charges.
Legacy
"The Cuckoo's Egg" - published in 1989 - introduced the concept of computer intrusion to a mass audience. Its influence on the generation of security researchers who came of age in the early internet era was substantial. Stoll's techniques - logging, honeypots, traffic analysis, legal coordination across jurisdictions - became the template for incident response.
The book also documented the institutional gaps that made Stoll's investigation so difficult: the absence of legal frameworks for computer intrusion, the jurisdictional fragmentation of US government agencies with overlapping but non-complementary interests, and the lack of any mechanism for sharing information about computer intrusions across organizational boundaries. These gaps were addressed, partially, by the creation of CERT following the Morris Worm in 1988 and by subsequent legislation.
Stoll went on to teach astronomy, make Klein bottles, and become something of a curmudgeon about the direction of technology - he wrote a 1995 book called "Silicon Snake Oil" arguing that the internet was being oversold as a transformative technology. His 1986-1987 investigation, conducted entirely with tools he built himself from spare parts in a university computer lab, remains one of the most consequential incident responses in the history of network security.