On May 4, 2000, a Visual Basic Script file called "ILOVEYOU.vbs" was sent as an email attachment with the subject line "I Love You." The email's body said "kindly check the attached LOVELETTER coming from me." Within ten hours, the worm had spread to an estimated 45 million computers globally. The Pentagon, CIA, British Parliament, and most of the world's corporate email systems went offline or disabled their email services to stop the spread. Estimated damages ranged from $5.5 billion to $15 billion. The two college students who created it - Onel de Guzman and a classmate in Manila, Philippines - were never prosecuted because the Philippines had no computer crime law at the time.
The ILOVEYOU worm is the definitive example of social engineering at the scale of the internet. The subject line - "I Love You" - worked because it exploited a universal human motivation: the desire to receive an expression of affection. People who knew better, who understood that email attachments could contain malware, opened the attachment because they couldn't resist knowing who loved them. The worm spread not through technical sophistication but through this fundamental emotional hook, combined with Windows' then-default behavior of hiding file extensions - the attachment appeared to be called "LOVE-LETTER-FOR-YOU.txt" rather than "LOVE-LETTER-FOR-YOU.txt.vbs," concealing that it was executable code.
Technical Mechanism
The ILOVEYOU worm (technically a computer virus and worm hybrid) was written in VBScript - the Visual Basic scripting language that Windows made available to automate system tasks. When executed, it performed several actions simultaneously. First, it copied itself to multiple locations in the Windows directory and added registry entries to ensure it ran on system startup. Second, it accessed the victim's Microsoft Outlook address book and sent copies of itself to every contact - at the time, Outlook would execute JavaScript in HTML emails and had no warning about VBScript attachments, so the spread was fully automated. Third, it overwrote files on the victim's system, replacing image files, audio files, and documents with copies of the worm script, making the originals unrecoverable.
The destructive component - overwriting files - was arguably the most damaging aspect. Infections spread so quickly that organizations disabled email before they could assess the full damage, and the overwritten files (family photos, documents, music files) were lost permanently unless backups existed. Many corporate networks had no recent backups or backup systems were infected before backups completed.
Attribution and the Philippine Legal Gap
The worm was traced to the Philippines within days - an unusual IP address in outbound traffic, combined with analysis of the script itself (which contained a string referencing "Manila" and "Barraka"). Filipino investigators identified AMA Computer College student Onel de Guzman as the likely author. De Guzman had submitted a thesis proposal to AMA proposing exactly this kind of credential-stealing worm (he wanted to steal internet access passwords, which was expensive in the Philippines at the time) - a proposal that had been rejected by the college as unethical.
Philippines law in 2000 had no computer crime statute. A warrant was issued and de Guzman's apartment was searched; investigators found evidence linking him to the worm. But prosecutors concluded that no applicable law had been violated. Charges filed under a credit card fraud statute were dismissed because the worm did not specifically target credit cards. De Guzman publicly admitted at a press conference that he "may have" released the worm but did not fully confirm authorship. He and his alleged collaborators were never convicted of any crime.
In 2020 - twenty years later - de Guzman gave an interview to security journalist Geoff White in which he confirmed he had written and released the worm. He said he had not expected it to spread globally; he had intended to use it to steal internet access passwords in the Philippines where dial-up internet access was expensive. He expressed no awareness at the time of the scale of damage it would cause.
Legacy in Email Security
ILOVEYOU's immediate legacy was a wave of email security improvements. Outlook patched the scripting execution path. Email gateways began blocking or quarantining executable attachments. Antivirus vendors added heuristic detection for scripts in email. Corporate email policies prohibiting executable attachments became standard. These changes, implemented in the months following ILOVEYOU, significantly raised the technical bar for email-borne malware.
But the social engineering mechanism - an enticing subject line, an attachment the recipient can't resist opening - proved permanent. Every subsequent era of email malware (Melissa, Klez, Bagle, Netsky, through modern phishing campaigns) used the same fundamental approach. The attachment type changes and technical mitigations meant that each new generation of malware needed to use a different file type (Word documents with macros, PDF exploits, ISO files, LNK files) - but the human vulnerability - curiosity, trust, emotional engagement - has never been patched. ILOVEYOU established that social engineering at internet scale was not a novelty; it was a permanent feature of the threat landscape.