How a 75-cent accounting error at Berkeley Lab exposed a hacker selling to the KGB
One of the first known cases of computer espionage was uncovered because a lab's computer bill was off by 75 cents.[1] This case file covers how a systems administrator at Lawrence Berkeley Laboratory turned that tiny accounting gap into a trail that led to Hanover, West Germany and a hacker selling to the KGB, and why the control that caught him is still the one most small businesses skip.
What happened
In August 1986, an astronomer working as a systems administrator at Lawrence Berkeley Laboratory in California noticed a 75-cent discrepancy in the accounting for the lab's shared computers.[1] Computer time at the lab was tracked and charged, so every bit of use should have belonged to a known account. The gap turned out to be an unauthorized user.[1][2]
Instead of simply locking the intruder out, the lab watched. The intruder used Berkeley as a stepping stone onto Milnet, the defense network that linked military bases, university labs and defense contractors, and searched for words such as nuclear, ICBM, SDI and Norad.[1] Reports at the time said he tried about 450 computers and got into more than 40, including Pentagon systems, defense contractors and military bases.[1]
Tracing a connection across several networks and an ocean took time the intruder did not normally give. So the administrator built bait: a made-up military project and a fake network called SDI Net, filled with bogus documents. The intruder spent 2 hours reading them, long enough for investigators working with the FBI and AT&T to trace the call to Hanover.[1][2] In April 1987, a letter from Pittsburgh asking for more information about the fake project arrived, showing that someone else was interested in the stolen data.[1][2]
How they got in
The intruder, later identified as Markus Hess, worked from West Germany. He connected through the West German public data network and international links onto U.S. networks, and used computers at Berkeley and elsewhere as relay points to reach others.[2] From there he probed hundreds of machines on the defense network looking for ones that would let him in.[1]
Many of the systems he entered were not protected well enough to stop someone who had already reached them. What made him visible was not a lock he failed to pick. It was the record of what he did once inside: logins, time used, and files read.
How it was caught
The lab reported the intrusion to the FBI in 1986, and the case later involved U.S. and West German authorities.[1] The fake SDI Net files did two jobs. They kept the intruder connected long enough for the trace to Hanover, and they drew out the Pittsburgh letter, which gave investigators more evidence of who was after the material.[1][2]
In March 1989, West German officials announced the arrests of hackers accused of selling stolen military information and passwords to the Soviet Union.[1] Hess and his associates had sold material to the KGB for about $54,000, according to accounts of the case.[2]
What it cost
In 1990, a West German court convicted Hess of espionage and gave him a 20-month suspended sentence.[2] For Berkeley and the military sites, the direct cost was small. The real price was months of access to defense networks that no one had noticed until one person refused to ignore a rounding error.
The missing control
The missing control: auditing and monitoring account usage logs, and acting on what they show.
Every system the intruder touched kept some record of who logged in and what they used. Most of those records went unread. At Berkeley, one person compared two sets of numbers, found a mismatch, and asked why. That habit caught a spy. If the other sites he entered had reviewed their logs for accounts used at odd hours, from unusual places, or by people who should not have had access, he would likely have been spotted far sooner and in many more places.
The lesson has aged well. Most modern breaches also leave traces in logs well before anyone notices. Logs only help if someone looks at them.
What to do in your business
- Turn on sign-in alerts. In email, cloud storage and accounting software, switch on notices for new devices, new countries and failed logins, and send them to someone who will read them.
- Review accounts monthly. Print the list of user accounts and ask of each one: who is this, do they still work here, and do they need this access?
- Reconcile the small numbers. Unexplained charges, odd usage totals or small billing gaps are worth a question. Small mismatches are how big problems first show up.
- Keep logs long enough to matter. Make sure sign-in and activity logs are kept for at least 90 days, so you can look back when something seems wrong.
- Know who to call. Write down your IT contact, your bank's fraud line and the FBI's ic3.gov reporting site before you need them.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How a small business keeps software and devices patched, and why default passwords must go
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- Every patching and monitoring control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.