Case file · BERKELEY HACK 1986

How a 75-cent accounting error at Berkeley Lab exposed a hacker selling to the KGB

Published 2026-09-29 · 4 min read · Missing control: Audit and monitor account usage logs

One of the first known cases of computer espionage was uncovered because a lab's computer bill was off by 75 cents.[1] This case file covers how a systems administrator at Lawrence Berkeley Laboratory turned that tiny accounting gap into a trail that led to Hanover, West Germany and a hacker selling to the KGB, and why the control that caught him is still the one most small businesses skip.

What happened

In August 1986, an astronomer working as a systems administrator at Lawrence Berkeley Laboratory in California noticed a 75-cent discrepancy in the accounting for the lab's shared computers.[1] Computer time at the lab was tracked and charged, so every bit of use should have belonged to a known account. The gap turned out to be an unauthorized user.[1][2]

Instead of simply locking the intruder out, the lab watched. The intruder used Berkeley as a stepping stone onto Milnet, the defense network that linked military bases, university labs and defense contractors, and searched for words such as nuclear, ICBM, SDI and Norad.[1] Reports at the time said he tried about 450 computers and got into more than 40, including Pentagon systems, defense contractors and military bases.[1]

Tracing a connection across several networks and an ocean took time the intruder did not normally give. So the administrator built bait: a made-up military project and a fake network called SDI Net, filled with bogus documents. The intruder spent 2 hours reading them, long enough for investigators working with the FBI and AT&T to trace the call to Hanover.[1][2] In April 1987, a letter from Pittsburgh asking for more information about the fake project arrived, showing that someone else was interested in the stolen data.[1][2]

How they got in

The intruder, later identified as Markus Hess, worked from West Germany. He connected through the West German public data network and international links onto U.S. networks, and used computers at Berkeley and elsewhere as relay points to reach others.[2] From there he probed hundreds of machines on the defense network looking for ones that would let him in.[1]

Many of the systems he entered were not protected well enough to stop someone who had already reached them. What made him visible was not a lock he failed to pick. It was the record of what he did once inside: logins, time used, and files read.

How it was caught

The lab reported the intrusion to the FBI in 1986, and the case later involved U.S. and West German authorities.[1] The fake SDI Net files did two jobs. They kept the intruder connected long enough for the trace to Hanover, and they drew out the Pittsburgh letter, which gave investigators more evidence of who was after the material.[1][2]

In March 1989, West German officials announced the arrests of hackers accused of selling stolen military information and passwords to the Soviet Union.[1] Hess and his associates had sold material to the KGB for about $54,000, according to accounts of the case.[2]

What it cost

In 1990, a West German court convicted Hess of espionage and gave him a 20-month suspended sentence.[2] For Berkeley and the military sites, the direct cost was small. The real price was months of access to defense networks that no one had noticed until one person refused to ignore a rounding error.

The missing control

The missing control: auditing and monitoring account usage logs, and acting on what they show.

Every system the intruder touched kept some record of who logged in and what they used. Most of those records went unread. At Berkeley, one person compared two sets of numbers, found a mismatch, and asked why. That habit caught a spy. If the other sites he entered had reviewed their logs for accounts used at odd hours, from unusual places, or by people who should not have had access, he would likely have been spotted far sooner and in many more places.

The lesson has aged well. Most modern breaches also leave traces in logs well before anyone notices. Logs only help if someone looks at them.

What to do in your business

Watch the case
A 75-cent error that led to a KGB hackerDrops 2027-01-11
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Deseret News: Astronomer cracks spy case; 75-cent accounting error started hunt for the hacker
  2. Wikipedia: Markus Hess