RepublicCyberIntel

A short history of cyber threats: from the Morris worm to ransomware-as-a-service

20 September 2026

Timeline from the 1988 Morris worm to modern ransomware

1988: the Morris worm — the accident that invented the field

A Cornell graduate student released a self-replicating program to measure the internet. A coding error made it reinfect machines until roughly 6,000 computers — a tenth of the internet then — ground to a halt. Its author became the first person convicted under America's new Computer Fraud and Abuse Act. Lesson one, still true: the internet was built for trust, and it still runs on it.

2000: ILOVEYOU — the love letter that cost billions

An email with the subject "ILOVEYOU" and an attachment carried a script that overwrote files and mailed itself to every contact. Tens of millions of machines were hit within days; damages were estimated in the billions of dollars. The author, in the Philippines, could not be prosecuted — the country had no cybercrime law yet. Lesson two: law always lags the attack, in every country, including India today.

2010: Stuxnet — code that broke machines

A worm widely attributed to state actors sabotaged uranium-enrichment centrifuges by making them spin themselves apart — while reporting normal readings to operators. Malware crossed from stealing data to destroying physical equipment. Lesson three: anything connected can be reached, including infrastructure.

2017: WannaCry and NotPetya — scale and collateral

WannaCry used a leaked NSA exploit to encrypt 200,000+ computers in 150 countries in days — hospitals included — until a researcher accidentally found its kill switch. Weeks later NotPetya, disguised as ransomware but designed only to destroy, caused an estimated $10 billion in damage, hitting shipping giant Maersk and others who were never the target. Lesson four: you don't have to be the target to be the victim.

Today: ransomware-as-a-service

Attack toolkits are now rented like software, with affiliates, helpdesks, and profit-sharing. The barrier to entry collapsed — which is why small businesses, schools, and individuals are hit as often as enterprises.

The single pattern

Every era's disaster has the same three ingredients: unpatched systems, over-trusted messages, and no offline backup. Remove any one and most attacks fail. Start with our free breach self-check and India's threat landscape.