A short history of cyber threats: from the Morris worm to ransomware-as-a-service
20 September 2026
1988: the Morris worm — the accident that invented the field
A Cornell graduate student released a self-replicating program to measure the internet. A coding error made it reinfect machines until roughly 6,000 computers — a tenth of the internet then — ground to a halt. Its author became the first person convicted under America's new Computer Fraud and Abuse Act. Lesson one, still true: the internet was built for trust, and it still runs on it.
2000: ILOVEYOU — the love letter that cost billions
An email with the subject "ILOVEYOU" and an attachment carried a script that overwrote files and mailed itself to every contact. Tens of millions of machines were hit within days; damages were estimated in the billions of dollars. The author, in the Philippines, could not be prosecuted — the country had no cybercrime law yet. Lesson two: law always lags the attack, in every country, including India today.
2010: Stuxnet — code that broke machines
A worm widely attributed to state actors sabotaged uranium-enrichment centrifuges by making them spin themselves apart — while reporting normal readings to operators. Malware crossed from stealing data to destroying physical equipment. Lesson three: anything connected can be reached, including infrastructure.
2017: WannaCry and NotPetya — scale and collateral
WannaCry used a leaked NSA exploit to encrypt 200,000+ computers in 150 countries in days — hospitals included — until a researcher accidentally found its kill switch. Weeks later NotPetya, disguised as ransomware but designed only to destroy, caused an estimated $10 billion in damage, hitting shipping giant Maersk and others who were never the target. Lesson four: you don't have to be the target to be the victim.
Today: ransomware-as-a-service
Attack toolkits are now rented like software, with affiliates, helpdesks, and profit-sharing. The barrier to entry collapsed — which is why small businesses, schools, and individuals are hit as often as enterprises.
The single pattern
Every era's disaster has the same three ingredients: unpatched systems, over-trusted messages, and no offline backup. Remove any one and most attacks fail. Start with our free breach self-check and India's threat landscape.