How "Hacker" Went From Compliment to Criminal Charge
← Back to Blog

How "Hacker" Went From Compliment to Criminal Charge

August 5, 2026 · 6 min read

Digital Outlaws
Featured book
Digital Outlaws
$0.99Free on Kindle Unlimited
Amazon

In 1970, calling someone a hacker was a compliment. It meant a person who could make a machine do something it was not designed to do — an MIT term of art, applied to people who solved problems in ways the manual did not cover.

By 1995 it was a category of federal crime.

Nothing about the underlying activity changed that much. What changed is that three genuinely different groups of people all ended up filed under the same word, and the legal system, the press, and eventually the public stopped being able to tell them apart. That confusion is not a historical curiosity. It is still doing damage.

Here is the arc, told through the cases that made it.

Phase One: The Explorers

The first generation was not stealing anything, and mostly could not have said what they were doing it for beyond the system is interesting.

The phone phreaks mapped AT&T's signaling network by ear through the 1960s, a community heavily made up of blind teenagers with acute hearing and perfect pitch, who lived on the telephone because it was the one place their disability was invisible. They shared everything they found. Their culture had a norm — you learn something, you pass it on — that was less about ideology than about the practical reality that hoarding knowledge in a network of strangers makes you useless to everyone.

The same instinct produced the blue box, and the blue box produced Apple. Steve Wozniak built the best-engineered boxes in the community, and he and Steve Jobs sold them out of Berkeley dorm rooms years before they built a computer. The through-line is not the crime. It is the belief that a system controlled by a large institution can be understood from the outside by anyone willing to work at it.

At this stage the word "hacker" carries no menace, because the people it describes are not adversaries. They are enthusiasts trespassing on a network that never imagined them.

Phase Two: The Politics

In 1981, a group in Hamburg founded the Chaos Computer Club, and did something the American scene never quite managed: they made an argument.

The CCC's position was that computer systems increasingly held decisions about ordinary people's lives, and that citizens therefore had a legitimate interest in knowing whether those systems actually worked. Not a licence to steal — a claim that security failures in public infrastructure are a matter of public interest, and that the institutions running them cannot be the only ones permitted to check.

They demonstrated the point rather than arguing it in the abstract. In 1984 they exploited a flaw in Germany's Bildschirmtext online banking system to move 134,000 Deutsche Marks from a Hamburg bank into the club's own account, held the money overnight, publicised exactly what they had done, and gave every pfennig back the next morning. The bank had insisted the system was secure. It was not, and now the argument was over.

The CCC still exists, still runs one of the world's largest hacker conferences, and has spent forty years as an expert voice on German privacy and security policy. It is the clearest proof that the tradition had a civic branch, not just a criminal one — and, in Europe at least, that branch was taken seriously enough to be consulted rather than prosecuted.

That distinction did not travel well across the Atlantic.

Phase Three: The Money

Then people showed up who were unambiguously stealing, and the vocabulary collapsed.

Vladimir Levin is the pivot case. In 1994, working from St. Petersburg, he and associates accessed Citibank's cash management system and initiated transfers totalling somewhere over ten million dollars to accounts in several countries. This was not exploration and was not a demonstration. It was bank robbery, conducted over a network, and it was the first widely publicised case of its kind.

Citibank recovered nearly all of it. Levin was arrested in London, extradited, and imprisoned. The interesting detail — much argued over since — is how ordinary the technique appears to have been: not a feat of cryptography, but access obtained through people and credentials.

That is the recurring finding across the whole history, and it is why the myth of the genius intruder is so misleading. Levin took ten million dollars using access. Markus Hess sold American military data to the KGB by walking through default passwords nobody had changed. The Morris Worm brought down a tenth of the internet using three publicly documented weaknesses. The common factor is not brilliance. It is that the systems were built by people who assumed everyone on the network was a colleague.

The Case That Shows the Damage

Gary McKinnon is where the collapsed vocabulary produces something genuinely ugly.

Between 2001 and 2002, McKinnon — a Scottish systems administrator who believed the US government was concealing evidence of UFOs and suppressed energy technology — accessed dozens of US military and NASA computers. He got in largely by scanning for machines with blank or default administrator passwords, of which there were a great many. He left messages. He was not subtle and made almost no attempt to hide.

American prosecutors described it as the biggest military computer hack of all time and sought extradition, with McKinnon facing the prospect of decades in prison. His defence was that he was looking for UFO files, which is exactly as absurd as it sounds and also appears to be entirely true. He was later diagnosed with Asperger's syndrome.

The extradition fight ran for ten years. In 2012 the British Home Secretary blocked it on human rights grounds, citing the risk to his life.

Two things are true at once here, and the word "hacker" cannot hold both. He did access military systems without authorisation, repeatedly, and that is a real offence. He was also an obsessive man looking for flying saucers who found the door unlocked, and the scale of the alleged damage rested substantially on the cost of an embarrassed institution securing systems it should have secured years earlier. The prosecution treated him as a strategic threat because by 2002 there was only one category available.

Why the Confusion Persists

The Computer Fraud and Abuse Act was passed in 1986, first seriously used against Robert Morris — a graduate student whose experiment escaped — and it has never distinguished cleanly between exploration, activism, research, and theft. Unauthorised access plus damage was the test, and intent has never had to be criminal.

That has produced four decades of prosecutions in which a security researcher reporting a flaw, a journalist verifying a leak, and a person emptying a bank account are all reachable under the same statute. Meanwhile the actual professionalisation happened anyway: penetration testing, bug bounties, red teams, and coordinated disclosure are now ordinary corporate functions, staffed by people doing — legally, under contract — precisely what the phreaks were arrested for.

The word never got repaired. We just built a licensing system around it and left the law where it was.

The early hackers were not one thing. They were curious kids, political activists, obsessives, showoffs, and thieves, and the only trait they reliably shared was refusing to accept that a system's official description of itself was the whole truth. That instinct built the personal computer industry and the security profession, and it also produced real victims. Both belong in the account.

Digital Outlaws: The Rise of Early Hackers covers the full cast — Draper and the phreaks, Wozniak and Jobs, Mitnick, the Morris Worm, the Chaos Computer Club, Stoll's KGB investigation, McKinnon, and Levin's Citibank heist.

From the Catalog

Browse all
New
Wu Zetian
Wu Zetian
China's Only Female Emperor and How She Got There
New
Rapa Nui
Rapa Nui
What Really Happened on Easter Island
$3.99KU🎧
New
Thera
Thera
The Volcano That Shattered the Minoan World
$3.99KU🎧
New
Göbekli Tepe
Göbekli Tepe
The Temple Before Farming
$3.99KU🎧