A 75-Cent Accounting Error Uncovered a KGB Spy Ring
August 5, 2026 · 6 min read
In August 1986, a 36-year-old astronomer named Clifford Stoll was given a housekeeping task. The accounting system at Lawrence Berkeley National Laboratory, which billed researchers for computing time, was off by 75 cents. Find the bug.
Stoll had just lost his position at an observatory to budget cuts and taken a systems job he was only partly qualified for. He was an astronomer who happened to be comfortable with Unix. He was not a security person, because in 1986 there was essentially no such job.
Seventy-five cents. Nobody cared about the money. It was the kind of task you hand a new hire because it is real, harmless, and will teach them the system.
Ten months later, it ended with the arrest of a West German hacker selling American military network access to the KGB.
Why the Error Mattered
The lab's accounting kept two independent records of computing time. They should have agreed. They differed by 75 cents.
The obvious explanations were rounding, a missed decimal, a bug in one of the two programs. Stoll checked those and found them clean. What he found instead was an account belonging to a user named Hunter — a name with no corresponding person, no billing address, and no reason to exist.
That is the whole insight, and it is worth stating plainly: the discrepancy was not a bug. It was a record of activity nobody had authorized, showing up as a rounding error because the person generating it was small and careful.
Stoll could have deleted the account. Most administrators would have. Instead he decided to watch.
Watching, With Printers
The lab was connected to MILNET and ARPANET, the precursor networks to the internet, joining research institutions and military installations. In 1986 the operating assumption on those networks was collegial: everyone on them was a researcher, and security amounted to a password.
Stoll wired printers to the incoming lines and let them run, capturing every keystroke of every session on continuous-feed paper. He slept on the floor of his office to catch sessions overnight. He filled boxes with printouts and read them line by line.
The picture that emerged from that paper was not a curious student.
The intruder moved with discipline. He escalated privileges using a flaw in the GNU Emacs movemail utility — a program installed with elevated permissions that could be persuaded to overwrite files it should never have touched — and used it to install himself as a superuser. He set up hidden accounts. He cleaned logs. He came in through Berkeley and then out again to other machines, treating the lab not as a target but as a waypoint.
And his searches gave away his purpose. He was not browsing. He was running keyword searches across the machines he reached: SDI, Strategic Defense Initiative, NORAD, nuclear, missile. He was doing collection.
Over months, Stoll watched him reach dozens of systems — military bases, defense contractors, research institutions — usually by walking in through default passwords that had never been changed and trust relationships between machines that assumed everyone was a friend.
Nobody Wanted the Case
The most quietly damning part of the story is what happened when Stoll tried to report it.
He called the FBI, which was not interested; no clear financial loss, and the amount at issue was 75 cents. He called the CIA, which does not operate domestically. He called the NSA, the Air Force, the Department of Energy. He was passed between agencies, each of which had a plausible reason it was somebody else's problem.
There was no procedure, because there was no category. An ongoing intrusion into military-connected systems by a foreign actor did not map onto anyone's jurisdiction in 1986. The institutional response to the first known case of computer espionage against the United States was a shrug distributed across a dozen agencies, and it lasted the better part of a year.
The Accidental Spy Catcher
So an astronomer with printers and a notebook ran the investigation himself.
The First Honeypot
The technical obstacle was time. Tracing an international call in 1986 was manual: technicians physically attached monitoring equipment at each switching point, noted the incoming line, and phoned the next exchange down the chain. A trace across several countries could take an hour. The intruder's sessions lasted minutes.
Stoll needed him to stay online long enough for the trace to complete, so he built something to hold his attention.
He invented a fictional government program — SDINET, a plausible-sounding Strategic Defense Initiative network — and filled a directory with hundreds of pages of official-looking bureaucratic documents about it. Budget memos, personnel rosters, forms. Deliberately tedious, deliberately voluminous, and containing nothing real. He added an address where a curious party could write to request more information.
The hacker found the files and stayed to read them. Session lengths went from minutes to hours. The traces completed, hop by hop, through the phone system and across the Atlantic.
Then a letter arrived at the fake address, from someone in Pittsburgh requesting the SDINET documents. The bait had been passed to somebody working for an intelligence service, which converted a network intrusion into a counterintelligence case with a paper trail.
This is the first documented deception system in computer security. Every honeypot, canary token, and tripwire deployed since is a descendant of a fake government program invented by one man to keep an intruder on the line.
Markus Hess
The traces led to Hannover, West Germany, and to Markus Hess, part of a small group of hackers who had been breaking into networks and selling what they found to the Soviet KGB for money and drugs.
The German investigation ran to prosecution. Hess and two others were convicted of espionage in 1990 and received sentences that most observers considered light. A fourth associated figure, Karl Koch, was found dead in a forest in 1989, burned, in circumstances officially ruled suicide and argued about ever since.
Stoll wrote the case up first as a technical paper and then as The Cuckoo's Egg, which became a bestseller and remains one of the few genuinely readable books about a computer investigation.
What It Established
Three things, all of which we are still living inside.
Networks were a target, not just a resource. Before this, network security was treated as a matter of keeping honest users from making mistakes. This case demonstrated a foreign intelligence service systematically collecting through them, and did it with evidence rather than speculation.
Detection is an accounting problem. The intrusion was not caught by a security product, because none existed. It was caught because two records that should have matched did not, and one person refused to accept the discrepancy as noise. That remains the actual foundation of detection: knowing what normal looks like precisely enough that a small deviation is visible.
Deception works. When you cannot catch an adversary in the time available, you can change how long they stay.
And underneath all of it, the thing that makes the story last: the case was solved by someone with no authority, no budget, no mandate, and no relevant job title, who was handed a trivial task and decided that the numbers not adding up was, by itself, worth an answer.
The Accidental Spy Catcher: How an Astronomer Found the KGB Online follows the whole investigation — the 75 cents, the printouts, the agencies that passed, the honeypot, the trace to Hannover, and the trial that followed.







