The Cuckoo’s Egg: How a 75-Cent Error Exposed a KGB Spy
In 1986, astronomer Cliff Stoll noticed a 75-cent difference in billing. The trail led him to a hacker selling data to the KGB. The first story about cyber counterintelligence.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 24 June 2026
- READING TIME
- 13 min read
- TOPIC
- Cybersecurity History
The best stories in our industry do not start with a spectacular break-in. They start with a little thing that bothers someone. In 1986, such a small thing was a difference of 75 cents in computer time billing at Lawrence Berkeley Laboratory. Anyone else would shrug. But the astronomer who was given the task of sorting out this discrepancy was one of those who had to understand. This persistence led him - step by step, over months - to a West German hacker selling American secrets to the KGB. This is the first ever, meticulously documented story about the hunt for a cyberspy. And still one of the best.
Astronomer turned hunter
The hero is Clifford Stoll - an astronomer who, due to lack of a scientific position, ended up in the computer department of a laboratory in Berkeley. When his supervisor asked him to explain a minor difference in CPU time accounting, Stoll treated it as a simple glitch. But the deeper he dug, the less it looked like a mistake. The difference was that someone was using the system without a paid account - someone who shouldn’t have been there.
Instead of simply blocking the intruder (which would be the natural instinct of an administrator), Stoll made the decision that made him a pioneer: he decided to watch. He figured there would be nothing to be learned from expelling the hacker - and following him might reveal who he was and what he was looking for.
Patience instead of blocking
A game of cat and mouse began, conducted using methods that today we would call digital forensics - although no one had a name for it at that time. Stoll:
- He connected printers and terminals to the intruder’s line to record his every keystroke. He spent hours and nights camping in the laboratory, documenting what the hacker was doing.
- Observed how the intruder exploited vulnerabilities in Unix systems (including a classic editor bug and weak passwords) to gain administrator privileges.
- He kept track of where the hacker was jumping next - because Berkeley was just a stop for him. From this machine, he hacked into military networks, databases and institutions across the United States, searching for documents about the military, intelligence and the Star Wars program.
Stoll discovered that he was not dealing with a curious student, but with someone who systematically hunts for state secrets.
The cuckoo’s egg and the trap
Where does the title metaphor come from? The cuckoo places an egg in another’s nest to be raised by unsuspecting birds. The hacker did something similar - he dropped his malicious programs into trusted systems, which unknowingly “parented” his code and gave him access. Hence the “cuckoo egg”.
The biggest obstacle to catching the intruder was time: the hacker connected over the telephone network and international connections, and tracing the source of the connection required him to stay online long enough. So Stoll came up with an idea that became a classic: he created a bait. He came up with a fictitious, tempting government project called “SDINet” and filled the fake account with a pile of attractive-looking but worthless documents. The hacker, lured, spent so much time downloading them that the connection was traced. It was one of the first honeypots in history - traps set for the attacker.
The trail leads to the KGB
The trail crossed the ocean and led to the Federal Republic of Germany. The intruder turned out to be Markus Hess, a hacker from Hannover, operating in a group that sold stolen American data to the Soviet KGB in exchange for money and drugs. What started as a 75-cent case ended up as a Cold War International Espionage Case - the first well-documented case in which a computer hack turned out to be a foreign intelligence operation.
Stoll described the whole story in the book “The Cuckoo’s Egg” (1989), which is still required reading in the industry - because it shows not only the technique, but also the defender’s way of thinking.
Why it’s still important today
This decades-old story was ahead of its time and established the principles we live by:
- An anomaly is a signal, not noise. The whole breakthrough started with the refusal to ignore a little thing. The best defenders are those who ask “why the 75 cents doesn’t add up” rather than rounding up the problem.
- Sometimes it is better to observe than to block immediately. Stoll showed the value of threat intelligence: understanding who and what is looking for is sometimes more valuable than immediately expelling the intruder (although this is a decision that is made consciously and with a plan).
- Honeypots work. The bait set for an attacker is still an effective technique - a clear signal that someone is where they shouldn’t be.
- Cybercrime can be geopolitics. Stoll was the first to document that foreign intelligence could be behind a “hacker”. This is a lesson that the world has since discovered time and time again, right up to Stuxnet and modern state operations.
Lessons for companies
- Collect and review logs. Without a record of what is happening in the systems, you will not notice any anomalies - and Stoll based the entire matter on meticulous logging. This is the foundation of security monitoring.
- React to minor irregularities. An unusual login, strange traffic, an account that shouldn’t exist - take them seriously before they become an incident.
- Consider traps and early warning. Bait accounts and assets that no one is legally using give one of the clearest reconnaissance signals.
- Assume that you may be an intelligence target. Even smaller companies can be a stop in the chain leading to a larger target - OSINT shows what the attacker already knows about you.
Summary
“Cuckoo’s Egg” is proof that big things start with small questions. An astronomer who couldn’t ignore a 75-cent difference single-handedly - with patience, a printer on the line, and some clever bait - unraveled a KGB spy operation before the concept of “cybersecurity” existed. He established principles that are still the core of defense today: treat the anomaly as a signal, collect evidence, understand the enemy, set traps. More than three decades later, his story teaches more about the mentality of a good defender than many textbooks.
Want to build the ability to detect anomalies and respond before a small signal becomes an incident? Get in touch - monitoring, auditing and testing helps you see what others miss.
Frequently asked questions (FAQ)
Who was Cliff Stoll and why is his story so famous? He is an astronomer who accidentally found himself in the computer department of a laboratory in Berkeley and, while tracking down a minor accounting irregularity, discovered a hacker selling data to the KGB. His book “The Cuckoo’s Egg” is famous for being the first to detail the hunt for a cyberspy - and to show the defender’s thinking, not just technique.
What is a honeypot and where does it come from in this story? A honeypot is a trap - a fake, attractive-looking resource set up to attract and expose an attacker. Stoll created one of the first: a fictitious government project full of worthless documents whose downloading would keep an online hacker long enough to trace the connection. To this day, honeypots are an effective early warning technique.
Does it also happen today that foreign intelligence is behind the attack? Yes, and much more often than in the 1980s. State operations (cyber espionage, sabotage) are a common element of the threat landscape today, and they target not only government institutions, but also companies - sometimes as the final goal, sometimes as a stop in the attack chain. Stoll was the first to document it.
What is the practical lesson from “The Cuckoo’s Egg” for my business? Don’t ignore minor anomalies and take care of the logs - without recording the events, you won’t notice the signal. Stoll’s entire case hinged on scrupulous record-keeping and a refusal to round the problem. Today, this translates into monitoring, reviewing logs, responding to unusual events and considering traps that provide early warning.


