Back to Blogs

Foundations of Cybersecurity: The history of cybersecurity

The history of cybersecurity

2026-07-24
LearningCybersecurity

Past cybersecurity attacks

Brain virus

In 1986, the Alvi brothers created the Brain virus, although the intention of the virus was to track illegal copies of medical software and prevent pirated lincenses, what the virus actually did was unexpected. Once a person used a pirated copy of the software, the virus-infected that computer. Then any disk that was inserted into the computer was also infected.

The virus spread to a new computer every time someone used one of the infected disks. Undetected, the virus spread globally within a couple of months. Although the intention was not to destroy data or hardware, the virus slowed down productivity and significantly impacted business operations. The Bran virus fundamentally altered the computing industry, emphasizing the need for a plan to maintain security and productivity.

image.png

Morris worm

In 1988, Robert Morris developed a program to assess the size of the internet. The program crawled the web and installed itself onto other computers to tally the number of computers that were connected to the internet. Sounds simple, right? The program, however, failed to keep track of the computers it had already compromised and continued to re-install itself until the computers ran out of memory and crashed.

About 6,000 computers were affected, reprensenting 10% of the internet at the time. This attack cost millions of dollars in damages due to business dissruptions and the efforts required to remove the worm.

image.png

After the Morris worm, Computer Emergency Response Teams, known as CERTs, were established to respond to computer security incidents. CERTs still exist today, but their place in the security industry has expanded to include more responsibilities.

Attacks in the digital age

The LoveLetter attack

In the year 2000, Onel De Guzman created the LoveLetter malware to steal internet login credentials. This attack spread rapidly and took advantage of people who had not developed a healthy suspicion for unsolicited emails. User received an email with the subject line “I Love You”. Each email contained an attachment labeled “Love Letter For You”. When the attachment was opened, the malware scanned a user’s address book. Then, it automatically sent itself to each person on the list and installed a program to collect user infomantion and passwords. Recipients would think they were receiving an email from a friend, but it was actually malware.

The LoveLetter ended up infecting 45 million computers globally and is believed to have caused over $10 billion dollars in damages. The LoveLetter attack is the first example of social engineering.

image.png

The Equifax breach

In 2017, attackers successfully infiltrated the credit reporting agency, Equifax. This resulted in one of the largest known data breaches of sensitive information. Over 143 million customer records were stolen, and the breach affected approximately 40% of all Americans. The records included personally identifiable information including social security numbers, birth dates, driver’s license numbers, home addresses, and credit card numbers. From a security standpoint, the breach occurred due to multiple failures on Equifax’s part.

It wasn’t just one vulnerability that the attackers took advantage of, there were several. The company failed to take the actions needed to fix multiple known vulnerabilites in the months leading up to the data breach. In the end, Equifax settled with the U.S. government and paid over $575 million dollars to resolve customer complaints and cover required fines. While there have been other data breaches before and after the Equifax brach, the large settlement with the U.S. government alerted companies to the financial impact of a brach and the need to implement preventative measures.

image.png

Key terms in this post

Computer virus

Malicious code written to interfere with computer operations and cause damage to data and software.

Malware

Software designed to harm devices or network.

Social engineering

A manipulation technique that exploits human error to gain private information, access, or valuables

Phishing

The use of digital communications to trick people int o revealing sensitive data or deploying malicious software.

Feedback for this post

What do you think about "Foundations of Cybersecurity: The history of cybersecurity"? Leave your feedback below!

Email

hoangminhtri.ngo@gmail.com

Address

Ho Chi Minh City, Vietnam