The Biggest Hacks That Ever Happened

The internet is a battlefield. And anyone can see everything you’re doing, all the time.
“Anyone” is a big demographic. You can never know how or why some people might decide to do something. There are those among us who do things for good, while others will do it just for the lulz. Some malicious types might even do something for evil, or just to watch the world burn.
What makes a person or group want to break into something? Revenge? Personal gain? Political motivation? We’ve uncovered them all. Here are five of the biggest hacks of all time — and one that hasn’t happened yet.
1 — Kevin Lee Poulsen takes over the phone lines
Kevin didn’t pull off the biggest hacks, but he is certainly one of the biggest hackers around. At the time, Lee Poulsen called himself Dark Dante, and he strove to be a “complete” hacker. So much so that he even learned how to pick locks — a skill that might have come in handy after he was arrested and sentenced to five years in prison.
Dark Dante was a notorious hacker, and the FBI had been building its case for some time before he was finally arrested. So serious a threat was he, and so significant his skills, that he is known as the first American released from prison with a court order banning him from using computers and the internet. A ban that lasted three years after his sentence expired.
His most famous hack kicked off when KIIS-FM, an LA-based radio station, decided to give away a Porsche 944 S2 to the 102nd caller in a phone-in competition.
And the best way to make sure you’re the 102nd caller? That’s right! Take over the radio station’s entire phone network. Which is exactly what Kevin did. Then he rode off laughing into the sunset.
Not quite. Kevin was a wanted man, and the FBI wanted their man, so the FBI started scheming. Mr. Poulsen was so high-profile that he was featured on the TV show “Unsolved Mysteries.”
Except, when they presented Kevin’s story, the show’s toll-free phone numbers (where people would call in to give information about the featured crimes) mysteriously crashed. What are the odds of that?
Kevin learned his lesson and is now an editor at Wired. He also created SecureDrop — a platform for secure communication between journalists and their sources.
2 — Albert Gonzalez steals all the credit cards
Between 2005 and 2007, Albert Gonzalez managed to collect and resell 170 million credit card numbers. That’s not a typo, and to put it in context — that’s half the population of the USA.
If you’re having trouble picturing 170 million credit cards, just look at this guy. Then picture him 169,999,999 more times.
We recently warned about the dangers of an unsecured Wi-Fi setup, and Gonzalez’s scam is one of the reasons why.
Armed with just a laptop, Gonzalez would drive up and down US Route 1, looking for vulnerabilities in public wireless networks. Once he found one, he would attack.
One of his targets, Heartland, reported losing $12.6 million in one of Gonzalez’s attacks. And that’s just one of the many companies involved. It’s not known for sure exactly how many companies Gonzalez hit or how much he stung them for, as many refused to publish details about it. We’re not surprised. It’s pretty embarrassing to get stung over something as silly as not changing the password on your Wi-Fi.
Thankfully, in August 2009, Gonzalez was charged in Newark, New Jersey. And now he’s serving twenty years in federal prison.
But there are more people like Gonzalez out there — people who have the desire and the skill to invade your digital life.
Be sure to protect yourself before you start doing things on strange and public Wi-Fi connections.
3 — Anonymous creates Project Chanology to attack the Church of Scientology
What happens when you cross the most infamous hacker collective in the world with the strangest religion on the planet?
Project Chanology happens.
Like many things on the internet, it started on 4Chan. For those who don’t know, 4Chan is an uncensored and anonymous message board. If you haven’t been there yet and want to check it out, heightened caution is required: it’s not for the faint of heart.
4Chan is the foundation of many internet memes and initiatives, but the crowning achievement of the 4Chan boards is the creation of the infamous hacker group Anonymous. Anonymous is a leaderless hacktivist group and probably the best-known hacker collective that has ever existed.
4Chan started Project Chanology when the Church of Scientology tried to remove material from an interview with Tom Cruise, a prominent member of the church, from the internet.
The church has a long history of censorship, often through aggressive lawsuits, but the biggest protest movement against them was carried out by Anonymous.
Anonymous doesn’t like censorship, especially when it comes from a powerhouse. And they’re also known for taking down a few bullies. The Church of Scientology certainly ticks those boxes.
And so Anonymous went to work. The hack began with a “Message to Scientology” on YouTube on January 21, 2008. Anonymous voiced their displeasure with the Church’s actions and stated their intent to fix it.
There followed a series of distributed denial-of-service (DDoS) attacks, prank calls, and black faxes.
The full extent of the damage to the Church of Scientology is unknown, as they are a quiet bunch. But given the resources Anonymous threw at them, it must have been heavy.
Not everything Anonymous does is great; after all, they’re just normal people. But they have the power to do great things — if they’re so inclined.
A lovely dinner of lettuce, tomatoes, spam, spam, spam, and spaaaam.
4 — Spamhaus, the biggest DDoS cyberattack in history
Spamhaus is an email filtering service that people use to weed out spam emails.
The service is especially popular in the UK, where it works in the background of many systems that determine whether to accept incoming emails or not.
On March 18, 2013, Spamhaus added Cyberbunker to its blacklist. Cyberbunker is a hosting site, and they were cut off entirely from traffic by Spamhaus. Cutting existing or new customers off from your communications is not good for business.
Despite communications, Spamhaus refused to remove Cyberbunker from the blacklist. So Cyberbunker responded in kind: “If you stop us from communicating with our customers, we’ll stop you from communicating with yours.”
And so Cyberbunker hit Spamhaus with a DDoS attack. DDoS attacks work by clogging a server with fake data requests. The equipment soon strains, and if the attack is big enough, it can shut down completely.
And oh boy, Cyberbunker’s attack was definitely big enough. It’s fair to say things escalated quickly.
What started as a light DDoS grew exponentially in size until at one point Spamhaus was hit with 300 Gbps (gigabits per second).
That hit was so massive it slowed down the internet across all of Europe.
And then Sven Olaf Kamphuis, a spokesperson for Cyberbunker’s executive director, went on the run, as he was wanted by the internet police for the DDoS attacks.
Kamphuis was eventually caught and arrested. We guess he didn’t want to take things as far as they went. But as we said before: be careful what you do on the internet. It could come back to bite you.
If you live on Earth, pay attention. The next entry is for you.
5 — The Saudi Aramco hack affected the whole planet
We’ve all heard of the Sony and US government hacks. But they don’t even register on the scale compared to the attack on Saudi Aramco.
Saudi Aramco is the biggest company you’ve never heard of. They’re a huge oil company from Saudi Arabia, with profits bigger than the GDP of most countries. They were also the victim of the biggest corporate hack in history.
The hack started sometime in mid-2012, when someone on Saudi Aramco’s IT team opened a bad link in an email. That was all the hackers needed to get in.
The actual attack happened during the Islamic holy month of Ramadan, when many Saudi Aramco employees were on holiday. On August 15, 2012, some employees noticed their computers behaving strangely. A few screens started flickering and, more worryingly, files started disappearing. Some computers even shut down without explanation.
Saudi Aramco’s IT team soon realized what was happening and frantically began pulling all the computers off the internet. But it was too late.
In just a few hours, approximately 30,000 computers were either badly damaged or completely destroyed.
Since Saudi Aramco supplies ten percent of the world’s oil, this hack could have led to a global catastrophe. If they lost the ability to deliver that oil, the effects would surely be felt all over the planet.
So Saudi Aramco did the only thing they could: they broke out the paper and pens. The entire company went back in time, to the ’80s. Reports were done on typewriters and communications sent by fax.
Buy all the computers in Southeast Asia
Using archaic technology was a short-term fix, but it couldn’t go on forever. Saudi Aramco had to replace all its hardware. And so they did. All at once.
If you purchased computer hardware between September 2012 and January 2013, you had to pay a higher price for it. That’s because Saudi Aramco bought everything, which put enormous strain on the computer industry. This is no exaggeration; it actually happened.
Saudi Aramco flew representatives to computer factory floors in Southeast Asia and had them buy every computer hard drive currently on the production lines. Saudi Aramco had to pay a hefty premium to jump the queue, and they bought over 50,000 units in one go.
The computer factory line after Saudi Aramco left.
A political group called the “Cutting Sword of Justice” claimed responsibility for the attack. Although, from what we know, nobody ever faced trial. Most details were kept secret — the full scope of the hack is only trickling out.
It took Saudi Aramco over five months to fully recover from the hack. Thankfully, they were able to keep delivering oil, even though their systems were in survival mode. If they hadn’t been able to, things could have been much worse.
Hacking isn’t just something for gamers and IT guys to worry about. It’s a serious threat to everyone. Even you.
6 — Apple is forced to hack itself
In a curious twist, potentially the biggest hack of all time hasn’t happened yet. But a court is insisting it happen.
Recently, a judge in California ruled that Apple must hack itself.
It all started with the San Bernardino shootings last December. The FBI wants to gain access to one of the perpetrators’ encrypted iPhones and has ordered Apple to hack it. Apple doesn’t want to do this, as it could potentially open a backdoor to every iPhone out there. Over 700 million iPhones have been sold, so this would be a hack of epic proportions.
For now it hasn’t happened, and we hope Apple stands up against the ruling. It sets a dangerous precedent.
We’re also not alone in supporting Apple’s decision. Some big hitters have voiced support for Apple — including major competitors like Google.
Where to from here?
Many of these attacks were carried out by skilled hackers, some were just DDoS attacks. But all of them were born from different motivations. Attacks can happen at any time, for any reason.
Innocent people get sucked into the mess caused by the few, and these tales are testament to the fact that anyone can be a victim.
You can limit the risk to yourself with a little common sense and by improving your security. Why not take a little time today to check your Wi-Fi settings? And how long has it been since you changed your passwords? If it’s been a while, we recommend getting a new one with ExpressVPN’s random password generator.
Maybe it’s time to review your security settings, so you don’t end up featured in our next blog!
Featured image: Krasimira Nevenova / Dollar Photo Club
Man with credit card: stockyimages / Dollar Photo Club
Spam, spam, spam: yasuhiro / Dollar Photo Club
Earth: Robert / Dollar Photo Club
Empty factory: Komarov Andrey / Dollar Photo Club

