Skip to content

The KGB Hack: Karl Koch, Markus Hess, and the Cuckoo's Egg

Abstract

In 1986, an astronomer-turned-sysadmin at Lawrence Berkeley National Laboratory named Clifford Stoll chased down a 75-cent accounting error in his computer’s billing logs. The error led him, over the next ten months, to an intruder who had quietly broken into hundreds of US military and research computers across the MILNET, and then to the discovery that the hacker was selling what he found to the Soviet KGB. The intruder was Markus Hess, a German hacker working with a small ring of young West Germans connected to the early Chaos Computer Club milieu. Among them was Karl Koch, a brilliant, drug-addicted, conspiracy-obsessed young man who called himself “Hagbard” and who, in 1989, was found burned to death in a forest in a still-disputed apparent suicide. The case was the first documented instance of computer espionage between Cold War superpowers, the first time network intrusion was shown to be a tool of statecraft rather than mischief, and (through Stoll’s bestselling book The Cuckoo’s Egg) the story that taught a generation what an intrusion actually looks like from the defender’s side.

A 75-Cent Error

In August 1986, Clifford Stoll was managing computers at Lawrence Berkeley National Laboratory when he was asked to resolve a trivial discrepancy: the lab’s accounting system, which billed users for connect time, was off by 75 cents. Most administrators would have written it off. Stoll treated it as a puzzle, and the puzzle revealed an unauthorized user who had obtained superuser (root) access and was using the lab’s systems as a stepping-stone into the wider MILNET, the US military’s segment of the early internet.

Rather than simply locking the intruder out, Stoll made an unusual decision: he left the door open and watched, meticulously logging every keystroke, in order to learn who the attacker was and what he was after. Over roughly ten months he documented the intruder breaking into an estimated 400 US military and government computers (at bases, defense contractors, and research institutions) searching specifically for material on nuclear weapons, the Strategic Defense Initiative (“Star Wars”), semiconductors, satellites, and aircraft.

The Cuckoo’s Egg

Stoll’s title is a metaphor for what the intruder did: like a cuckoo that lays its egg in another bird’s nest to be raised by an unwitting host, the hacker planted his code and credentials inside trusted systems that then did his work for him. Stoll’s account, published in 1989, was groundbreaking because it documented an intrusion from the defender’s point of view, in granular operational detail, at a time when almost no one understood what network security even meant. It reads as a detective story and functions as the founding text of practical incident response, including the first famous use of a honeypot.

The Honeypot

The intrusions were real, but proving who was behind them (and getting any agency to care) was its own ordeal. Stoll found the FBI, CIA, NSA, and Air Force Office of Special Investigations initially uninterested: the dollar losses were trivial and jurisdiction was murky. To force the issue and keep the hacker online long enough to trace the transatlantic phone connection, Stoll fabricated a trap. He created a fictitious set of files about a non-existent military project, “SDINET” (a supposed Strategic Defense Initiative network office), and salted his systems with them.

The bait worked spectacularly. The intruder spent hours greedily copying the fake documents, keeping the connection open long enough for technicians to trace the call across the Atlantic, and, later, a letter arrived from someone in Pittsburgh requesting more information about the fictional SDINET project, confirming that the stolen material was being passed to others and, ultimately, to a foreign intelligence service. The trace led to Hanover, West Germany.

Markus Hess and the Ring

The hacker at the keyboard was Markus Hess (handle “Urmel”), a programmer from Hanover. He was not acting out of curiosity: Hess and a small ring of associates were selling the stolen military data to the Soviet KGB for cash and drugs. Hess personally received tens of thousands of Deutsche Marks for his intrusions (figures around $54,000 are cited for his take). The material he exfiltrated was, in intelligence terms, mostly low-grade (unclassified or modestly sensitive documents reachable from networked systems) but the principle was unprecedented: a foreign intelligence service was paying hackers to loot computers over a network from the other side of the world.

The ring around Hess was loosely tied to the explosive early hacker scene in West Germany and the orbit of the Chaos Computer Club. Its members included Dirk Brzezinski (“DOB”), Hans Heinrich Hübner (“Pengo”), and the central tragic figure, Karl Koch.

Karl Koch / “Hagbard Celine”

Karl Koch was born July 22, 1965, in Hanover. As a teenager he took his handle, “Hagbard Celine,” from a character in the cult Illuminatus! trilogy (a gift from his father) and absorbed its paranoid mythology of secret societies battling for control of the world through the number 23 and the forces of “Eris,” chaos. He bought his first computer in 1982 and named it “FUCKUP.” Brilliant and politically restless, he was also, by the mid-1980s, deep into cocaine and amphetamine addiction and a worsening confusion between the conspiracy fiction he loved and the genuine espionage he had drifted into. To Koch, hacking Western military computers and selling to the KGB could feel like a move in the cosmic Illuminatus! game rather than a crime with consequences.

The ring unraveled in early 1989. After Hess’s activities were exposed and German authorities closed in, Koch and Hübner came forward and confessed under a West German espionage amnesty provision, which spared them prosecution in exchange for cooperation.

Two Endings

The two endings of the story could not be more different.

Markus Hess was tried in West Germany and convicted of espionage in 1990, receiving a suspended sentence of around 20 months, a strikingly light punishment that reflected both the novelty of the crime and the modest classification of what he had actually stolen.

Karl Koch did not live to see it. On May 23, 1989, he drove a company car out of Hanover and disappeared. His body was found on June 1, 1989, in a forest near Celle: he had apparently doused himself with gasoline and burned to death, the ground around him scorched. The death was officially ruled suicide, but no note was found, and the timing, a key witness in a Cold War espionage case dying violently just as investigations and the public attention around the KGB hack peaked, has fueled decades of speculation that it was murder. The truth has never been established. Koch was 23, the number that had haunted his Illuminatus!-soaked imagination.

Myth: The KGB hackers stole vital nuclear secrets and gravely damaged US security

The espionage was real and the precedent historic, but the substance of what was stolen is routinely exaggerated. By most assessments, including Stoll’s, the material Hess exfiltrated was largely unclassified or low-sensitivity documents accessible from networked machines; he never cracked genuinely secret weapons data. The case mattered enormously as the first proof that network intrusion could be an instrument of state espionage, not because it handed Moscow anything decisive. See Myths and Misconceptions.

Legacy

The KGB Hack is a hinge in the history of computer security on several axes at once. Technically and operationally, Stoll’s investigation invented much of the playbook of modern incident response, keystroke logging an active intruder, building a honeypot to bait and trace an attacker, and patiently correlating evidence across organizations, and The Cuckoo’s Egg taught it to a wide public in narrative form. Strategically, it was the first documented case of state-sponsored cyber-espionage, the distant ancestor of every later nation-state intrusion campaign, from Moonlight Maze to the APT era. Culturally, through Koch’s death and the 1998 German film 23 dramatizing it, the case became a foundational legend of the European hacker scene and of the Chaos Computer Club’s self-understanding.

Koch and Hess are documented here on the principle of impact, not endorsement: they were paid agents of a hostile intelligence service who treated other people’s systems as merchandise, and the romance that has accreted around Koch’s tragic death should not obscure that. But the history of computing genuinely turns on this episode; it is where the network first became a battlefield between states, and where, thanks to one stubborn astronomer chasing 75 cents, the defenders first learned how to fight back.


📚 Sources