Picture this: it's May 2021, and gas stations up and down the US East Coast are running dry. People are filling plastic bags with gasoline. Panic buying, news choppers, a state of emergency. And the whole thing traces back to one login. One password. No second factor.
Start at the beginning, 1988. A Cornell grad student named Robert Morris writes a program just to see how far it can travel across the early internet. He's not malicious. He's curious. He miscalculates one variable, and the thing spirals past what he intended, chewing through roughly 6,000 machines, choking universities and government networks that had never seen anything like it.
Here's the part that got under my skin: the flaws Morris exploited weren't exotic. They were boringly simple. And thirty-seven years later, I kept finding the exact same shape hiding underneath every "sophisticated" headline. Strip away the drama, and it's almost always a door somebody forgot to lock.
A password with nothing behind it
Now go back to that gas line. Colonial Pipeline, the artery that moves 45% of the East Coast's fuel, got taken down by a single VPN account — a password that had been quietly circulating on the dark web for who knows how long. No multi-factor authentication. Nothing standing in the way. The attackers never even touched the physical pipeline systems. The company shut everything down anyway, out of sheer precaution, and the country felt it within days.
Then there's Change Healthcare, 2024. Same story, bigger number: a remote-access portal with zero MFA, a stolen login, and nine full days where nobody noticed a stranger was inside. By the time it ended, roughly 190 million people had their data exposed, a $22 million ransom got paid, and the total bill blew past $2.9 billion. Nine days. That's how long it takes for a quiet break-in to become a national headline.
I kept waiting for the "aha, that's genius" moment in these stories. It never came. What came instead was a kind of dread — because the fix, every single time, was something almost surprisingly small.
The patch that already existed
Here's where it gets worse. Zero-day exploits — the mysterious, undiscovered flaws — get all the glory in movies and headlines. But dig into the actual damage, and you find something quieter and more damning: patches that already existed, sitting there, unapplied.
WannaCry, 2017. It tore through more than 150 countries in a matter of days, using a Windows exploit called EternalBlue — originally built by the NSA, later leaked to the world by a group called the Shadow Brokers. Microsoft had shipped the fix two months before the attack. Two months. The UK's National Health Service still got hit hard enough to cancel thousands of appointments and surgeries.
Equifax, that same year, follows an almost identical script — a known, already-patched flaw in Apache Struts. Except this time there's a second twist: the tool meant to watch for exactly this kind of intrusion had an expired security certificate, so the breach ran undetected for 76 days. Seventy-six days of a stranger quietly walking out with the Social Security numbers of 147 million people.
Two months. Seventy-six days. Nine days. I started noticing myself counting the days in every one of these stories, because that gap — between "the door was open" and "someone finally noticed" — is where all the real damage happens.
One broken lock, a thousand open doors
And then there's the part that genuinely unsettled me: you don't even have to be the target anymore.
SolarWinds. Attackers didn't break into 18,000 organizations one by one. They broke into one software company's build process, planted a backdoor inside a legitimately signed update, and let those 18,000 organizations — including US federal agencies — install the malware themselves, willingly, thinking it was routine maintenance.
MOVEit did the same thing on a different scale. Over 2,500 organizations got swept up, many of them — British Airways, the BBC — never touching the software directly. They were just standing near someone who did.
That's the moment this stopped feeling like "other people's problem." If your security depends entirely on your own systems, you're not looking at the whole board. Somewhere down your vendor chain, there's a door you've never even seen.
Okay, but is it really this hopeless? (it's not)
I want to be honest about something, because the story I've just told you is a little rigged. Every single case here made this list because the defense failed. What you never hear about are the thousands of near-identical attempts that got stopped cold — by MFA that was actually turned on, by a segmented network, by a log file someone actually read that morning. Those don't make headlines, so they don't make lists like this one. After WannaCry, patching discipline visibly tightened across plenty of organizations. After Equifax, penalties got sharp enough to change board-level priorities. This isn't a story of a species that never learns — it's a story of a species that learns exactly as fast as it's forced to, no faster. And now there's a new frontier already opening: AI-written phishing that's harder to spot than anything on this list.
What's actually chasing you
So here's what I walked away with, and it's not comforting: almost none of these disasters required a genius. Not one needed some unstoppable, undiscoverable weapon. Every single one of them was a door somebody left open — an account with no second lock, a fix that shipped and sat there unused, a log nobody was watching. Ordinary. Preventable. Almost boring.
Which might be the most unsettling part of all. We keep imagining the threat as something dazzling and futuristic. But if you trace every one of these stories back to its actual root cause, it's never the future. It's just Tuesday, and somebody forgot to turn something on.





Comments
Post a Comment
Got a thought or a question about this? Leave a comment.