---
title: "Cybercrime doesn't Follow Regulations - Part II: the Evolution of Hacking"
description: We started this series with lessons from the past and looked at the fight of regulations against cybercrime. We saw that regulations have evolved and become better and better – but so has hacking. So now let’s take a look at how we got here.
image: https://insights.comforte.com/hubfs/blog_cybercrime%20doesnt%20follow%20regulations%20(2).jpeg
---

[![Hubspot_blog_logo](https://insights.comforte.com/hs-fs/hubfs/Hubspot_blog_logo.png?width=295&name=Hubspot_blog_logo.png)](http://www.comforte.com)

[![Subscribe](https://no-cache.hubspot.com/cta/default/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/ba125972-4bdc-4e47-b9a9-81df496120a0)

[![blog_cybercrime doesnt follow regulations (2)](https://insights.comforte.com/hubfs/blog_cybercrime%20doesnt%20follow%20regulations%20(2).jpeg)](https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-ii-the-evolution-of-hacking)

[Felix Rosbach](https://insights.comforte.com/author/felix-rosbach) l Sep 18, 2018 l [GDPR](https://insights.comforte.com/tag/gdpr), [PCI DSS](https://insights.comforte.com/tag/pci-dss), [Data Protection](https://insights.comforte.com/tag/data-protection), [Compliance](https://insights.comforte.com/tag/compliance)

# Cybercrime doesn't Follow Regulations - Part II: the Evolution of Hacking

There is a basic question we want to answer in this series: Is it really true that “compliance isn’t security”?

We started with [lessons from the past](https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-i-lessons-from-the-past?hsLang=en) and looked at the fight of regulations against cybercrime. We saw that regulations have evolved and become better and better – but so has hacking. So now let’s take a look at how we got here.

[Part I: Lessons from the Past](https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-i-lessons-from-the-past?hsLang=en)  
[Part III: What's Next?](https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-iii-?hsLang=en)

## The origins of hacking – the good old days & how hacking has evolved

Hacking has always been there - since the beginning of information technology there have been those trying to disrupt it. In the early days, most hackers were just breaking stuff for fun.

It all started in 1903 when Nevil Maskelyne, a magician and inventor, interrupted a presentation of a wireless telegraph by sending insulting Morse code messages. Just a few decades later, Alan Touring was brute-forcing Germany's enigma machine for military purposes in 1939 and  in the late 40s, John von Neumann described the theory of self-reproducing computer programs, what we refer to today as viruses.

From the 50s to the 70s, hacking was mostly reserved to local systems and individual penetration.

By 1981, the New York Times described hackers as: “technical experts; skilled, often young, computer programmers, who almost whimsically probe the defenses of a computer system, searching out the limits and the possibilities of the machine. Despite their seemingly subversive role, hackers are a recognized asset in the computer industry, often highly prized”.

After an increasing number of break-ins into corporate and government computers, the US Congress passed the Computer Fraud and Abuse Act, which finally made it a crime to break into systems in 1986.

But hacking didn’t stop. And even with all the regulations in place and all the security technology available - the impact of breaches has grown significantly since the 80s, and it’s still growing – here are a few examples:

![cf_timeline_hackers](https://insights.comforte.com/hs-fs/hubfs/cf_timeline_hackers.png?width=3887&name=cf_timeline_hackers.png)

- In 1988 the First National bank of Chicago was the victim of $70-million computer theft
- In 1994 Russian hackers siphoned $10 million from Citibank
- In 1997 we had the first high profile attacks on Windows machines
- In 2003 the hacktivitst group Anonymous was formed and started with attacks to force organizations, companies, and governments to acknowledge their ideas
- In 2005: North Korea claimed to have trained 500 hackers who successfully cracked South Korean, Japanese, and their allies' computer systems
- In 2010 Google publicly revealed that it had been the victim of a "highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google"
- In 2015 the records of 21.5 million people, mostly US citizens, including dates of birth, addresses, fingerprints, and social security numbers, were stolen from the United States Office of Personnel Management. Press reports indicated that government sources believed the government of China was responsible for the attacks.

This is by no means a comprehensive timeline of every data breach from 1988 until 2015. These are just a few select examples to demonstrate how hacking has evolved over time and become increasingly sophisticated.

## Cybercrime today – the balance of powers?

Over the last half century we went from obvious hackers, to criminal organizations  stealing credit card information, and moved on to activists like Anonymous. Today, we have entered the age of cyber warfare. We’ve heard many examples of the West saying Russia, North Korea, or China are the sources of attacks.

And attacks are not only coming from the outside. Edward Snowden showed us that any thought of online privacy is an illusion. Governments are forcing organizations to hand over the private information of their costumers.

In reaction to cyber criminals, hacktivists, and foreign governments, organizations are scrambling to improve security. But how have attacks changed?

## Types of attacks

New and dangerous types of hacks have emerged that have victimized government entities and prominent businesses like Microsoft, Sony, eBay, Yahoo!, Target, and Amazon. Most companies are shocked when they find out that the average time it takes to detect that a breach is 170 days.

Criminals are able to sell hacking as a service either directly by selling software or based in the cloud which has developed over last few years. The underground hacking industry and the legitimate industry are offering pretty similar services.

There are hacking services, there are escrow services, there are ransomware services and they're all very well organized. With $50-100 US you can rent a botnet to attack any website and put it down for hours or days.

In 2018 we are looking at machine learning and IoT – two things that don’t ease the situation. With memory based worms we have very specific malware now. If you have 15 computers attacked by these worms you might be able to recover, but there is no way to recover if you have an enterprise with a complex network and thousands of clients.

While Microsoft pays up to $100k US for discovering a Windows vulnerability or a zero day exploit, criminal organizations pay up to three times that amount. Unethical hackers turn around and sell it to the highest bidder, which leads to bugs and gaps that won’t be fixed for months or years.

## What can we do about all of this?

The famous quote: “Know your enemy and know yourself, then you will not once be defeated in a hundred battles” doesn’t seem to be working here. In the end, it seems to be impossible to know your enemy at all. Hackers are always one step ahead.

But what can we do about it?

In [the next post](https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-iii-?hsLang=en), we will look at the key takeaways and how to find the right data security strategy.

---

| Share this:  | [![LinkedIn](https://insights.comforte.com/hubfs/Social%20Icons/linkedin%20icon.png)](https://www.linkedin.com/shareArticle?mini=true&url=https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-ii-the-evolution-of-hacking&utm_medium=social&utm_source=linkedin) | [![Bluesky](https://insights.comforte.com/hubfs/Social%20Icons/bluesky_logo.png)](https://bsky.app/intent/compose?url=https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-ii-the-evolution-of-hacking&utm_medium=social&utm_source=Bluesky) | ![Twitter](https://insights.comforte.com/hubfs/Social%20Icons/twitter_x_logo-1.png) | [![XING](https://insights.comforte.com/hubfs/Social%20Icons/xing-color2.png)](https://www.xing.com/spi/shares/new?url=https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-ii-the-evolution-of-hacking&utm_medium=social&utm_source=xing) | [![Email](https://insights.comforte.com/hubfs/Social%20Icons/email%20icon.png)](mailto:?subject=Check%20out%20https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-ii-the-evolution-of-hacking&utm_medium=social&utm_source=email%20&body=Check%20out%20https://insights.comforte.com/cybercrime-doesnt-follow-regulations-part-ii-the-evolution-of-hacking&utm_medium=social&utm_source=email) |
| --- | --- | --- | --- | --- | --- |

## Want to know how PCI DSS and GDPR Overlap?

Being aware of the ways in which PCI DSS and GDPR overlap can save time and resources when trying to achieve compliance with both.

Click the button below to get our free white paper "PCI DSS as a Foundation for GDPR Compliance".

[![Download White Paper](https://no-cache.hubspot.com/cta/default/4026697/aea1fd18-c4e0-4e49-8af5-2f3ba7b8a21c.png)](https://cta-redirect.hubspot.com/cta/redirect/4026697/aea1fd18-c4e0-4e49-8af5-2f3ba7b8a21c)

### Related posts

![OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/hubfs/comforte%20AG_blog%20post_AI.png)

 Apr 6, 2023 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [AI](https://insights.comforte.com/tag/ai)

### [OpenAI’s GDPR Travails Demonstrate Need for Data Security-by-Design](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

After several weeks of incredible growth, OpenAI has come in for a bumpy ride of late. First it revealed details of a data breach exposing a significant number of ChatGPT subscribers. Then the Italian data protection regulator (GPDP) became the...

[Read more](https://insights.comforte.com/openais-gdpr-travails-demonstrate-need-for-data-security-by-design?hsLang=en)

![How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/hubfs/Analytics%20on%20Red%20Button%20Enter%20on%20Black%20Computer%20Keyboard..jpeg)

 Aug 4, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [PCI DSS](https://insights.comforte.com/tag/pci-dss) , [Compliance](https://insights.comforte.com/tag/compliance) , [Big Data Analytics](https://insights.comforte.com/tag/big-data-analytics) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [How to Stay Agile and Compliant with Format-preserving Protection for Analytics](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

Cloud-based analytics offer a truly transformative opportunity for global organizations. By extracting insights from data, they are already helping companies better serve their customers, improve operational efficiencies and make better business...

[Read more](https://insights.comforte.com/how-to-stay-agile-and-compliant-with-format-preserving-protection-for-analytics?hsLang=en)

![17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/hubfs/Int_Datenschutz_Strategie_1.png)

 Jan 13, 2022 l [GDPR](https://insights.comforte.com/tag/gdpr) , [Data Protection](https://insights.comforte.com/tag/data-protection) , [Compliance](https://insights.comforte.com/tag/compliance) , [CCPA](https://insights.comforte.com/tag/ccpa)

### [17 Countries with GDPR-like Data Privacy Laws](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

GDPR wasn't the beginning and it certainly won't be the end. Strict data privacy legislation with extraterritorial applicability is appearing in more and more economies across the globe, meaning the list of “GDPR-free” havens is growing shorter by...

[Read more](https://insights.comforte.com/countries-with-gdpr-like-data-privacy-laws?hsLang=en)

### Service

- [Contact](https://www.comforte.com/contact/)
- [About us](https://www.comforte.com/company/)
- [Blog](https://insights.comforte.com/)
- [Press Releases](https://www.comforte.com/company/press-releases/)
- [Career](https://www.comforte.com/company/career/)
- [Resources](https://www.comforte.com/resources/)

### Germany

comforte AG  
Abraham-Lincoln-Str. 22   
65189 Wiesbaden  
Germany

Phone: + 49 611 93199 00  
Fax: + 49 611 93199 05

### Australia

comforte PTY  
Suite 20, 1 Rivett Road  
North Ryde  
NSW 2113  
Australia

Postal Address:   
PO Box 1710  
Lane Cove  
NSW 1595  
Australia

Phone: +61 2 8197 0272

### USA

comforte Inc.  
30 Wall Street, 8th Floor  
New York, NY 10005-2205  
USA

Phone: +1-646-438-5716

### Singapore

comforte Asia Pte. Ltd.   
1 Raffles Place, #19-61 Tower 2   
Singapore 048616

Phone: +65 6808 5507

- [Sitemap](https://www.comforte.com/sitemap/)
- [Legal Notice](https://www.comforte.com/legal-notice/)
- [Privacy Policy](https://www.comforte.com/privacy-policy/)

© comforte AG 2026

<https://x.com/comforteag> <https://www.youtube.com/c/comforte-ag> <https://www.linkedin.com/company/comforte-ag/>