☰Series Navigation (13 parts)
Every weapon before 2010 obeyed the same rule. To break a machine, you had to touch it. A bomb, a bullet, a saboteur with a wrench, a spy who cut a wire. The damage was always physical, done by something physical, and the wall around a sensitive facility was built to keep physical things out.
Stuxnet broke that rule. It was software, nothing but a pattern of ones and zeros, and it destroyed a thousand precision machines spinning in a hardened plant that no bomb had touched. That is why it matters, and why it earns its own place in this series. Everything before it was a burglar getting through a wall. Stuxnet was the first time the wall didn’t matter, because the weapon was already inside, delivered by people who thought they were just doing their jobs.
What was Stuxnet?
Stuxnet was a computer worm, a self-spreading program in the same family as the Morris worm that opened this series, but built for a single purpose by people with a nation’s resources behind them. Its target was the uranium enrichment plant at Natanz, in Iran, and the centrifuges there: tall, delicate cylinders that spin uranium gas at enormous speed to concentrate the material used in reactors and, if enriched far enough, in weapons.
Iran’s centrifuges ran under the control of industrial computers made by Siemens, the same kind of controllers that run factories, pipelines and power plants all over the world. Stuxnet was written to find those specific controllers, in that specific configuration, and to wreck what they controlled while telling the people watching that everything was fine. It ignored almost every computer it ever touched. It was hunting for one room in one country.
It worked. Between late 2009 and early 2010, roughly a thousand centrifuges at Natanz, about a tenth of the machines in operation, failed or were pulled out and scrapped. The breakage rate ran far past normal wear. Iran’s scientists spent months watching their equipment die and not knowing why, because the computers on their desks kept insisting the machines were running normally.
Where did Stuxnet come from?
Nobody has officially admitted building it, and I’ll be plain about that. The United States has never confirmed its role, and neither has Israel. What follows is the account assembled by journalists, most prominently David Sanger of the New York Times, and by the security researchers who took the code apart. It is widely reported and broadly accepted, and it has never been formally acknowledged by any government that took part. Treat it as the best available reconstruction, not as a signed confession.
The program was reportedly called Olympic Games. It started under President George W. Bush around 2006, at a moment when the United States and Israel wanted to slow Iran’s nuclear progress without dropping bombs, because a physical strike on Natanz risked a wider war. President Obama reportedly continued and expanded the operation after taking office. The goal was sabotage that looked like bad luck: centrifuges failing often enough to set the program back, in a way Iran would blame on its own faulty equipment instead of on an attack.
Reporting since has filled in more of the delivery. A Dutch engineer, recruited by Dutch intelligence at the request of the CIA and Israel’s Mossad, is said to have helped get the infection inside Natanz by installing compromised equipment. He died in a motorcycle accident in Dubai two weeks after the attack, at 36, a detail that has fed speculation ever since and that I’ll leave as what it is, a detail, because I have no way to know more than that.
What the researchers could prove, from the code itself, is that this was not the work of a lone hacker or a criminal crew. The thing was too expensive.
It burned four zero-day exploits at once, previously unknown flaws that sell on the black market for six figures each, and no criminal spends that arsenal on a target that doesn’t pay. It carried drivers signed with certificates stolen from two real hardware companies. It was tailored to one plant’s exact machinery. Reported development cost ran to around a billion dollars across the agencies involved. Everything about it said state, and the states it pointed to were the two with the motive.
How was Stuxnet discovered?
Here is the irony at the center of the whole story. The most carefully targeted cyberweapon ever built was found because it failed to stay where it was put.
Stuxnet was designed to live inside Natanz and die there. It was supposed to spread quietly among the plant’s machines and never leave.
But at some point a programming change let it copy itself onto a laptop that then left the building, and when that laptop connected to the internet, the worm no longer recognized that its environment had changed. It started spreading the way any worm spreads, machine to machine, across the wider world. It infected more than 200,000 computers globally before anyone understood what it was, doing nothing to almost all of them because none of them was the plant it wanted.
In June 2010, a small antivirus company in Belarus called VirusBlokAda got a call about machines in Iran that kept rebooting for no reason. An engineer named Sergey Ulasen, reportedly at a wedding when the call came, spent the evening on the phone trying to work out what was wrong.
His team pulled the malware apart and realized fast that they were looking at something unlike anything in the catalog: code that exploited an unknown Windows flaw just to spread, and drivers signed with certificates that belonged to legitimate Taiwanese hardware makers. That was the moment they knew it was no ordinary virus.
Word moved through the security world, and the big firms took it apart in public. Symantec published a detailed dossier.
A German control-systems expert named Ralph Langner spent weeks on the payload and worked out the part everyone else had missed: this wasn’t spyware and it wasn’t a normal worm. It was aimed at Siemens industrial controllers, and its purpose was to physically damage whatever those controllers ran. By September 2010, with news that Iran’s centrifuges had been failing, the picture came together. The world was looking at the first piece of software built to destroy physical equipment, and it had been running for months before anyone outside Iran knew it existed.
Why was Stuxnet different from every attack before it?
Three things set it apart, and each one opened a door that has stayed open.
It crossed an air gap. Natanz was not connected to the internet. That was the whole defense, the assumption that a plant cut off from the outside world cannot be reached from the outside world. Stuxnet reached it anyway, and the next article in this series is about exactly how, because the method is the lesson.
It caused physical destruction. Before Stuxnet, a computer attack stole data, wiped drives, or knocked a service offline. Damage stayed inside the machines. Stuxnet reached through the controllers and broke steel, spinning centrifuges past what their rotors could survive until they cracked. It proved that code could do what until then had required a bomb or a saboteur, and it did it to one of the most protected facilities on earth.
And it lied to the operators while it worked. A man who spent twenty years in operations cannot read that part calmly. Stuxnet recorded what normal looked like on the plant’s monitoring systems and played that recording back to the control room while it wrecked the machines. The engineers watched their screens, saw ordinary readings, and had no reason to think anything was wrong until the centrifuges started failing in numbers no normal fault could explain. The instruments they trusted had been turned into liars.
I’ve written before, in my reading of the Hugging Face AI agent attack, that the log is the floor every other control stands on, and when the record lies you have lost the ability to know anything at all. Stuxnet is where that lesson starts. Sixteen years before AI agents were caught falsifying their own activity records, a cyberweapon was already feeding a nuclear plant’s operators a recording of a normal day while the machines died in front of them.
What did Stuxnet accomplish in the end?
Less than the headlines suggest, and I’ll state it plainly.
It destroyed around a thousand centrifuges and it set Iran’s program back, by estimates ranging from months to a couple of years. It did that without a single airstrike, without a soldier crossing a border, and without Iran being able to prove for a long time that it had been attacked at all. On its own terms as a sabotage operation, it worked.
But Iran rebuilt. Enrichment continued. And because the worm escaped and was caught, the secret was out: the code was studied by every government and security researcher on earth, and the techniques inside it went into circulation. The operation bought time and lost the element that made it special. Whether the trade was worth it is an argument that people who know far more than I do still have, and I won’t pretend to settle it.
What is not in dispute is what Stuxnet started. It proved a nation could reach across the world through a computer and break another nation’s infrastructure, and it proved a physical wall could no longer stop that. Every attack in the rest of this series lives in the world Stuxnet made.
The next article takes apart the piece that should worry anyone who has ever trusted a wall: how a weapon crossed an air gap that was supposed to be uncrossable. For the wider view of security and the executives and writers who need to understand it, the cybersecurity hub collects the rest of my work on this.
Frequently Asked Questions
Continue the Series
1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI
