The Emergence of Cybercrime 1990s

The 1990s brought the internet out of research labs and into homes and offices. With millions of new and inexperienced users arriving online through commercial services, the opportunity for deception grew quickly. Early schemes targeted popular online service platforms, where small groups manipulated account systems and free-trial mechanics. This period also overlapped with phone phreaking culture, a hobbyist fascination with telephone networks that blended curiosity with rule-breaking and helped seed later computer crime communities.

As email became universal, so did its abuse. The Melissa virus, which spread rapidly in 1999, used infected documents and a victim's own address book to mail itself onward. It did not steal data or destroy systems, but it overwhelmed mail servers at major organizations and demonstrated how social trust could be weaponized at scale. Around the same time, the earliest phishing messages appeared, impersonating trusted services to trick people into revealing passwords and account details.

Defenders responded with new tools and new thinking. Firewalls, which filter traffic between a trusted internal network and the open internet, moved from niche deployments to standard practice during this decade. Organizations began to treat security as a continuous responsibility rather than a one-time setup.

By the end of the 1990s, cybercrime was no longer only the work of lone hobbyists. Financially motivated actors began to coordinate, laying the groundwork for the organized criminal networks that would define the following decades.

References#

  • CISA, resources on phishing awareness and the evolution of email-based threats.
  • NIST Special Publication series on firewall technology and network security principles.

Cookie Consent

We use cookies to enhance your experience. Learn more