Cybersecurity Books: Nonfiction investigations

Journalism and memoirs: real operations, real consequences, and names on the record.

8/20/2026
Cybersecurity Books: Nonfiction investigations
Part 8 of 9: nonfiction investigations

Cybersecurity Books: Nonfiction investigations

Part eight of nine. Journalism and memoirs: real operations, real consequences, and names on the record.

They read like thrillers while giving you what textbooks cannot: the scale, the motivations of each side, and the price of a mistake.

Clifford Stoll. The Cuckoo's Egg (1989)

An astronomer finds a 75-cent discrepancy in the lab's billing and, a year later, ends up on the trail of a spy ring working for the KGB. The first documented hunt for a network intruder in history.

Topics: detection by anomaly, traps and decoys, logging and preserving evidence, dealing with agencies that do not understand the problem, attribution without modern tooling.

Kim Zetter. Countdown to Zero Day (2014)

The full story of Stuxnet: how it was found, how it was taken apart, and what it did to the centrifuges at Natanz.

Topics: zero-day vulnerabilities and the market for them, code signed with stolen certificates, crossing an air gap, attacks on industrial controllers, cyber weapons and the absence of rules for using them.

Andy Greenberg. Sandworm (2019)

The chronicle of the group that cut the power in Ukraine and released NotPetya, which cost the world economy billions.

Topics: attacks on power grids, malware with no way to stop it, compromise of the software supply chain, the collateral damage of state operations, the problem of how to respond.

Nicole Perlroth. This Is How They Tell Me the World Ends (2021)

On the market for zero-day vulnerabilities: who buys, for how much, and what happens when a state hoards holes instead of closing them.

Topics: the economics of exploits, brokers and intermediaries, commercial spyware, the leak of the NSA's arsenal, the conflict between a state's offensive and defensive missions.

Kevin Poulsen. Kingpin (2011)

The story of Max Butler, who took over the market in stolen cards by swallowing the competing forums. Written by a former hacker turned journalist.

Topics: carding as an economy, trust and reputation in criminal communities, hacking the competition, the work of informants, evidence in digital cases.

Nick Bilton. American Kingpin (2017)

Silk Road from the idea to the arrest, told from the founder's side and the investigation's side at once.

Topics: hidden services and cryptocurrency, operational security and how its mistakes accumulate, deanonymisation through old posts, corruption inside the investigating team.

Andy Greenberg. Tracers in the Dark (2022)

The sequel to that theme: how blockchain analysis turned an "anonymous" currency into an instrument of investigation.

Topics: address clustering, deanonymising transactions, seizing crypto assets, investigations into international marketplaces, the limits of privacy in public ledgers.

Joseph Menn. Cult of the Dead Cow (2019)

The history of the group that coined the term "hacktivism" and influenced the industry more than it is usually given credit for.

Topics: vulnerability disclosure and the arguments over responsible publication, early remote access tools, pressure on vendors, the passage of hackers into corporations and politics.

Joseph Cox. Dark Wire (2024)

The FBI launches its own "secure" messenger for criminals and spends three years reading the correspondence of tens of thousands of users.

Topics: trust in closed platforms, a backdoor at the level of the service itself, metadata and the scale of interception, the legal consequences of operations like this.

Edward Snowden. Permanent Record (2019)

A memoir from the inside: what the work of a contractor with maximum access looks like, and how the decision to carry it all out is made.

Topics: how mass data collection systems are built, internal access control and its holes, operational security while preparing a leak, the motivation of an insider.


Read more