Hard2bit
← Volver al blog

The first cyberattack in history happened in 1834

Por Adrián González · 28 de septiembre de 2026
The first cyberattack in history happened in 1834

The case most often called the first cyberattack in history took place in France between 1834 and 1836. Twin brothers François and Louis Blanc, speculators in Bordeaux, bribed operators of the state-run Chappe optical telegraph at Tours to hide market signals inside official dispatches, so they learned how Paris bond prices had moved before anyone else.

In 1998 Tom Standage of The Economist called the electric telegraph "the Victorian Internet". Years later, writing for the paper's 1843 Magazine, he went further back. Before any wire was strung, France already ran a national data network of semaphore towers, and it had already been compromised by insiders selling access to the highest bidder. The Blanc affair has everything a modern incident report needs: a critical channel, trusted staff who could be bought, data hidden in control traffic, and a legal system with no offence to charge.

What was the Chappe network?

Claude Chappe's optical telegraph linked French cities through a chain of towers set between 5 and 15 kilometres apart. On top of each stood a pivoting beam with two smaller arms, and their positions encoded 98 combinations. Six of those were reserved for operational use, such as end of message or error. An operator watched the previous tower through a telescope, copied its position, and the next tower did the same. A message could cross the country in hours; a mounted courier took days.

The network belonged to the government and private use was forbidden. Financial news from Paris reached the provinces by mail coach, which gave anyone who knew the latest price of the rente (French government bonds paying 3 %) a trading edge in Bordeaux.

How did the Blanc brothers game it?

The twins could not send messages over the network, so they bought the people who ran it. The scheme, as reconstructed from court reporting of the time and Maxime Du Camp's 1867 account, relied on a handful of accomplices and a very low-tech code.

An agent in Paris watched the bond market and sent a parcel to Tours by stagecoach. Its contents were the message: gloves meant the rente had risen, socks meant it had fallen, and some accounts mention coloured ties or scarves. At Tours, a station on the Paris to Bordeaux line, two bribed employees named Guibout and Lucas inserted an agreed symbol into an official dispatch heading south, then immediately sent the service signal for an error. When the dispatch was transcribed at the end of the line, the cancelled symbol was dropped and the government's text arrived intact.

In Bordeaux, Pierre Renaud, a former telegraph official from Lyon, watched the city's tower through a telescope and noted the symbol that every clerk down the line had been told to ignore. Standage compares the trick to typing a character and hitting backspace: the character still travels, it just never appears in the final document. According to La France pittoresque, Guibout received 300 francs a month plus 50 francs per signal, against an official wage of 1.50 francs a day.

Was it insider trading?

Not in the modern sense. The Blancs did not trade on confidential corporate information; the bond price in Paris was public the moment it was set. What they bought was time. They paid insiders to move public information faster than the market could, which makes the affair closer to latency arbitrage than to insider dealing, and a distant ancestor of the private fibre routes and microwave links that high-frequency traders build today.

The distinction matters for risk teams. The asset the Blancs stole was not the data itself but the integrity and exclusivity of a channel. Many organisations still classify and protect information while treating the pipes it travels through as neutral.

How was it caught, and why did they walk free?

The scheme ran from roughly August 1834 to the summer of 1836. La France pittoresque counts 121 false transmissions, a figure we have not been able to check against the court records. It unravelled through people, not technology. Lucas fell ill and died in early 1836, and before he died he confided the secret to a colleague, Cailleteau, hoping he would take over the arrangement. The story reached the management at Tours, who had also noticed that Guibout was living far more comfortably than his colleagues could explain. The Blancs were arrested in August 1836 and spent about seven months in custody.

The trial opened before the assize court at Tours on 11 March 1837. The jury accepted that the signals had been sent and the bribes paid, but found that Guibout had not been corrupted to perform an act of his office, which was what articles 177 and 179 of the 1810 Penal Code required. No law prohibited private use of the telegraph. On 14 March 1837 Renaud was acquitted and the Blancs and Guibout were ordered only to pay costs; one English-language source also mentions fines. The brothers kept their profits, and François Blanc went on to run the casinos of Bad Homburg and, from 1863, Monte Carlo.

Parliament moved within weeks. A law of 2 May 1837 punished anyone who transmitted signals from one place to another without authorisation, "by telegraphic machines or by any other means", with one month to one year in prison and a fine of 1,000 to 10,000 francs. It enshrined the state monopoly on telecommunications, and its open wording outlived the towers.

The pattern has repeated since. In the UK, Robert Schifreen and Stephen Gold broke into British Telecom's Prestel service in 1984 and 1985; the House of Lords upheld their acquittal in 1988 because forgery law did not fit, and Parliament passed the Computer Misuse Act 1990. In the US, Van Buren v. United States (2021) turned on a police sergeant paid to run a licence-plate search with his own valid credentials. The Supreme Court held, 6 to 3, that misusing access you legitimately hold does not "exceed authorized access" under the Computer Fraud and Abuse Act. Spain's criminal code has a similar shape: its computer-intrusion offence (article 197 bis) requires acting without authorisation. Close to two centuries after Tours, the bribed insider remains the hardest case for cybercrime law.

What should a CISO take from the Blanc affair?

Insider risk is a people problem with technical symptoms. No perimeter was breached; the attackers rented legitimate access. The signal that gave Guibout away was lifestyle, not logs. Guidance such as the CISA Insider Threat Mitigation Guide and Carnegie Mellon's Common Sense Guide to Mitigating Insider Threats both pair technical monitoring with screening, segregation of duties and attention to financial pressure or unexplained wealth, the same controls ISO/IEC 27001:2022 lists in Annex A as 6.1 (screening) and 5.3 (segregation of duties). Our glossary entry on insider threat covers the main indicators.

Protect the channel, not only the payload. Every official dispatch arrived word-perfect. A control that validates only the final document would have passed every manipulated message. The modern equivalent is data exfiltration hidden in headers, metadata, padding or traffic a protocol is designed to discard.

Covert channels live in what the system ignores. Strictly speaking, Tours was less steganography than a covert storage channel: a control signal repurposed to carry data. The same idea reappears in DNS tunnelling, image least-significant bits and packet timing, catalogued in MITRE ATT&CK under techniques such as T1048 (exfiltration over alternative protocol) and T1001.002 (steganography). NIST SP 800-53 even has a dedicated control, SC-31, for covert channel analysis in high-assurance systems.

Error rates are telemetry. Nothing suggests the telegraph administration compared how many cancellations each station sent. A simple count per tower might have flagged Tours long before a dying man's confession did. Today that means centralised, protected logs that someone actually reviews, as described in ISO/IEC 27001:2022 controls 8.15 (logging) and 8.16 (monitoring activities) and NIST SP 800-53 AU-6, usually through a SIEM and behavioural analytics (UEBA) that treat "benign noise" as data. If you are deciding what to feed that SIEM, our guide on which logs to send is the practical next step.

Regulation now expects the controls the law once lacked. In the EU, the NIS2 Directive lists human resources security and supply-chain security among the minimum cybersecurity risk-management measures (article 21(2)). Compliance does not catch a Guibout, but it forces the questions that would have.

Sources