Stuxnet
The computer worm discovered in 2010 that physically destroyed Iranian centrifuges, the first cyberattack to break real machinery and the moment code became a weapon.

In June 2010 a small Belarusian antivirus firm was called to look at Iranian computers that kept crashing and rebooting. What they found, and what researchers at Symantec and elsewhere then spent months pulling apart, was a piece of software unlike anything seen before: enormous by malware standards, using four previously unknown Windows vulnerabilities at once, carrying stolen digital certificates from two legitimate Taiwanese companies, and designed to do nothing at all on almost every machine it infected.
It was hunting for one specific configuration of industrial equipment. When it found it, it broke it.
What it did
The target was the uranium enrichment plant at Natanz. Centrifuges spin at enormous speeds to separate uranium isotopes, and they are mechanically delicate: they must run within a narrow band of rotational speed or they tear themselves apart.
Stuxnet infected the Windows machines running the Siemens software that programmed the controllers governing those centrifuges. It checked whether the frequency converters were operating in the specific range used by Iranian machines, and only then activated. It then periodically drove the rotors far above and below their safe speeds, while simultaneously replaying recorded normal readings back to the control room and to the safety systems.
That last part is the innovation. The operators watched screens showing everything was fine while the machines destroyed themselves. Iranian engineers spent months replacing centrifuges without understanding why they kept failing, and reportedly suspected sabotage, defective parts, and their own staff before anyone suspected software. Estimates suggest around a thousand centrifuges were wrecked.
Natanz was air-gapped, physically disconnected from the internet. Stuxnet crossed that gap on USB drives, spreading widely and harmlessly through ordinary computers until one was carried inside.
Who did it
No government has admitted it. The overwhelming consensus of security researchers and subsequent reporting is that it was a joint American and Israeli operation, reportedly codenamed Olympic Games, begun under George W. Bush and continued under Barack Obama.
The logic behind it was straightforward. Israel wanted Iran's program stopped and was prepared to bomb it. An airstrike meant a regional war. Sabotage that looked like malfunction offered a way to buy years without a single acknowledged act of war.
Why it mattered more than the damage
The centrifuge losses were real but recoverable, and Iran's enrichment capacity was larger three years later than before.
The significance is categorical. Before Stuxnet, cyberattacks stole information, defaced websites, or knocked services offline. Stuxnet destroyed physical objects. It established that code could do what previously required a bomb, and it did so with no aircraft, no casualties, and no attributable signature, which makes it the first genuine cyberweapon in the ordinary sense of that word.
It also escaped. The worm spread far beyond Natanz, turning up in tens of thousands of machines around the world, which is how it was found. A weapon that propagates on its own does not stay in the target country, and every state's investigators then got a free, working master class in how to build one.
The echo
The world it opened is now routine. Industrial control systems are a standard target: Russian operations shut down parts of the Ukrainian power grid in 2015 and 2016, the NotPetya attack in 2017 did billions of dollars of collateral damage worldwide, and ransomware against pipelines and hospitals is now ordinary crime using techniques that were once state-level.
Two problems Stuxnet created have no solution yet. Attribution is slow, contested, and deniable, which makes deterrence, a doctrine built on the certainty of return fire, very hard to apply. And the tools do not stay with their authors; they are copied, reverse-engineered, and reused within months.
The United States built the first one because it had the best capability. It also has the most exposed infrastructure of any country on earth, which is the uncomfortable arithmetic underneath every subsequent decision in this domain.