"FREE PIZZA IN THE BREAK ROOM" Was a Cyberattack and Nobody Noticed
In 1999, a bored college sophomore typed net send * "WINDOWS IS SHUTTING DOWN PLEASE SAVE YOUR WORK" into a command prompt and watched an entire computer lab erupt in panic. He thought he was just being funny. He was actually writing the first draft of a $20 billion criminal industry.
Net Send was a Windows command-line utility that broadcast a text message to every computer on a local network. It required no authentication. It required no special software on the receiving end. It popped up a dialog box that looked, to the uninitiated, like an official Windows system message, because it was an official Windows system message — just one that any idiot with access to a command prompt could trigger.
Microsoft shipped this feature intentionally. It was designed for network administrators to push alerts to users. "Server going down at 5pm. Save your work." That kind of thing. What Microsoft did not fully anticipate — or did anticipate and decided was someone else's problem — was that every college kid with a computer lab login also had access to a network administration tool with zero access controls.
The Classic Playbook, Annotated
Let's walk through the canonical Net Send prank, because the steps map almost perfectly onto a modern social engineering attack, and the parallel is not subtle once you see it.
Step 1: Craft a message that implies authority or urgency. "IT DEPARTMENT: Your password expires in 5 minutes. Please log out and log back in immediately." In 1999, this was a prank. In 2024, this is a phishing SMS sent to hospital employees that results in a ransomware deployment.
Step 2: Exploit the user's assumption that system messages are legitimate. The Net Send dialog box had the Windows logo on it. It came from the operating system. Users in 1999 had been conditioned to do what Windows told them, because Windows was the authority figure of the digital world. The attack worked because the delivery mechanism was trusted, not the content. Sound familiar? It should. It's exactly how macro-enabled Office documents worked in the early ransomware era.
Step 3: Create time pressure. "SHUTTING DOWN IN 60 SECONDS." Urgency bypasses critical thinking. This has been documented in social psychology since the 1970s and weaponized in cybercrime since approximately the moment cybercrime became a profession. The college kids running Net Send pranks in computer labs had independently reinvented a core principle of con artistry.
Step 4: Watch the chaos and learn from it. This is the part that doesn't get discussed enough. The kids who ran these pranks were, whether they knew it or not, conducting user behavior research. They were learning which messages caused panic, which caused compliance, which caused people to immediately call IT. They were A/B testing social engineering vectors in a live environment with real subjects.
From Dorm Room to Dark Web
Net Send died in Windows Vista, killed by the firewall defaults that Microsoft finally turned on by default after roughly a decade of watching the internet get absolutely destroyed by worms that propagated through exactly the kind of unauthenticated network messaging that Net Send exemplified. Messenger Service — the Windows background process that received Net Send messages — became a spam vector almost immediately after spammers figured out you could send them over the internet to any machine with the port open, which in the early 2000s was most of them.
You'd be sitting there playing Counter-Strike and a dialog box would pop up advertising a mortgage refinancing service. From a server in Ukraine. Through a port that Microsoft had left open because network administrators might need it. This was not a sophisticated attack. It required no malware, no exploit, no social engineering. It just required that Windows trusted the network by default, which it did, because it was designed in an era when "the network" meant the office LAN and not the entire planet.
The spam problem got bad enough that security researchers started writing about it seriously. Which meant that the people reading those security write-ups — including some who were not researchers — started understanding exactly which Windows services were exposed, which ports were open, and what you could do with unauthenticated access to a messaging system.
The Unwritten Curriculum
Here's the uncomfortable thesis: the Net Send era was an accidental security education program, and it taught different lessons to different people.
The IT administrators who had to deal with the fallout learned to segment networks, disable unnecessary services, and treat unauthenticated access as inherently dangerous. Some of them went on to build the security infrastructure that protects large organizations today.
The kids running the pranks learned that humans are the weakest link, that authority is a costume anyone can wear, and that the gap between a funny joke and a serious attack is mostly a matter of intent and scale. Some of them went on to build the attack infrastructure that threatens large organizations today.
The net send * "Server maintenance tonight, please email your password to [email protected] for account verification" prank was the primordial soup from which a thousand phishing templates eventually crawled. Nobody documented it. Nobody wrote it up in a conference paper. It was just a thing that happened in computer labs across America, repeated thousands of times, teaching lessons that nobody was officially teaching.
The Ransomware Connection
Modern ransomware operations — the ones that hit hospitals and pipeline companies and school districts — rely on social engineering as a primary initial access vector. Somebody clicks a link. Somebody enters credentials into a fake login page. Somebody, somewhere, gets a message that looks official and does what it says.
The message doesn't need to come from an OS dialog box anymore. It comes from a spoofed email address, a cloned website, a text message with a fake tracking number. The delivery mechanism has evolved. The underlying principle — manufacture authority, create urgency, exploit trust — has not changed one single bit since some guy in a computer lab typed net send and watched people frantically save their CS homework.
The prank was the proof of concept. The ransomware is the production deployment.
We're not saying those college kids invented cybercrime. We're saying they independently discovered it, in dorm rooms and computer labs across America, armed with nothing but a Windows command prompt and too much free time. Which is, when you think about it, exactly how most of the internet got built.