What Was ILOVEYOU? The Love Letter That Took Down the Pentagon
The email said: kindly check the attached LOVELETTER coming from me.
That was it. One sentence, no greeting, no signature, a subject line reading ILOVEYOU, and an attachment called LOVE-LETTER-FOR-YOU.TXT.vbs.
By six o'clock that evening, US time, CERT had reports involving more than 420,000 internet hosts. The Pentagon, the British Parliament, Ford and the International Monetary Fund had all been hit. Several of them switched their mail systems off entirely, because turning email off was the only reliable way to stop it.
Everyone remembers the punchline: people opened an attachment called "I love you" and got what they deserved. That is not what happened. The attachment did not say .vbs. Windows was hiding that part.
What was ILOVEYOU?
ILOVEYOU — also catalogued as VBS/LoveLetter — was an email worm that appeared on 4 May 2000, written in VBScript, which is to say written in a scripting language that shipped with Windows and required no compiler, no toolchain and no particular expertise. It arrived as an email attachment, and when opened it did two things: it damaged files on the machine, and it mailed itself to every single contact in the victim's Outlook address book.
That second part is why it moved the way it did. The Melissa virus, a year earlier, had mailed itself to the first fifty addresses it found. ILOVEYOU mailed everyone. And it arrived from a colleague, a friend, a spouse — someone whose name you recognised, saying they loved you.
Why did people open it?
Because it looked like a text file, and text files cannot do anything.
Windows shipped — and still ships — with a setting called "Hide extensions for known file types" switched on by default. Explorer strips the final recognised extension off the displayed filename. So LOVE-LETTER-FOR-YOU.TXT.vbs appeared on screen as:
LOVE-LETTER-FOR-YOU.TXT
A plain text file. The single most inert thing an email can carry. The .TXT that users could see was not the real extension at all — it was part of the filename, deliberately placed there so that the actual extension would be the one Windows hid.
This is the detail that reframes the whole story. The users were not careless. They were shown a text file and they treated it like a text file. The operating system lied to them, for the sake of a tidier-looking folder.
That setting is still the default in Windows 11 today, twenty-six years later.
What it actually did
Once running, the script made itself persistent — copying itself into the Windows system directories and registering under the standard startup keys so it ran again at every boot. Then it went through the filesystem, and this is the part that is almost always reported wrong:
-
.vbsand.vbefiles were overwritten in place. Gone. -
.js,.jse,.css,.wsh,.sctand.htafiles were deleted and replaced with a copy of the worm. -
.jpgand.jpegfiles were deleted and replaced. Your photographs were destroyed. -
.mp3and.mp2files were hidden, not deleted. Your music was recoverable.
It destroyed people's photographs and merely inconvenienced their music collection, which in 2000 was very much the wrong way round for how anyone felt about their files.
There was a second stage. The worm changed the Internet Explorer home page to point at a file hosted on a Philippine ISP, so that the next time the victim opened a browser they downloaded WIN-BUGSFIX.EXE — a separate password-stealing trojan called Barok. It harvested cached Windows and dial-up credentials and emailed them to an address at a Manila ISP.
That address is how they caught him.
The signature in the code
The author did not obfuscate anything. Sitting in the VBScript, in plain comments, were two lines:
rem barok -loveletter(vbe) <i hate go to school>
rem by: spyder / ispyder@mail.com / @GRAMMERSoft Group / Manila,Philippines
A name, an email address, a group, a city, and a complaint about school. It reads less like a cyberweapon than like something scratched into a desk.
How bad was it?
You will see figures of $5.5 billion, or $10 billion, in almost every account of ILOVEYOU. They are worth understanding before you repeat them.
Every one of those numbers traces back to a single consultancy, Computer Economics of Carlsbad, California, issuing rolling estimates to reporters in the days after the outbreak. The methodology, stated openly at the time, was: roughly 45 million people received the email, multiplied by about $100 of impact each. The firm said $2.6 billion on 5 May, then $6.7 billion on 9 May, then talked about $10 billion. When The Register looked into it in 2002, antivirus companies Sophos and MessageLabs said the firm had never contacted them for infection data at all.
What the US government told Congress was that estimates "ranged from $100 million to over $10 billion" — a spread of two orders of magnitude, with the GAO declining to endorse any point inside it.
Here is what was actually measured:
- CERT had reports involving over 420,000 internet hosts by 18:00 EDT on day one.
- A survey presented to the House Science Committee found that of 62 companies, 98% received it and 65% were infected. For Melissa the year before, the figures were 20% and 15%.
- The Veterans Health Administration counted seven million copies of the message. Health and Human Services counted three million.
- The Social Security Administration took five days to return to full function.
- At least fourteen major US federal agencies were penetrated. NASA reported at least a thousand damaged files.
Those are real numbers from real institutions. They are also more interesting than the invented ones.
Why was nobody ever prosecuted?
Because in May 2000, writing malware was not a crime in the Philippines.
The trail from the stolen-password mailbox led investigators to Manila within days. The National Bureau of Investigation searched an apartment, and attention settled on Onel de Guzman, 23, a dropout from AMA Computer College who had earlier proposed a college thesis on a program to steal internet passwords.
And then the case ran into a wall. There was no computer crime law to charge him under. Prosecutors reached for Republic Act 8484, the Access Devices Regulation Act — a credit card fraud statute — because it was the closest thing available. It did not fit. On 21 August 2000 the Chief State Prosecutor signed a resolution dropping the charges.
The Philippines passed Republic Act 8792, the Electronic Commerce Act, on 14 June 2000. It criminalised hacking and virus distribution. It arrived forty-one days after the outbreak, and laws do not work backwards. The largest malware event in history to that point produced no conviction anywhere in the world.
He explained himself, twenty years later
In 2019, the journalist Geoff White tracked de Guzman down to a phone repair stall in Quiapo, Manila, and published the conversation in 2020.
His account: he could not afford internet access, so he wrote something to steal other people's dial-up passwords. He aimed it at Filipino chat room users at first, because those were the credentials he could actually use. Later he added the self-spreading behaviour, and chose the subject line deliberately — in his words, "I figured out that many people want a boyfriend, they want each other, they want love, so I called it that."
He said he sent it to one contact in Singapore and went out drinking. He learned what had happened when his mother told him the police were looking for a hacker in Manila. "I didn't expect it would get to the US and Europe. I was surprised."
Those are his claims about his own intentions, made two decades after the fact, and they should be read as such. But they describe something more ordinary and more plausible than the master criminal the coverage in 2000 imagined: a broke student who wanted free internet and did not understand what an address book multiplied by an address book comes to.
What actually changed
Microsoft responded fast. The Outlook E-mail Security Update, re-released in June 2000, did two things that are now simply how email works:
It made roughly seventy executable and script attachment types — .vbs among them — invisible and inaccessible inside Outlook, with no way for the user to override it. And it added a consent prompt, with a mandatory delay, whenever any program tried to read the address book or send mail on its own. That second measure exists specifically because of this worm.
It was unpopular. It broke mail merges and CRM integrations, and Microsoft had to re-release it. It also ended mass address-book propagation as a viable technique more or less permanently.
The one thing that did not change is the setting that made the whole thing work. Windows still hides known file extensions by default. You can turn it off in about four seconds, and almost nobody does.
Further reading
- Matt Bishop — Analysis of the ILOVEYOU Worm (UC Davis, 9 May 2000). Written five days after the outbreak; still the clearest technical account.
- CERT Advisory CA-2000-04, Love Letter Worm. The contemporaneous advisory.
- GAO/T-AIMD-00-181 — testimony to Congress on the federal government's response, including the agency-by-agency damage.
- Geoff White — Crime Dot Com (2020), and his write-up of finding de Guzman in Manila.
EXHIBIT 0003 — ILOVEYOU
We put it on a shirt. The filename, exactly as it was, both extensions intact.
Most people who see it will read it as a joke about a love letter. A smaller number will look at where the .TXT sits and understand immediately what the joke actually is.
That's the whole idea.