The Michelangelo Virus That Changed the History of Cybersecurity

20.07.2026 14 minutes Author: Lady Liberty

Italy in the 16th century was a dangerous place, and although Michelangelo lived a long life, he witnessed horrors of his time that still exist in our society today. Darkness never truly disappears; it simply takes on new forms, and since the second half of the 20th century, one of those forms has been digital technology. Few could have imagined that the life of a Renaissance artist would influence computers nearly 500 years after his death, but that is exactly what happened in March 1992. It triggered one of the biggest waves of panic in the history of the computer world.

How It All Began

Viruses were nothing new by the 1990s. They had existed almost since the dawn of computing, but as email became more widespread in the 1980s, they began spreading from one computer to another faster than ever before. Traditionally, however, most viruses relied on physical media for transmission. An infected file or boot sector could be copied from a floppy disk to a hard drive or simply loaded into memory, and then spread to another floppy disk. Once that disk was inserted into another computer, the new machine became infected, and the cycle continued. It was nowhere near as efficient as the Internet, but you might be surprised by how quickly such viruses could spread. This was exactly how the Michelangelo virus operated.

The Michelangelo virus was first discovered in February 1991 by Australian antivirus researcher Roger Riordan. He recognized that the new, then-unnamed virus was a variant of the Stoned virus, a relatively harmless piece of code that, using the system clock as a source of randomness, displayed the message, “Your PC is now Stoned!” on roughly every eighth boot. The new virus, however, displayed no messages and gave no warning. It simply carried out its task while remaining unnoticed. Unfortunately, its capabilities were far more dangerous than those of Stoned.

Roger Riordan; Australian expert on antiviral therapy

At a meeting on computer viruses held in the Netherlands in April 1991, which the media often cite as the moment of its discovery, the security community discussed the virus and identified it as a potentially serious future threat. Its malicious payload was designed to activate on March 6 each year, Michelangelo’s birthday. That is why Roger Riordan named it the Michelangelo virus. Of course, March 6, 1991, had already passed by then, but the virus had not yet spread widely, so the damage it caused was minimal.

However, March 6, 1992, which marked the 517th anniversary of Michelangelo’s birth, had the potential to be a very different story. By October 1991, most antivirus programs were already capable of detecting and removing the virus, but software was not updated automatically in those days, and most people did not even realize they should be using antivirus protection. At the same time, personal computers were becoming increasingly popular, while sharing floppy disks and copying files had become commonplace, creating the perfect conditions for the virus to spread.

Just like Stoned and, incidentally, the real Michelangelo, who according to legend slept in his boots, Michelangelo is a boot sector virus. This means it does not run within the operating system, which at the time was DOS. Instead, it executes at the BIOS level on IBM PC-compatible computers based on the AT architecture.

When you turn on a computer, the BIOS controls all system operations for a brief moment. It effectively serves as the gateway to the computer’s hardware, but at a certain point it hands control over to the operating system. To do this, the BIOS reads the first sector of the hard drive, or the floppy disk if one is inserted, and executes whatever it finds there.

If you booted a computer from a floppy disk infected with a boot sector virus, Michelangelo would first load itself into the upper area of system memory, redirecting interrupt 12 to prevent itself from being overwritten. It would then infect the hard drive’s boot sector, relocating the original boot code to cylinder 0, head 1, sector 14. From that point on, every new floppy disk accessed by the computer would become infected with Michelangelo, with its boot sector rewritten as well. In this way, a single computer could very quickly infect a large number of floppy disks. If any of those disks were later used to boot another computer, the cycle would repeat.

For most of the year, relocating the boot sector caused no noticeable problems. However, if the computer was turned on on Michelangelo’s birthday and the system clock showed the correct date, then, as demonstrated by the Danooct1 channel, the user would face a very different outcome.

Once activated, Michelangelo simply overwrote the first 100 sectors of the hard drive with zeros. As a result, the DOS boot sector and the File Allocation Table (FAT), which serves as a map of where data is stored on the disk, were destroyed. Although the data itself physically remained on the drive, the system could no longer determine where one file ended and another began, making recovery virtually impossible for the average user.

Once activated, it was a genuinely destructive virus, and if there was reason to believe it had already spread to a large number of computers, the panic was entirely understandable. And people had good reason to believe that it had.

The Virus Approaches

On January 28, 1992, several news outlets reported that the American computer manufacturer Leading Edge had shipped around 500 computers infected with the Michelangelo virus between December 10 and December 27. Warning customers about the threat, the company announced that it would send them special software to detect and remove the virus. The infection was believed to have originated from a driver floppy disk supplied by a modem vendor. The New York Times also spoke with John McAfee, president of McAfee Associates, who said, “This is an extremely common occurrence. It’s just not very common for it to happen to a company the size of Leading Edge.” These would be far from his last comments on the subject. As a precautionary measure, Osicom Technologies also announced that same day that it would begin shipping an antivirus package with all of its personal computers.

The following day, United Press reporter Jack Lesar wrote that “Michelangelo could erase data on hundreds of thousands of computers around the world,” while Winn Schwartau, director of the International Partnership Against Computer Terrorism, warned, “Normally, a virus cannot spread simply by reading a data disk. But apparently that is no longer the case,” making Michelangelo sound almost like some sinister mythical creature. McAfee also weighed in again, stating, “The Michelangelo virus is the third most widespread virus based on reported infections. It accounts for 14 percent of all infection reports, about 6,000 in total over the past year, and each report may represent anywhere from a single computer to as many as one hundred.”

As February began, the situation only grew worse. On February 3, it was reported that Da Vinci Systems had distributed 900 infected floppy disks during January, and by February 11, McAfee issued yet another statement, this time claiming that 5 million computers worldwide were already infected. It was Reuters reporter Wilson da Silva who brought this alarming figure to the attention of the wider public.

By February 13, the rest of the antivirus industry had grown a little jealous of all the attention McAfee was receiving and decided to do something about it. Microcom announced a free virus removal utility, and on February 19, Symantec introduced its own free program, promoting it with a full-page advertisement in Computerworld. Users could download it via CompuServe, obtain it from a local dealer, order it by mail, or access it through a bulletin board system (BBS). The only problem was that many media outlets now mistakenly assumed Michelangelo itself spread through BBSs. You have to love the media. Accurate reporting… since time immemorial.

By the end of February, the hype surrounding the virus had reached a fever pitch. Self-proclaimed “antivirus experts” were offering advice from every direction, while computer columnists, including Lawrence Magid, even recommended leaving computers switched on from March 5 through March 7 to avoid triggering the virus. Great advice, Lawrence, unless the power happened to go out on March 6 and your computer rebooted automatically.

On February 28, Seattle-based Egghead Software offered a special Norton AntiVirus Michelangelo Edition for just $4.99. Unfortunately, most copies were not shipped until after March 6, making them of little practical use.

March…

As Doomsday approached, McAfee once again appeared on NBC’s Today show, repeating his claim that 5 million computers around the world were already infected. He did not even present it as an estimate. According to him, it was an established fact. This only intensified the media frenzy, with television networks and newspapers racing to warn the public about a supposed global epidemic that threatened everyday life.

On March 3, Poland woke up to the headline: “Michelangelo, the Mass Killer, Will Strike on Friday.” In the United States, the threat of Michelangelo was reported not only by the Associated Press, which even mentioned it on Capitol Hill. Intel also found itself affected, forcing the company to halt shipments of its LANSpool networking software after discovering 839 floppy disks infected with Michelangelo. Although Intel was using antivirus software, it failed to detect this particular variant of Stoned.

If even Intel was having problems, it did not bode well for everyone else.

  • March 4: Ross Greenberg, the programmer behind Microcom’s Virex-PC antivirus package, disappeared for four days. He did not return until after March 6.

  • March 5: Isolated reports began arriving from around the world that Michelangelo had activated a day early on some computers whose internal clocks had incorrectly handled the leap year and mistakenly advanced to March 6.

McAfee and Charles Rutstein debated on NewsHour about how many people would actually be affected by the virus.

The Day of Reckoning. Panic. Confusion. Shouting.

As dawn broke on March 6, the first reports began to emerge. Most of them simply reminded readers about the virus and what was expected to happen. That was hardly surprising, since newspapers could not report on events unfolding in real time. After all, the modern Internet did not yet exist.

Time zones, however, already did, allowing regions such as Asia and Australia to provide Western media with the first reports of what was actually happening.

AP: “Personal computer users today reported isolated cases of Michelangelo virus infections, but so far there are no signs of the widespread damage that had been predicted from the heavily publicized malicious software.”

UPI: “The long-anticipated Michelangelo virus struck computers around the world on Friday, although it appears not to have caused the data catastrophe that some experts had predicted.”

These were not the frantic, chaos-filled headlines we had been expecting. They sounded more like calm weather forecasts than the dawn of a global pandemic. But perhaps things were simply quieter in the United States, while the situation in Europe was different. Maybe the virus had taken a stronger hold in those technological hubs.

Around midday, 1,200 ATMs in New York stopped working. Shortly afterward, three-quarters of the lottery terminals in New Jersey went offline. The systems at New York’s Hilton Hotel failed, while cable television subscribers in Philadelphia found their TVs locked to the channel they had been watching the previous day. Perhaps Michelangelo really had begun to strike. Perhaps the worst predictions were starting to come true.

It turned out that Citibank had been affected by a power outage that disrupted its ATMs, the lottery system problems were caused by a separate computer malfunction, someone at the Hilton Hotel had accidentally unplugged a power cable, and the cable television failure had nothing to do with viruses at all. Although people were quick to blame Michelangelo for everything, it later became clear that these were unrelated incidents, and the day passed without catastrophe.

AP reporter Bart Ziegler filed a news report that read roughly as follows:

“Tech Doomsday turned out to be a bust… For days, the media had been broadcasting predictions of Michelangelo’s inevitable devastation. The story had all the necessary ingredients: a mysterious invader with a memorable name, capable of wreaking havoc on the machines millions of people depended on by a specific deadline. Reports often failed to mention that many of the predictions about potential damage came from companies that developed antivirus software and stood to benefit from the panic.”

“One such source was John McAfee of McAfee Associates, the largest seller of antivirus software. McAfee was widely quoted after claiming that Michelangelo had infected as many as 5 million computers worldwide. When asked on Friday whether he had overstated the threat, he replied that the relatively low level of actual damage caused by Michelangelo was partly due to the precautions many PC users had taken.”

Based on reports received by his company, McAfee quickly revised his estimate from 5 million infected computers to just 10,000 worldwide. Of course, as with Y2K, some of the potential damage was genuinely avoided thanks to widespread publicity and the increased use of antivirus software. Even so, 10,000 represents just 0.2% of the original estimate, a very significant drop.

Symantec claimed that a quarter of a million users worldwide had obtained a copy of its virus removal software, which undoubtedly helped reduce the impact. However, actual reports of infections remained scarce. AT&T reported that only two out of roughly a quarter of a million company computers had been infected. A bowling center in Swanton lost the records for its bowling league, while Reverend Stan Wilkins of New Salem Baptist Church lost records relating to his congregation.

Additional reports the following day suggested that the overall damage was somewhat greater. In South Africa, 750 computers used to manage the country’s pharmacy network were affected. Scotland Yard reported that two British companies had suffered significant losses, and at Boston University the virus disabled three computers.

What did not happen was that 5 million computers required complete reinstallation.

Harold Highland, editor-in-chief of the journal Computers & Security, remarked:

“We raised awareness, but we also caused a great deal of harm. When all of this is over, senior management will feel that a lot of money was wasted.”

McAfee weighed in on the matter, saying:

“The biggest loser in this whole story will be the antivirus community.”

Given the surge in sales antivirus companies enjoyed as a result of the scare, that was hardly a convincing argument. In fact, it sounded like complete nonsense.

Scotland Yard reported that two British companies had suffered significant losses, while three computers at Boston University failed after booting up.

Although the entire antivirus industry faced a wave of criticism, with some even arguing that antivirus vendors themselves were responsible for fueling the panic over the destructive code, the harshest criticism fell on McAfee. Countless newspapers repeated his claim that 5 million computers were infected. McAfee later explained that his estimate had ranged from 50,000 to 5 million infected machines, and that the media had simply focused on the upper end of that range. Perhaps the real problem was that the media themselves had become overly sensationalist in an effort to sell more of their own product—newspapers.

Or perhaps, as is so often the case, the truth lay somewhere in the middle. A little bit of both. As always.

McAfee resigned from the National Computer Security Association on the first business day following the Michelangelo media fiasco, choosing instead to focus on selling an ever-growing number of McAfee products. His company went public in October 1992, raising $42 million through its initial public offering. And, of course, the brand still exists today, even though McAfee himself does not. According to the official account, he was found hanged in his cell at a Spanish prison just hours after a court approved his extradition to the United States on tax-related charges.

Interestingly, Michelangelo is still with us, and new detections continue to appear from time to time. It seems that somewhere out there, floppy disks infected with the virus are still sitting around, quietly continuing to do exactly what they were designed to do.

The biggest lesson the media should have learned was that, when gathering facts and making predictions, they ought to consult independent experts rather than antivirus software vendors. Yet, considering that a similar wave of panic had erupted only a few years earlier over the Datacrime II virus, which also wiped hard drives on Friday the 13th—albeit on a much smaller scale—it seems these are lessons that have to be learned more than once.

Perhaps it’s no surprise, then, that the next “Friday the 13th” virus, which was ironically scheduled to activate just one week after Michelangelo, received almost no attention from a thoroughly exhausted media.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.