Skip to the timeline
Bombe

The history of
breaking Enigma

Codebreakers recovered Enigma keys by using weaknesses in the machine, in German operating procedures and in operators’ habits.

Polish cryptanalysts worked out the machine’s wiring in 1932. British and American codebreakers built on their methods with bombes, guessed plaintext and captured documents. Several German changes to the machine and its procedures stopped existing methods and required new ones.

01

The Polish Cipher Bureau trains mathematics students.

Polish radio intelligence intercepts German Army messages in a new machine cipher from 1928. In 1929 the Cipher Bureau and Poznań University run a secret evening course in cryptology for mathematics students who know German.

Marian Rejewski, Jerzy Różycki and Henryk Zygalski are selected from the course. They work for the Bureau’s Poznań branch and join its Warsaw office in September 1932.

Sources & notes 5

MacTutor dates the start of the course to January 1929; Adam Mickiewicz University gives March 1929.

02

French intelligence passes Schmidt’s Enigma documents to Poland.

Hans-Thilo Schmidt, an employee of the German cipher office, sells Enigma documents to French intelligence. In December 1931 Captain Gustave Bertrand agrees with the Polish Cipher Bureau that France will supply intelligence and Poland will do the cryptanalysis.

The material includes documentation on the machine, training messages in both plain text and cipher text, and later the keys for September and October 1932. It does not include the rotor wiring. Rejewski receives the keys in December 1932, when his analysis cannot go further without them.

Sources & notes 4
03

Rejewski links the letters of the doubled message key.

Each operator chooses a three-letter message key and types it twice, starting from the same daily position used by every operator. The first and fourth enciphered letters of every message therefore stand for the same key letter, as do the second and fifth, and the third and sixth.

With about 80 messages from one day, Rejewski links these letters into three tables and analyses them with the theory of permutations. Operators who choose keys such as AAA, or three neighbouring keys on the keyboard, help him split the tables into the machine’s individual steps.

Weakness used

Every message key of the day is enciphered twice from the same starting position, and many operators choose predictable keys.

Sources & notes 4

NSA dates the start of Rejewski’s work on Enigma to October 1932.

04

Rejewski reconstructs the rotor wiring.

The French keys give Rejewski the plugboard pairs for the days he is studying, leaving the right-hand rotor as the main unknown. His equations fail until he guesses that the keys are wired to the entry wheel in alphabetical order. The commercial Enigma uses keyboard order.

The keys cover two months in different quarters of the year, and the rotor order changes each quarter. A different rotor stands on the right in each month, so Rejewski can solve two rotors; the third rotor and the reflector follow.

Weakness used

The entry wheel connects the keys in alphabetical order, and leaked keys remove the plugboard from Rejewski’s equations.

Marian Rejewski as a Polish Army signals officer in Britain, 1943 or 1944.
Marian Rejewski as a Polish Army signals officer in Britain, 1943 or 1944. Unknown photographer · Public domain · Wikimedia Commons ↗
Sources & notes 7

Rejewski later wrote that he guessed the entry-wheel wiring in December 1932 or the first days of 1933. Alexander’s wartime history describes three months of keys with an unchanged rotor order; Rejewski’s own account describes two months with a change of right-hand rotor.

05

The Cipher Bureau reads Army messages with replicas and hand methods.

By early 1933 the Bureau reads German Army Enigma messages. The AVA Radio Company in Warsaw builds replica machines to Rejewski’s design.

Daily keys are recovered by hand. The grill and other hand methods rely on the plugboard swapping only six pairs, which leaves 14 letters unchanged. Różycki’s clock method compares the letters of pairs of messages to identify the rotor on the right, which turns at every key press.

Weakness used

At first the plugboard swaps only six letter pairs, and the rotor order changes only once a quarter.

Sources & notes 7

Christensen dates the first readable messages to mid-January 1933; Tůma dates the first replica to the end of January 1933. MacTutor describes the clock method as finding the rotor “in the first position”.

06

The Poles catalogue cycle lengths with Rejewski’s cyclometer.

On 1 October 1936 the Germans begin using five to eight plugboard pairs, and the hand methods stop working. The Poles return to the three tables built from each day’s doubled message keys.

The plugboard changes which letters appear in each cycle of those tables, but not the cycle lengths. Rejewski’s cyclometer, two linked sets of rotors with lamps, measures the lengths for all 105,456 rotor orders and starting positions. The card catalogue takes more than a year to compile; with it, a daily key usually takes 10 to 20 minutes.

Weakness used

The plugboard does not change the cycle lengths, and every message key of the day still starts from one position.

Sources & notes 3
08

Reflector B forces the Poles to rebuild the catalogue.

The Germans replace reflector A with reflector B. The catalogue was compiled with the old reflector, so the Poles work out the new wiring and compile the catalogue again.

Sources & notes 4

Rejewski’s 1980 paper and Crypto Museum give 1 November 1937; Rejewski’s 1981 account, quoted by Christensen, and Sullivan and Weierud give 2 November.

09

Zygalski’s sheets and the bomba search for repeated letters.

From 15 September 1938 each operator picks a starting position, sends it unenciphered and enciphers the doubled message key from it. The catalogue no longer works, but the doubled key sometimes shows the same enciphered letter in the first and fourth places, the second and fifth, or the third and sixth. The Poles call these repeats females; they occur only at certain rotor positions, whatever the plugboard pairs.

Zygalski’s perforated sheets mark the positions that can produce a female, and stacking the sheets for a day’s messages leaves a hole at the likely setting. The AVA company builds six bomby in November 1938, one for each rotor order; each tests rotor positions against three females, and a search takes about two hours.

Weakness used

The doubled message key still produces females, and the plugboard does not change the rotor positions where they can occur.

Sources & notes 5

No bomba survives, and its exact stop rule is not documented. David Link’s reconstruction shows that the repeated letter had to be unplugged for the method to work.

10

The Poles lack equipment for five rotors and ten plugboard pairs.

Rotors IV and V let operators choose three rotors from five, and the possible rotor orders rise from 6 to 60. The Nazi Party’s SD network still uses the old indicator procedure, so when a new rotor stands on the right, Rejewski recovers its wiring with the 1932 method.

On 1 January 1939 the plugboard rises to as many as ten pairs, so the letter in a female is less often unplugged. The sheets and bomby cover 6 rotor orders; covering 60 needs ten times as much equipment, more than the Bureau can build.

Weakness used

The SD network keeps the old indicator procedure, so the new rotors can be solved with the 1932 method.

Sources & notes 7

Sullivan and Weierud describe the January 1939 change as six to ten pairs; Crypto Museum and Link record five to eight pairs in use from October 1936. Rejewski’s 1980 paper says only that the number of cables increased gradually.

11

Poland shares its Enigma methods at Pyry.

At the Cipher Bureau’s centre at Pyry, outside Warsaw, the Poles show French and British codebreakers their replicas, the Zygalski sheets and designs for the bomba and cyclometer. Alastair Denniston and Dilly Knox represent Britain. German changes have reduced Polish success in the preceding months, but the Poles have read far more traffic than either ally.

Knox’s first question is how the keys are wired to the entry wheel. France and Britain each receive a Polish-built replica; Bletchley Park has its machine in August 1939.

Sources & notes 6

GCHQ, NSA and Rejewski’s 1980 paper date the meeting from 25 July; Christensen and MacTutor give 24–25 July.

12

Polish, French and British teams break wartime keys.

After Poland is invaded, Rejewski, Różycki and Zygalski reach France and resume work on 20 October 1939 at PC Bruno, near Paris, with French colleagues. At Bletchley Park, John Jeffreys’ section makes Zygalski sheets for all 60 rotor orders, and a set goes to PC Bruno.

Using the sheets, the team in France breaks a wartime key in early January 1940, and Bletchley Park makes its first wartime break the same month. Alan Turing meets the Polish codebreakers in France that January.

Weakness used

Army and Air Force operators still type the message key twice, so the sheets still work.

The mansion at Bletchley Park, photographed in 2017.
The mansion at Bletchley Park, photographed in 2017. The first British wartime breaks were made in the Cottage in the stable yard. DeFacto · CC BY-SA 4.0 · Wikimedia Commons ↗
Sources & notes 7

Tony Sale gives early January 1940 for the team in France and 14 January for Bletchley Park; Bletchley Park’s own summary gives January 1940. Sale says Turing brought the sheets to France in December 1939; GCHQ dates his visit to January 1940.

13

The first British bombe tests settings against a crib.

Victory, built by the British Tabulating Machine Company under Harold “Doc” Keen, arrives at Bletchley Park. Alan Turing designed it to work from a crib, a guessed piece of plain text, so it does not depend on the indicator procedure. In June and July, with text captured from the patrol boat VP 26, it helps Hut 8 solve six days of April naval traffic.

Because of the reflector, Enigma never enciphers a letter as itself. Codebreakers slide the crib along the cipher text and reject any position where a letter would stand above itself; the bombe then searches for rotor settings consistent with the crib.

Weakness used

Enigma never enciphers a letter as itself, so a crib can be placed only where no letter lines up with itself.

The reconstructed British bombe at Bletchley Park, photographed in 2015.
The reconstructed British bombe at Bletchley Park, photographed in 2015. The Turing Bombe Rebuild Project, Bletchley Park, Milton Keynes, Buckinghamshire by Christine Matthews · CC BY-SA 2.0 · Wikimedia Commons ↗
Sources & notes 7

TNMOC gives 14 March 1940 for Victory; Crypto Museum and NSA give 18 March. The photograph shows the modern reconstruction, not Victory.

14

Army and Air Force operators stop doubling the message key.

On most Army and Air Force networks the message key is now enciphered once. The females that the Zygalski sheets and the bomba relied on disappear. Codebreakers now need cribs, operator mistakes or captured keys.

Sources & notes 3

Crypto Museum records that the Yellow network, used in the Norwegian campaign, changed on 15 May 1940.

15

Hut 6 breaks the Red key from operators’ habits.

In February 1940 John Herivel suggests that hurried operators may choose a first message setting close to the day’s ring settings, so the first indicators from many operators would cluster around them. In late May such a cluster lets David Rees break Red, a Luftwaffe key that the Polish methods could no longer break.

Codebreakers also look for cillies: message keys such as three consecutive keyboard letters, a word or a set of initials, or a key reused from the previous message.

Weakness used

Operators choose first message settings near their ring settings, or predictable keys such as keyboard sequences and initials.

German military radio operators using Enigma, October 1940.
German military radio operators using Enigma, October 1940. Bundesarchiv, Bild 183-L22303 / Mees / CC-BY-SA 3.0 · CC BY-SA 3.0 DE · Wikimedia Commons ↗
Sources & notes 4

Sources give different origins for the word cillies: Bletchley Park suggests one operator’s initials, CIL, while NSA repeats a story about an operator’s girlfriend. The photograph shows German operators in October 1940, not the habits described here.

16

Welchman’s diagonal board applies the plugboard’s two-way pairs.

A plugboard cable swaps two letters both ways: if A is plugged to E, E is plugged to A. Gordon Welchman’s diagonal board wires this rule into the bombe, so a deduction about one letter pair also tests its reverse.

The board removes most false stops. Agnus Dei, the first bombe fitted with it, is installed in August 1940.

Weakness used

Plugboard pairs work both ways, so a deduction that A is plugged to E also means E is plugged to A.

Sources & notes 5

Crypto Museum and NSA give 8 August 1940 for Agnus Dei; Erskine writes that improved bombes came into service from September.

17

Dilly Knox’s section reads Enigma machines without a plugboard.

The Italian Navy uses a commercial-type Enigma with no plugboard. Knox’s rodding method, devised in 1937, tests a crib against each position of the right-hand rotor using prepared tables.

In March 1941 Mavis Lever sees that an operator’s test message contains no L. Because Enigma never enciphers a letter as itself, she concludes that the operator typed only L, and the key is recovered. Intelligence from Italian naval Enigma helps the Royal Navy at Cape Matapan on 28 March.

Weakness used

The machines have no plugboard, and an operator sends a test message of repeated Ls.

Sources & notes 5

The test-message detail comes from Crypto Museum. Knox had read Italian naval Enigma during the Spanish Civil War; it had since become unreadable. His section issued its first decrypt of Abwehr Enigma, a different model, on 25 December 1941.

19

Banburismus narrows the choice of naval rotors.

Every naval message setting of a day is enciphered from one starting position. Once the bigram tables are known, Hut 8 can line up pairs of messages whose settings overlap; at the right offset, letters repeat between the two cipher texts about as often as in German text, and more often than at random.

Turing’s Banburismus scores these repeats with Bayesian statistics to identify the likely right-hand and middle rotors. It can cut the rotor orders to test from 336 to about 18, saving bombe time; from August 1941 Hut 8 breaks Dolphin without captured keys.

Weakness used

All message settings of a day are enciphered from one starting position, and German text repeats letters more often than random text.

Sources & notes 4

Alexander records that Turing thought of the method in late 1939 and that Hut 8 used it until June 1943. Erskine credits the U-110 indicator books with helping to develop it.

20

Routine messages, repeated texts and minelaying supply cribs.

Many messages follow fixed forms, such as weather reports, and bombe menus are built from these guessed texts. When the same text is sent in Enigma and in a hand cipher that has already been broken, the decrypt gives the Enigma message’s plain text.

The RAF sometimes lays mines in chosen places, an operation called gardening. German signals about the cleared channels are then sent in both naval Enigma and the dockyard cipher, which Bletchley Park can read.

Weakness used

Routine message forms, and the same text sent in two ciphers, give codebreakers known plain text.

Sources & notes 4
21

The four-wheel M4 stops Allied reading of the U-boat key.

The Atlantic and Mediterranean U-boats move their key, Triton (Shark at Bletchley Park), to the four-wheel M4. A new edition of the weather short signal book removes Hut 8’s main cribs at the same time.

The thin fourth wheel does not step during a message, so it works like a choice of 26 reflectors rather than a full fourth rotor. Bletchley Park already knows its wiring from a December 1941 message sent on four wheels and repeated on three, but without cribs the bombes cannot be used against Shark.

A four-wheel naval Enigma M4 at the Caen Memorial, photographed in 2025.
A four-wheel naval Enigma M4 at the Caen Memorial, photographed in 2025. Andy Li · CC0 1.0 · Wikimedia Commons ↗
Sources & notes 3

This stopped reading of Shark only; other naval, Army and Air Force keys were still read. Crypto Museum’s M4 page and Erskine give 1 February; its bombe page gives 2 February.

22

U-559’s codebooks and a neutral fourth wheel let Hut 8 read Shark again.

Before U-559 sinks, sailors from HMS Petard recover its weather short signal book and short signal book; Anthony Fasson and Colin Grazier die in the attempt. Hut 8 finds that U-boats encipher weather reports with the fourth wheel in its neutral position, so the M4 works like a three-wheel machine, and weather broadcasts read by Hut 10 supply the plain text.

On 13 December 1942 Bletchley Park sends the Admiralty the positions of more than 12 U-boats. When a new weather book starts on 10 March 1943, Hut 8 uses sighting reports, also sent in three-wheel mode, and reads Shark again from 19 March.

Weakness used

Weather and sighting reports are enciphered with the fourth wheel in its neutral position, so a three-wheel bombe run can find the key.

Sources & notes 3

The capture on 30 October and the first useful decrypts in December are separate events. The Shark blackout lasted from February to December 1942.

23

British and American four-rotor bombes enter service.

British four-rotor bombes enter service in June 1943 and US Navy bombes in August. Joseph Desch’s team at NCR in Dayton, Ohio, completes the prototypes Adam and Eve in spring 1943. WAVES, members of the US Navy’s women’s reserve, wire the rotors and operate the machines in Washington.

From September 1943 Shark is usually broken within 24 hours, and at the end of the year the US Navy’s OP-20-G takes over the work. By spring 1944, 96 US bombes are in routine use, spending about 45 percent of their time on non-naval keys under British direction.

Sources & notes 4

NSA counts 121 bombes built in Dayton and 77 running at the end of 1943; Crypto Museum reports 120 installed by December 1943.

24

Shared daily keys let Bletchley Park break the rewirable reflector.

The Luftwaffe introduces UKW-D, a reflector whose wiring operators can change, called Uncle Dick or Uncle D at Bletchley Park. It is issued for selected traffic only; most messages still use reflector B.

Networks use the same rotor order, ring settings and plugboard with both reflectors. Once the reflector B key is broken, the UKW-D messages can be attacked with it, and in Norway Bletchley Park finds the D wiring within 24 hours.

Weakness used

The same daily key is used with the new reflector and with the old one.

Sources & notes 3

Ostwald and Weierud date the introduction to 1 January 1944. Crypto Museum reports that operators changed the wiring only every ten days.

25

Bletchley Park solves the Enigma Uhr within days.

The Luftwaffe’s Uhr is a box that replaces the plugboard cables and changes their connections in 40 positions. Bletchley Park receives the first Uhr messages on 10 July 1944.

Some operators who do not know the new procedure resend messages with the ordinary key, which gives the first break. The Uhr changes only the 20 plugged letters, and once one setting is known the effect of all 40 can be predicted.

Weakness used

Messages are resent without the Uhr, and the same daily key is used with and without it.

Sources & notes 1

The Uhr prevented use of the diagonal board, but bombes could still run with long cribs.

26

Most bombes are dismantled and the work stays secret.

By the end of the war Britain has 211 bombes, worked by about 1,676 Wrens and 263 RAF personnel at Bletchley Park and outstations such as Eastcote and Stanmore. About 50 are kept for a time; the rest are dismantled. One US Navy bombe survives, at the National Cryptologic Museum.

Veterans keep the work secret for decades. Gustave Bertrand describes the Polish and French work in 1973, and F. W. Winterbotham’s The Ultra Secret brings the British work to a wide audience in 1974.

Sources & notes 6

Władysław Kozaczuk described the Polish break in Polish in 1967, but the book was not translated and was little known in the West.