Gavin Schmidt woke on Tuesday 17 November 2009 to find that his login to RealClimate, the blog he ran with other climate scientists, no longer worked, and neither did the administrator's. Each time he got into the server's back end he was logged out again. He had the hosting company take the site offline, and when he had control back he found what had been left on it: a large uploaded file and a draft post, ready to go, announcing the theft of email from the Climatic Research Unit at the University of East Anglia in Norwich. RealClimate warned the unit that day. Around the same time a short comment on Climate Audit, a climate-sceptic blog, announced that a miracle had happened.
The archive held more than a thousand emails and some three thousand other documents, running from 1996 to a message dated 12 November, five days before the attempt to publish it; Schmidt said the files had come through a hack into the unit's backup mail server. Stopped at RealClimate, the archive reappeared on 19 November as a 61-megabyte file on an anonymous FTP server in Russia, linked from the comment threads of climate-sceptic blogs, with an anonymous note calling it "a random selection of correspondence, code, and documents" and climate science "too important to be kept under wraps". Copies spread that day; the newspapers had it the next. The university said it could not yet confirm how much of it was genuine, and that it had called in the police.
Early commentary looked inward, with some security researchers suggesting that a leak by an insider was likelier than an outside intrusion. Norfolk Constabulary's major investigation team took the case, with national units including the Police Central e-Crime Unit and the National Domestic Extremism Team. The method repeated on 22 November 2011: about five thousand more emails, apparently taken in the same intrusion, appeared on a Russian server, linked from the same kind of blogs, with a note saying the rest, some 220,000, were encrypted and the passphrase would stay private. On 14 December officers searched the West Yorkshire home of a blogger among the recipients and took two laptops and a router. No one was arrested, and he was never charged.
On 18 July 2012 Norfolk Constabulary closed the case. Detective Superintendent Julian Gregory said there was no realistic prospect of identifying the offender or offenders and bringing proceedings "within the time constraints imposed by law". The force concluded the breach had been "a sophisticated and carefully orchestrated attack on the CRU's data files, carried out remotely via the internet", and that there was no evidence anyone working at or associated with the university was involved. Britain's three inquiries of 2010 found no evidence of dishonesty or deliberate scientific malpractice by the unit's researchers, while criticising what a Commons committee called a "culture of non-disclosure"; Phil Jones, who stood aside as director on 1 December 2009, returned after the last of them as director of research. No one was charged.
A Request With Two Authors
On 4 November 2009 Martin Rex of SAP posted to the Internet Engineering Task Force's TLS mailing list an attack on the renegotiation of encrypted sessions. He had arrived independently at what Marsh Ray of PhoneFactor had found in early August, and what Ray and his colleague Steve Dispensa had been explaining to vendors under non-disclosure since late September; the two published their paper that day. Renegotiation let the ends of a TLS connection agree fresh keys mid-session, but nothing bound the new handshake to the old. A man in the middle could open his own session, send the first half of a request, then splice in the victim's connection, and the server took both halves for one. Eric Rescorla's illustration was a pizza ordered on the victim's account and delivered to the attacker, who never saw the reply. Moxie Marlinspike thought webmail and banking unaffected. Within ten days Anil Kurmus, a graduate student in Zurich, had made Twitter publish a victim's intercepted request, password included, as the attacker's status update; Twitter switched renegotiation off. The protocol fix, RFC 5746, followed in February 2010.
What the Insulators Said
On Sunday 8 November 2009 CBS's 60 Minutes, citing six unnamed sources, told viewers that hackers had caused a blackout north of Rio de Janeiro in January 2005 and a two-day outage for three million people in Espírito Santo from 26 September 2007. Raphael Mandarino Jr., director of the Brazilian government's Homeland Security Information and Communication Directorate, said he had found no evidence and that the control systems were not directly connected to the internet. Furnas, the utility, had blamed the 2007 failure within two days on dust and soot from burning fields, built up on its high-voltage insulators over eight months without rain; the grid operator agreed, and the regulator fined Furnas $3.27 million in January 2009. Two nights after the broadcast, storms short-circuited a 750-kilovolt line from Itaipu, the dam shut down completely for the first time in its 25 years, and some 60 million Brazilians lost power. The timing revived the story. A US diplomatic cable of 1 December, published by WikiLeaks a year later, recorded the grid operator's officials ruling hackers out: the control network stood apart, and cutting transmission required a voice command.
Traceable or Switched Off
India spent November 2009 insisting that every mobile phone lead back to a person. The month opened under a Home Ministry order, issued on 30 October, that from 1 November no prepaid connection be sold and no existing prepaid SIM renewed in Jammu and Kashmir. The ministry cited dealers who had not verified subscribers, single buyers holding several connections and forged identity documents; a few months earlier some 30,000 connections had been cancelled after police found their papers fake or incomplete. It caught about 3.8 million prepaid users. On 9 November the chief minister, Omar Abdullah, said the state had advised against a blanket ban that punished genuine users for the lapses of a few operators' staff. It was lifted in January 2010, with stricter verification in its place.
The month closed on the handsets. The Department of Telecommunications had told operators to reject, from midnight on 30 November, calls from any phone whose fifteen-digit IMEI was missing or absent from the GSM Association's database, calling non-genuine numbers "a national security hazard". Most were unbranded grey-market imports: 25 million by the ministry's count, nearer 20 million by the industry's. The operators' association asked for more time, did not get it, and on 1 December the phones were cut off; some 1,600 centres implanted genuine numbers at about 200 rupees a handset. Since May 2023 the same fifteen digits have let owners block lost and stolen phones through the Sanchar Saathi portal, and an order of November 2025 that its app come preinstalled and undeletable on every new phone was withdrawn on 3 December. How a phone call is turned into a fraud today is set out on our India desk.
IBM's cat-scale cortex and its critic
On 18 November 2009, at the SC09 supercomputing conference in Portland, Oregon, IBM Research announced a cortical simulation it said exceeded the scale of a cat's cortex. Dharmendra Modha's group and Lawrence Berkeley National Laboratory had run it on Dawn, Lawrence Livermore's Blue Gene/P, across 147,456 processors; one model held 1.6 billion neurons and 8.87 trillion synapses. The next day the paper took one of two special-category Gordon Bell Prizes. Within days Henry Markram, who led the Blue Brain Project in Lausanne, sent IBM and the press an open letter calling the claim a hoax and "a PR stunt": each model neuron was the simplest equation possible, and no neuroscientist would call the result close to a cat's brain. IBM stood by the work, saying it had claimed a cat's scale, not a cat. On 2 November Google's voice search, until then English-only, had learned Mandarin on Nokia phones, with Google warning that strong southern accents might defeat it. Modha's group went on to build neurons in silicon, unveiling its first SyNAPSE chips in August 2011.
FireEye silences Mega-D, briefly
On 6 November 2009 FireEye moved against Mega-D, also known as Ozdok, a large spam botnet. Hosting providers took most of its command servers offline, registrars disabled its domains, and FireEye claimed the fallback domains written into the bots, pointing them at sinkholes where about a quarter of a million infected computers checked in; within days the spam all but stopped. The pause was short. Researchers at Berkeley who had infiltrated the botnet found its operators had no backup domains or hosting ready, yet by 22 November it was sending a larger share of the world's spam than before. On 3 November Sophos's Chester Wisniewski had reported a test on Windows 7's launch day: ten fresh samples, a clean machine, default settings, no anti-virus. Two failed to work, User Account Control stopped one, and the rest ran. Microsoft's Paul Cooke replied that the test bypassed Internet Explorer's download filter and objected to vendors "sensationalizing findings" to sell software, but agreed anti-virus was still needed.
⏳ Time capsule — November 2009
- On 9 November, twenty years after the Wall was opened, Berlin held a Festival of Freedom at the Brandenburg Gate. More than a thousand painted foam dominoes, each over two metres tall, had been stood along the Wall's former route through the city centre, and were toppled in stages until the last fell in front of the Gate.
- On 18 November, in extra time of the World Cup play-off at the Stade de France, Thierry Henry handled the ball twice in the move that led to William Gallas's goal, and France went through 2–1 on aggregate at Ireland's expense. Henry admitted the handball after the match; on 20 November FIFA turned down Ireland's request for a replay.
- On 20 November, fourteen months after a magnet fault had damaged more than fifty of its superconducting magnets, the Large Hadron Collider at CERN circulated beams again. The first collisions followed on 23 November, and on 30 November it reached 1.18 TeV per beam, taking from the Tevatron a record held for eight years.
- On 24 November Manmohan Singh made the first official state visit of Barack Obama's presidency. The talks at the White House took in trade and nuclear power, and the state dinner that evening was held in his honour.
Where the proof ran out
November 2009 put an intrusion nobody could attribute beside an attribution with no intrusion behind it. In Norwich the police found a sophisticated remote attack and never a name. What the case left was a form: private mail taken, then released anonymously through intermediaries less than three weeks before the Copenhagen conference opened on 7 December. The same form carried the Democratic National Committee's email out three days before its convention in July 2016. In Brazil no investigation bore the accusation out. When a blackout was first confirmed as the work of intruders, in western Ukraine on 23 December 2015, it came with an operator locked out of his own console and a switchboard flooded with calls, not six unnamed sources.
The renegotiation flaw ended the way protocol flaws are meant to. RFC 5746 bound each new handshake to the one before, the libraries shipped it, and in June 2025 the SSL Pulse survey found 99.8 per cent of popular sites supporting the secure kind; TLS 1.3, published in August 2018, dropped renegotiation altogether. What outlasted the fix was Kurmus's week: a weakness dismissed as hard to use turned practical as soon as someone found a service that would publish whatever it was sent. The attacks that came after went for the encryption itself — BEAST in September 2011, POODLE in October 2014 — and each was closed for good only when an old version of the protocol was retired.