Stratfor's website went down over Christmas and came back as a message. On 24 December 2011 a group flying the AntiSec banner defaced the site of the Austin private-intelligence company, published a first tranche of subscriber data and announced a week of releases it called LulzXmas. What that meant in practice was explained by a subscriber in Austin, Allen Barr, recently retired from the Texas Department of Banking, who learned from an Associated Press reporter's telephone call that Stratfor had been breached at all, and then found about $700 gone from his account in five transactions he had not made, the money given away to charities. Stratfor suspended its servers and email and told members that an unauthorised party had disclosed personally identifiable information and related credit card data.
The intrusion was older than the defacement. Reporting drawn from chat logs and court filings places the opening on 4 December 2011, when a hacker using the name Hyrriiya told an IRC channel that Stratfor's systems were open — and the man he told was Hector Xavier Monsegur, "Sabu", who had been co-operating with the FBI since his arrest earlier that year and had pleaded guilty in August 2011. By 6 December Monsegur and Jeremy Hammond were discussing the target in chat; the bureau's account was that Hammond brought Stratfor to Monsegur, while logs published later suggested Monsegur had heard of the opening first. Hammond was inside by the middle of the month, and Monsegur, at the bureau's direction, told him to upload what he took to a server the FBI controlled. The agency therefore held the stolen card numbers, and a record of the theft, while the charges were being made. The dump of 24 December was the last step, not the first.
What the company said afterwards was unusually plain. The site stayed dark until 11 January 2012, and Stratfor's founder and chief executive, George Friedman, put the failure in one line: "We did not encrypt credit card files. This was our failure." He took responsibility, said he regretted the hardship caused to customers, and offered members a year of identity protection through CSID. Researchers reading the dump reported that Stratfor's shop ran on the Ubercart e-commerce package, which offers encryption, and that customer data sat in clear text; a forensic report on the breach by Verizon's investigators found that the shop's database had retained the card number, the expiry date and the security code, which the card schemes forbid. Counts varied with who was counting: the attackers' own announcement claimed 75,000 card numbers and about 860,000 registered users, an early analysis of the published files by Identity Finder found 50,277 unique card numbers of which 9,651 had not expired, and the figures that reached court were the FBI's — 860,160 accounts and some 60,000 cards.
The donations were the part nobody could keep. Anonymous accounts claimed roughly $500,000 given away and Sabu's Twitter feed boasted of more than a million dollars in donations, but the only figure tested anywhere was the FBI's: an agent told a federal judge that at least $700,000 in unauthorised charges had been made on the stolen accounts between 6 December 2011 and early February 2012; the American Red Cross and CARE said they were working out how many fraudulent gifts they had received so they could return them, and as issuers reversed the transactions the charities lost twice over, in the money and in the fees. Other Anonymous channels disowned the target. WikiLeaks began publishing Stratfor's email in February 2012, and Hammond was arrested in March 2012. Stratfor settled a class action with subscriptions, an e-book and credit monitoring, kept trading, and was bought by RANE in 2020.
The thermostat and the printer
On 21 December 2011 the Wall Street Journal reported that intruders had sat in the US Chamber of Commerce's network for at least six months, which the Chamber put at November 2009 to May 2010, and that it had learned of them from the FBI, not its own monitoring: the bureau said servers in China were taking its information. They had concentrated on four employees working on Asia policy, taking about six weeks of their email along with trade-policy documents, meeting notes and trip reports. Two details from the clean-up lodged: a thermostat in a Chamber-owned townhouse was talking to an internet address in China, and a printer used by executives printed pages of Chinese characters. David Chavern, the chief operating officer, said what was unusual was somebody very sophisticated who knew exactly who the Chamber was and targeted specific people; the Chamber also said it had found no harm to its members from the intrusion. Publicly the attribution went no further than unnamed sources telling the Journal that technical aspects suggested a known group in China; a foreign ministry spokesman, Liu Weimin, called the report baseless and said Chinese law bans hacking. Eight days earlier Microsoft had patched the font flaw that October's Duqu used.
Six million, then forty
The month's largest exposure of passwords was not an intrusion but a cascade. In the third week of December 2011 a file holding about six million user names, passwords and email addresses from CSDN, the Chinese Software Developer Network, appeared online in clear text; CSDN apologised and said the records came from a backup in which passwords written before 2009 were stored without encryption. Within days a far larger file was reported from Tianya, the country's biggest web forum, carrying some 40 million accounts and again drawn from a store that predated the forum's switch to encrypted passwords in November 2009; Tianya emailed users and posted on the forum telling them to change their passwords. Reports across the last week of December added game and shopping sites, and the totals quoted ran past 100 million records without anybody able to verify them. China's Ministry of Industry and Information Technology said on 28 December that it was investigating and urged the affected companies to inform their users. Separately, on 16 December, Beijing's municipal authorities issued provisions requiring microblog services to register users' real identities behind the scenes by March 2012 — the same fortnight, a different anxiety.
Screen it before it appears
The request was for prior screening, and it was made in a room. On 5 December 2011 the New York Times reported that India's communications and information technology minister, Kapil Sibal, expected Google, Facebook, Yahoo and Microsoft to set up a proactive pre-screening system — staff reading user posts and removing objectionable ones before they appeared — and that executives would tell him at that day's meeting the demand was impossible, given the volume of Indian content and their inability to judge what was defamatory. Sibal had been at it since at least 5 September, when officials first met Facebook, Twitter and Orkut representatives; the Committee to Protect Journalists counted six meetings by December. On 6 December he held a press conference, showed reporters images ridiculing the prime minister and the Congress party president and a page depicting pigs in Mecca, and denied that censorship was the point.
His formula was that the companies had agreed orally and then declined in writing, and that if incendiary material would not come down the government would have to act; it gave him no pleasure, he said, to restrict social media. Facebook replied that it removed content breaking its own rules on violence and hatred and would continue to engage Indian authorities; Google drew its line in a sentence — when content was legal and did not violate its policies, it said that month, "we won't remove it just because it's controversial". Nothing in the Information Technology (Intermediaries Guidelines) Rules notified that April required screening before publication. The row acquired a courtroom within the month: a Delhi magistrate's summons to the companies on 23 December belongs to January 2012. The screening question was settled in March 2015, when the Supreme Court struck down section 66A and read the takedown duty down to orders from a court or the government.
Passwords, brainwaves and priority mail
On 19 December 2011 IBM published the sixth edition of its annual 5 in 5, the five technologies the company expected to matter within five years. The 2011 list ran to energy harvested from walking and cycling, biometrics replacing the typed password, brain-computer interfaces read from electrical activity, mobile devices closing the information gap in poorer countries, and analytics precise enough that, in the company's own heading, "junk mail will become priority mail". Six days earlier Google had bought Clever Sense, whose Alfred app learned users' tastes from their behaviour and recommended places to eat; terms were not disclosed, and the team joined Google's local division. Read from 2026, the list is one near-hit among misses — biometrics, and later passkeys, displaced the typed password on personal devices without abolishing it; mind reading stayed in laboratories and clinics; harvested energy stayed a novelty; the divide narrowed rather than ceased. The forecast that paid was the dullest: that machine learning would be spent working out what people want.
Duqu's font flaw, closed at last
Microsoft closed the hole on 13 December 2011. Bulletin MS11-087, rated critical, corrected a bounds check in the TrueType font parsing engine of a Windows kernel-mode driver, CVE-2011-3402: a malformed font embedded in a document or a web page could corrupt kernel memory and run code, which is how October's Duqu installed itself. The flaw had been public since 3 November, when Microsoft issued an advisory carrying no patch but a stopgap, in its own wording "Deny access to T2EMBED.DLL", which disabled embedded-font rendering and had to be reversed once the update shipped. Adobe's month ran the same way: an advisory on 6 December for a memory corruption flaw in Reader and Acrobat, reported by Lockheed Martin's response team and the Defense Security Information Exchange and already used in targeted attacks, then an out-of-band fix for Reader 9 on Windows on 16 December, the sandboxed Reader X left until January. On 15 December Microsoft said Internet Explorer would begin upgrading itself automatically — the start of the silent updating endpoint software now assumes.
⏳ Time capsule — December 2011
- On 5 December NASA's Kepler team announced Kepler-22b, about 640 light years away in Cygnus and roughly 2.4 times Earth's radius on the first estimate — the first transiting planet confirmed in the habitable zone of a Sun-like star, on a 290-day orbit.
- On 15 December the American flag was lowered at a ceremony in Baghdad marking the end of the United States military mission in Iraq, and the last troops crossed into Kuwait on 18 December.
- On 19 December North Korean state television announced that Kim Jong-il had died two days earlier; his son Kim Jong-un succeeded him, and the state funeral was held on 28 December.
- On 27 December the Lok Sabha passed the Lokpal and Lokayuktas Bill; the Rajya Sabha took it up on 29 December, debated past midnight and was adjourned without a vote.
Unencrypted, and on the record
Stratfor's failure was not sophistication but storage, and storage is the part the industry fixed. Encryption of stored card data, and a ban on retaining security codes, were already in the card schemes' rules in 2011; what December supplied was a company selling intelligence that had not followed them, and a chief executive willing to say so. The more uncomfortable residue is the informant. A cooperating witness sat in the channel as the intrusion ran, the stolen data went to a bureau-controlled server, and the charges were made anyway. Hammond was sentenced to ten years on 15 November 2013, moved to a halfway house on 17 November 2020 and finished his sentence on 5 March 2021; Monsegur was sentenced on 27 May 2014 to the seven months already served.
The other two stories became law and indictments. The Chamber's intruders were never named in public; the pattern was set out by Mandiant in February 2013, and in May 2014 a grand jury in Pittsburgh charged five officers of a People's Liberation Army unit over intrusions at six American victims — the Chamber not among them — the first such charges against acknowledged state personnel. China's cascade of plain-text passwords was followed by a Cybersecurity Law in force from 1 June 2017 and a Personal Information Protection Law from 1 November 2021. India's own statute arrived in 2023 with the DPDP Act, and the screening idea came back in the intermediary rules of 2021, which ask the largest platforms to use automated tools to find certain material before anyone complains.