The claim ran in the Financial Times on Friday 4 February 2011. Joseph Menn reported that Aaron Barr, chief executive of a small firm called HBGary Federal, had spent weeks watching Anonymous from inside its chat channels and social accounts and believed he had identified the people who ran it: two key figures, one of them described as a co-founder in the United States, with senior members he placed in Britain, Germany, the Netherlands, Italy and Australia. Barr had not given the names to the police. He intended to present the method at a security conference in San Francisco later that month. One of his own programmers had already told him by email that the social-network analysis behind it did not hold — email that was about to be public.

The way in was the company's own website. Ars Technica's reconstruction of 15 February 2011, built from the material Anonymous released, traced it to a content management system made for hbgaryfederal.com whose page parameter could be persuaded to return database rows it should not have. The user table came out with its passwords hashed in MD5, with no salt and no repeated hashing. Two of them — Barr's, and that of the chief operating officer, Ted Vera — were six lower-case letters followed by two digits, which a rainbow table answers instantly. Vera had used his again for a secure-shell login on support.hbgary.com. An unpatched Linux privilege-escalation flaw published the previous October took the intruders from there to root, and gigabytes of backups came off the machine.

Barr's password was worth more: it carried administrator rights over the company's hosted Google Apps mail, and an administrator can reset any mailbox — including that of Greg Hoglund, HBGary's founder. Writing as Hoglund, they asked an administrator of rootkit.com, the research site he ran, to set a root password to changeme123 and open secure shell; the administrator did. The site was defaced and its user database taken. Over the weekend of 5 and 6 February the mail went onto file-sharing networks — counts at the time, the attackers' own among them, ran from about sixty thousand messages to more than seventy thousand — Barr's Twitter account was taken over, files were deleted and the phone system stopped. The defaced page left a sentence: "We've seen your internal documents, all of them, and do you know what we did? We laughed."

What the mail held mattered more than how it was taken. It showed HBGary Federal, Palantir Technologies and Berico Technologies working as Team Themis on proposals solicited by the law firm Hunton & Williams — for Bank of America, then facing a threatened WikiLeaks disclosure, and for the US Chamber of Commerce. One deck placed the journalist Glenn Greenwald on a chart of WikiLeaks' support: without people like him, it argued, WikiLeaks would fold, and his advocacy needed to be disrupted. Palantir's chief executive apologised to Greenwald on 11 February and severed any and all contacts with HBGary; Berico said it did not condone efforts proactively targeting American organisations or individuals; the Chamber called the allegations a baseless smear; Bank of America denied knowledge of the proposals. HBGary pulled its booth from the RSA Conference on 16 February, days after finding it papered overnight with a note reading "Anon… in it 4 the lulz..", and cancelled its talks; Barr, who said he had received death threats, resigned on 28 February.

Also that month · 10 February

The Paper With HBGary in the Credits

McAfee published Global Energy Cyberattacks: "Night Dragon" on 10 February 2011, four days after HBGary's mail was taken; its acknowledgements listed HBGary and Greg Hoglund among the contributors. It described intrusions from November 2009 at global oil, energy and petrochemical companies: extranet web servers taken by SQL injection, hacker tools uploaded to them, pass-the-hash for more credentials, Internet Explorer proxy settings switched off so infected machines could talk straight to the internet, and remote administration tools on executives' computers to take mail archives and field-bid papers. Appendix B was plain: "McAfee has no direct evidence to name the originators of these attacks but rather has provided circumstantial evidence" — the circumstances being a reseller in Heze City, Shandong, advertising hosted American servers with no records kept, exfiltration from Beijing addresses on weekdays nine to five, and Chinese-language logon-stealing tools. The paper named no victims; Dmitri Alperovitch told reporters at least five multinationals had been identified, that a preponderance of evidence put the operators in China, and that they were incredibly sloppy yet professional enough to keep office hours. ICS-CERT reissued it as an advisory, noting that in certain cases the attackers collected data from SCADA systems. At SophosLabs, Fraser Howard objected on 11 February that there was no Night Dragon malware family and no new risk that week, only a label for a pattern.

Also that month · 16–17 February

Two Departments Off The Internet

Canada's answer to a break-in was to pull the plug. CBC News reported on 16 and 17 February 2011 that intruders had been inside federal systems since at least early January, by what its sources called executive spear-phishing: innocuous-looking attachments apparently sent by public servants the recipient knew, the malware taking passwords and the captured accounts passing the same attachment onward. Security staff cut all internet access at the Finance Department and the Treasury Board, the government's two economic centres, to stop data leaving; thousands of public servants worked without it. Defence Research and Development Canada was the third body named. Stephen Harper said on 17 February that a strategy was in place to evolve the government's systems, and a Treasury Board spokesman that there was no indication data about Canadians had been compromised. The addresses used were in China, and officials conceded they had no way of knowing whether the operators were Chinese or merely routing through it; the Chinese government denied any involvement. Nasdaq OMX had already said, after a story ran on 5 February, that suspicious files were found on servers running its Directors Desk board-papers service and that its trading platforms were untouched — what those files had been doing came out in October.

India desk · February 2011

The clause written in 1948

From 9 to 28 February 2011 about 2.7 million enumerators walked 7,935 towns and more than 600,000 villages with the census schedule, counting 1,210,854,977 people for about ₹2,200 crore — under half a US dollar a head. It was the largest deliberate collection of personal data attempted anywhere that month, and the law governing it was sixty-three years old. Section 8 of the Census Act, 1948 made every person asked a question legally bound to answer it. Section 15 closed the other end: no person has a right to inspect any book, register or record made by a census officer, and notwithstanding the Indian Evidence Act, no entry in one is admissible in any civil proceeding, or in any criminal proceeding other than a prosecution under the Act itself. Answers compelled by statute were sealed by the same statute.

Neither of the other two collections then under way had such a clause. The same office — the Registrar General and Census Commissioner — was assembling the National Population Register under rules framed beneath the Citizenship Act, 1955, taking a photograph, ten fingerprints and iris images of usual residents at camps in the locality; the citizenship rules carry nothing resembling section 15. The Unique Identification Authority of India, created on 28 January 2009 by a notification of the Planning Commission, had been issuing Aadhaar numbers since September 2010 with no statute at all. The National Identification Authority of India Bill, introduced in the Rajya Sabha on 3 December 2010, went to the Standing Committee on Finance a week later and was not reported on until 13 December 2011, when the committee rejected it. A constitutional right to privacy followed in 2017; the statute came with the DPDP Act in 2023.

AI Tech desk · February 2011

Watson wins on air, and misplaces Toronto

Broadcast over three nights, 14 to 16 February 2011, the two-game match ended with Watson at $77,147, Ken Jennings at $24,000 and Brad Rutter at $21,600. The machine named Toronto, with five question marks, in the first game's Final Jeopardy as the US city whose airports honour a Second World War hero and a battle, risking only $947 on it. Jennings, conceding, wrote under his last answer "I for one welcome our new computer overlords". IBM gave the $1 million prize to World Vision and World Community Grid, and on 17 February announced with Nuance, Columbia and the University of Maryland a research agreement to take the system into clinical decisions, with products promised within two years. On 24 February Google's Panda change, a classifier trained on outside raters' judgments of quality and named for the engineer Navneet Panda, noticeably altered nearly 12 per cent of US queries. Watson's name outlived the machine; since 2023 it has labelled IBM's watsonx platform.

Digital Guard desk · February 2011

Intel takes delivery of McAfee

On 28 February 2011 Intel completed its purchase of McAfee, announced the previous August at $48 a share, about $7.68 billion. The European Commission had cleared it on 26 January on Intel's undertaking that rival vendors would get the same access to its processors' and chipsets' functions as McAfee, unobstructed. McAfee kept its name and its president, Dave DeWalt, as a subsidiary inside Renée James's Software and Services Group. Paul Otellini had called security a "third pillar" of computing; James said hardware-enhanced security would bring breakthroughs against increasingly sophisticated threats. What came first was DeepSAFE, that October; the name became Intel Security in 2014, and in 2017 Intel sold control to TPG on a $4.2 billion valuation (September 2016). Quieter, and wider: from 8 February Windows Update delivered the change that stops Windows XP and Vista, and their server editions, offering to run programs from a USB stick. Conficker had spread that way; by May Microsoft's malware protection centre counted such infections per scanned machine down 59 per cent on XP and 74 per cent on Vista against 2010.

⏳ Time capsule — February 2011

  • The Cricket World Cup, co-hosted by India, Sri Lanka and Bangladesh, opened with a ceremony at the National Stadium in Dhaka on 17 February; the first match followed on 19 February at the Sher-e-Bangla National Stadium in Mirpur, where India beat Bangladesh.
  • On 22 February a magnitude 6.2 earthquake struck Christchurch at 12.51 in the afternoon, five kilometres down; 185 people from more than twenty countries were killed, 115 of them in the collapse of the Canterbury Television building.
  • On 24 February, at 16:53 Eastern time, Discovery lifted off from Kennedy Space Center on STS-133, its thirty-ninth and final flight, carrying the Leonardo module to be left permanently docked to the International Space Station along with a humanoid robot torso.
  • On 27 February the 83rd Academy Awards were held at the Kodak Theatre in Hollywood, hosted by James Franco and Anne Hathaway; The King's Speech took four awards, including best picture, best director for Tom Hooper and best actor for Colin Firth.
Where it stands today — 2026

The month the pitch deck became evidence

Both companies were gone within the year. HBGary, Inc. was bought by ManTech International on 29 February 2012, a year and three weeks after the weekend, and HBGary Federal did not survive the sale. The intrusion itself was charged: the indictment unsealed in Manhattan on 6 March 2012 described a crew calling itself Internet Feds which, from December 2010, had gone into the website of an Irish political party and the systems of a security firm and its affiliates, taking confidential data from tens of thousands of user accounts — that case is March 2012's story. The proposals produced no prosecution. Seventeen members of Congress wrote on 1 March 2011 asking whether federal law had been broken, and on 16 March a House Armed Services subcommittee asked the Defense Department and the National Security Agency for their contracts with the three firms. That is what the record holds.

The lasting thing was the method. A complete mail archive, taken and published, proved the most damaging instrument available against a firm that sold discretion, and within five months it was turned on a defence contractor in July and, at Christmas, on a private intelligence company in December. The narrower lesson took longer. HBGary fell to an injectable URL parameter and two eight-character passwords; the next month a phishing message with a spreadsheet attached reached a far larger security company, which said only that information related to its SecurID tokens had been extracted and never said publicly what it was — March 2011's story. Night Dragon's hedge has worn better than its name: attribution from working hours and hosting invoices is still most of what public reports offer, and that paper's appendix said as much. In India the 1948 secrecy clause has company at last, and incidents must now reach CERT-In within six hours.