The pump served the Curran-Gardner Public Water District, west of Springfield, Illinois, and it failed on 8 November 2011. A contract computer repairman looking into it went through the logs of the district's remote management system and found a login from an internet address in Russia, months old. The district reported it. On 10 November the Illinois Statewide Terrorism and Intelligence Center issued a report headed "Public Water District Cyber Intrusion", which said an intruder had reached the control system with credentials stolen from its software vendor, had been inside for two to three months, and had switched the pump on and off until it burned out. On 17 November a control-systems consultant, Joe Weiss, published the report's substance on his blog; the Washington Post carried it on 18 November.

What the logs held was a man on holiday. Jim Mimlitz runs Navionics Research, a small integrator in Missouri and the firm that had set up the district's remote management system, and in June 2011 he had logged into it from Russia, where he was travelling with his family, at Curran-Gardner's request, to look at historical data. His user name sat in the log beside a Russian address because he had put it there. Nobody telephoned him before the report went out. Five months separated that session from the pump's failure, and by his account he had been reading charts rather than operating anything. Interviewed afterwards by Wired and by msnbc.com, he said one phone call would have defused the whole thing, and that he had not been trying to hide anything.

Homeland Security took the fusion centre's material, sent specialists to Illinois for forensic work on site, and stated its conclusion within days of the Washington Post story: after detailed analysis, DHS and the FBI had found "no evidence of a cyber intrusion" into the Curran-Gardner system. There had been no malicious traffic from Russia or any foreign entity, no stolen credentials, and no involvement by the vendor. The pump had failed as pumps fail. Earlier, a district trustee, Don Craven, had told a local television station there was some indication of a breach. Weiss's own account was that he had published because the report carried a state fusion centre's name and he had had no reason to doubt it; his complaint after the correction was with the reporting machinery rather than the pump, and a document of that kind, he argued, should not have gone out before anyone checked it.

Homeland Security's caution produced its own reaction. On 18 November, while the department was still saying it was gathering facts and had no corroborated data indicating a risk to critical infrastructure or a threat to public safety, someone using the name pr0f posted screenshots of the interface controlling the water and sewer plant at South Houston, Texas, saying he disliked the way Homeland Security played down the condition of American infrastructure. He said the console had been reachable from the internet behind a three-character password, that he had altered nothing, and that he had no appetite for vandalism. South Houston's mayor, Joe Soto, said no damage had been done to the sewer system. The false alarm and the open console arrived in the same week; a decade later a Florida water plant produced the same confusion (February 2021).

Also that month · 8–9 November

Four million machines, seven names

On 8 November 2011 the FBI took the servers, and on 9 November the case was made public: Operation Ghost Click, a two-year investigation with Estonian police, and an indictment in the Southern District of New York charging six Estonian nationals and one Russian over the DNSChanger fraud. Six were arrested in Estonia; the seventh, Andrey Taame, was not in custody. The malware, spread as a codec, rewrote a machine's DNS settings so that its traffic passed through name servers the defendants controlled, which substituted advertising and redirected searches; prosecutors put the count above four million computers in more than a hundred countries, about half a million of them in the United States, and the proceeds at more than $14 million. Because pulling the rogue servers would have cut those machines off, the court allowed clean replacements, run by the Internet Systems Consortium, to stand in their place. The day they were switched off belongs to July 2012. In February 2012 Harju County Court in Estonia declined to block the extradition of the men it was holding, and the ring's organiser, Vladimir Tsastsin, pleaded guilty in New York in July 2015.

Also that month · 6–28 November

The software nobody had chosen

On 12 November 2011 a researcher, Trevor Eckhart, wrote up what he had found in diagnostic software called Carrier IQ, preinstalled on handsets sold by American carriers, using training manuals copied from the company's own public website. On 16 November Carrier IQ sent him a cease-and-desist letter claiming copyright in the manuals and alleging false statements, with damages of up to $150,000 a violation. The Electronic Frontier Foundation took his side and called the claim unfounded; on 23 November the company's chief executive withdrew the letter and apologised for any trouble it had caused. On 28 November Eckhart published a video of the software handling keystrokes, search terms, addresses and the text of messages; Carrier IQ said its metrics and tools were not designed to deliver such information. A Senate subcommittee chairman wrote to the company days later, and investigations followed. On 6 November, earlier in the month, Steam's community forums were defaced; Valve disclosed on 10 November that the intruders had also reached a database of user names, hashed and salted passwords, purchases, addresses and encrypted card numbers, with no evidence that any of it had been taken.

India desk · November 2011

The argument in London

On 1 and 2 November 2011 the British Foreign Office gathered more than seven hundred people from sixty countries, and over a hundred businesses, at the Queen Elizabeth II Conference Centre for the London Conference on Cyberspace — the first of the London Process. William Hague chaired it across five themes, and his closing statement settled on the formula that what is unacceptable offline is unacceptable online, while warning that security must not be bought at the price of fundamental rights. India's delegation argued that the safety of cyberspace was a global public good to be secured jointly, and that the rules for it should be settled between governments. Days earlier, at the United Nations General Assembly in October, India had proposed a new UN body for internet-related policy — a multilateral home for questions the conference in London preferred to leave with governments, companies and civil society together.

At home the same ministry was in a narrower conversation. By early December, the Committee to Protect Journalists reported, the information technology ministry had held six meetings since September with the leading social networking companies; what was asked of them became public argument that December, and reached a Delhi court the following month. None of it ran on a clock. A defaced Indian website or a compromised server in November 2011 carried no statutory deadline for telling anyone; since CERT-In's direction of April 2022 an incident must be reported within six hours. The conference series India argued with in London, India went on to host: the fifth met in New Delhi on 23 and 24 November 2017, with some three and a half thousand participants.

AI Tech desk · November 2011

What Siri would not answer

Six weeks after the assistant arrived with the iPhone 4S, users began comparing what it would find and what it would not. Siri would find Viagra and escort services, and in several states offered crisis pregnancy centres, but returned nothing useful for abortion clinics; on 30 November 2011 Nancy Keenan of NARAL Pro-Choice America wrote to Tim Cook that the answers were neither accurate nor complete, the American Civil Liberties Union published a similar complaint, and a MoveOn petition gathered tens of thousands of signatures within days. Apple's spokeswoman, Natalie Kerris, replied the next day that these were "not intentional omissions", that the assistant was still in beta, and that the gaps would be closed in the coming weeks; the searches were not reliably fixed until early 2016. Two other announcements aged better. On 8 November Honda unveiled an all-new ASIMO with what it called autonomous behaviour control, able to decide its next movement without an operator, and on 22 November Microsoft bought VideoSurf, whose computer vision read individual video frames, to sharpen search on the Xbox.

Digital Guard desk · November 2011

Symantec's exit, and an unpatched font

On 14 November 2011 Huawei agreed to buy Symantec's 49 per cent of Huawei Symantec Technologies, the security and storage venture they formed in 2008, for $530 million; the sale closed the following March. Enrique Salem, Symantec's chief executive, said the company had met the objectives set four years earlier and left with a good return, and American reporting noted the partnership had grown awkward for a firm selling to federal agencies while Congress and the administration examined Huawei's expansion — weather that worsened, and by 2020 Huawei's equipment was being ordered out of British and American networks. The month's other work was unglamorous. CrySyS Lab in Budapest had recovered Duqu's installer, a Word document exploiting an unknown flaw in the Windows kernel's TrueType font parsing; Microsoft issued an advisory and a one-click workaround on 3 November 2011, said the risk to customers remained low, and left the repair to December. On 30 November Kaspersky's Vitaly Kamluk counted more than a dozen CentOS command servers, in Vietnam, India, Belgium and elsewhere, every one wiped by the attackers on 20 October.

⏳ Time capsule — November 2011

  • On 8 November Sachin Tendulkar became the first cricketer to reach 15,000 runs in Test matches.
  • On 10 November Dutch researchers, writing in Nature, reported driving a single molecule across a copper surface with electrical pulses from a scanning tunnelling microscope; the press called it the world's smallest electric car.
  • On 11 November The Elder Scrolls V: Skyrim went on sale for PC, PlayStation 3 and Xbox 360; by the same day Modern Warfare 3 had sold more than 6.5 million copies in North America and the United Kingdom.
  • On 26 November an Atlas V lifted the Mars Science Laboratory from Cape Canaveral carrying the rover Curiosity, which was still driving on Mars in 2026.
Where it stands today — 2026

A log line is not an attribution

Illinois settled a point that keeps needing settling: a foreign address in a log is a fact about routing, not a finding about an intruder. The machinery built to share warnings turned one unverified paragraph into a worldwide story in a week, and a bipartisan Senate subcommittee report of 3 October 2012 found fusion centre intelligence to be of uneven quality, often shoddy and rarely timely. The exposure pr0f pointed at was real. In late 2023 the FBI, CISA, the NSA, the EPA and partner agencies in Israel, Canada and Britain attributed the defacement of Israeli-made Unitronics controllers at water and wastewater plants — at least thirty-four of them in American systems — to actors affiliated with Iran's Islamic Revolutionary Guard Corps, reached through devices left with default passwords.

The month's other stories closed more tidily. DNSChanger's replacement servers ran until July 2012, and the men arrested in Estonia were cleared for extradition in February 2012, with the ring's organiser pleading guilty in New York in 2015 and others drawing sentences of a few years. Carrier IQ's measurement business was absorbed by AT&T at the end of December 2015, and the practice it was caught doing quietly now lives behind consent screens on every handset. Valve's 2011 file, hashed and salted, aged better than most. What has not closed is the gap the water story opened between a system's owner, its integrator and the agency told about it: in 2011 nobody had to tell anyone anything on a deadline. India's answer to that came in two parts — a reporting clock in 2022, and a privacy statute in 2023.