The Wall Street Journal published it on 14 February 2012, hours before China's vice-president, Xi Jinping, met Barack Obama. Intruders had moved through Nortel Networks' computers for nearly a decade, from at least 2000, on seven passwords taken from senior executives, a chief executive's among them, and had carried off technical papers, research and development reports, business plans and employee email. The source was Brian Shields, nineteen years at the company and its senior adviser for systems security, who had led the internal investigation. "They had access to everything," he said. There was not much left of Nortel to embarrass. Valued at C$398 billion in September 2000, it had filed for bankruptcy protection on 14 January 2009 and spent the three years since selling itself in pieces.
The first sign had come in 2004, when an employee noticed that a senior executive appeared to be downloading an unusual set of documents, and the executive denied it. Shields's team found a few machines on the network sending small bursts of data, every month or so, to addresses in Shanghai. Records from his inquiry, reported by Global News in 2020, show one address registered to a company called Shanghai Faxian taking 779 documents on 24 April 2004 through the account of the chief executive, Frank Dunn — four days before Nortel fired him over its accounting. The company's response, by Shields's account, was to change the seven passwords. An investigation of about six months fizzled out for want of leads, and Nortel made no effort to find out whether its products had been compromised.
In March 2009 Shields won approval to examine two suspect computers and was then laid off; the results arrived the day after he left, showing rootkits reporting over an encrypted channel to an address near Beijing. Rehired as a consultant, he sent the chief executive, Mike Zafirovski, a report that year: the intruders were still inside. The buyers were not told. Avaya said it learned of the breach only after its purchase, and former staff said many colleagues had carried Nortel laptops into Avaya and Genband and connected them there. Zafirovski told the Journal that those who looked into the hacking did not believe it was a real issue. The case for China rested on the addresses, and the Chinese embassy said cyber attacks were transnational and anonymous and should not be assumed to come from China without thorough investigation.
Nortel ended in liquidation rather than a verdict. Its patents had already gone for $4.5 billion in June 2011 to a consortium of Apple, Microsoft, Research In Motion, Sony, Ericsson and EMC, and the estates fought over the $7.3 billion the pieces raised until judges in Delaware and Ontario approved a settlement on 24 January 2017, after nearly $1.9 billion in fees. A University of Ottawa study of the collapse, published on 17 March 2014, found no evidence that foreign espionage had contributed to the downfall and considered it unlikely; one of its authors said the company could not blame its failure on hacking by any party. Shields, interviewed by Global News in 2020, said the tactics Mandiant had attributed to a Chinese military unit in Shanghai in February 2013 fitted everything he had seen.
Anonymous on the line
On 3 February 2012 Anonymous published a recording of a 17 January conference call between the FBI and Scotland Yard about the hunt for Anonymous and LulzSec, with the invitation that had gone to some forty police officials in the United States and several European countries, dial-in code included. The FBI confirmed the recording was genuine and said none of its systems had been breached; suspicion fell on a participant's private email account, and who had been listening is March's story. On 6 February the same banner released emails from 78 accounts at Syria's Ministry of Presidential Affairs, several reportedly using the password 12345, among them coaching for Bashar al-Assad's December interview with ABC; government forces were attacking Homs that day. On 27 February WikiLeaks began publishing some five million emails, by its count, taken from the intelligence firm Stratfor in December, and said they showed Stratfor monitoring Bhopal activists for Dow Chemical, which said it had operated within the law. Stratfor called the theft deplorable and said some emails might be forged or altered. On 28 February Interpol announced 25 arrests of suspected Anonymous members in Argentina, Chile, Colombia and Spain; that night its website went offline, and Anonymous claimed it.
Late, and in the small print
On 2 February 2012 Reuters reported what VeriSign, which runs the .com and .net registries, had put in a quarterly filing on 28 October 2011: several successful attacks on its corporate network in 2010, information taken, and a security team that had not told management until September 2011. It said it had no indication the domain name system was affected, and would not say what had gone. Reuters found the paragraph among more than 2,000 filings made after the SEC's staff advised, on 13 October 2011, that material intrusions belonged in disclosures. On 17 February the Wall Street Journal reported that Google and other advertising companies had used code submitting an invisible form to slip past Safari's default block on third-party cookies — found by Jonathan Mayer, a Stanford graduate student. Google said the Journal had mischaracterised what happened and began removing the cookies; on 9 August it agreed to pay the FTC $22.5 million, the agency's largest penalty for breach of one of its orders, without admitting liability. Path, whose iPhone app had been found early in the month uploading users' entire address books, settled FTC charges for $800,000 a year later.
The servers in Mumbai
The servers were in Mumbai, and government officials had already inspected them. Late in February 2012 reports led by the Times of India said Research In Motion would shortly allow lawful interception of BlackBerry Messenger and consumer email whenever India's intelligence agencies suspected terrorism or other serious crime — the paper end of a quarrel in which the government had threatened to shut the service down. Corporate traffic stayed outside. Companies running their own BlackBerry Enterprise Servers held their own keys, which RIM had always said it did not have, and the Intelligence Bureau's director, Nehchal Sandhu, was reported as saying such communications were not of high concern anyway. The government would instead ask Vodafone, Airtel and RCom for a list of the roughly five thousand such servers in the country.
Paper took seventeen months to become plumbing. In August 2012 officials were reported as claiming that RIM had handed over its keys, which RIM denied; only in July 2013 did a Department of Telecommunications document call the interception system ready, still without enterprise mail. The month's louder traffic ran across the eastern border. From about 9 February Bangladeshi groups defaced Indian websites, the Border Security Force's reportedly among them, in protest, they said, at killings by its personnel at the border; one group claimed twenty thousand sites, a figure nobody verified, Indian groups answered against Bangladeshi government sites, and later in the month the Bangladeshi side was reported to have called a halt. None of it had to be reported to anyone on any clock. Since CERT-In's direction of April 2022, a defacement must be reported within six hours.
Target's pregnancy score and the big-data age
On 16 February 2012 the New York Times Magazine published online Charles Duhigg's account of how a Target statistician, Andrew Pole, had found about 25 products that, analysed together, gave each shopper a "pregnancy prediction" score and an estimated due date, so that coupons could be timed to each stage; unscented lotion and mineral supplements were among the signals. Its most retold scene, a father protesting in a store outside Minneapolis at baby coupons sent to his daughter, still at school, who proved to be pregnant, rested on one unnamed employee's account. Target told Duhigg that almost all of his statements contained inaccurate information, without saying which, and that it complied with all federal and state laws. Five days earlier Steve Lohr's The Age of Big Data had set McKinsey's projected shortage of analysts beside warnings of false discoveries and discriminatory inference. The point, that an inference can reveal more than the data beneath it, reached statute in 2018: California's privacy law counted inferences drawn to profile a consumer as personal information.
AVG floats, Kaspersky buys out its investor
On 2 February 2012 AVG Technologies, the Czech-born maker of free anti-virus, began trading on the New York Stock Exchange. Priced the day before at $16, the bottom of its range, the flotation raised $128 million, half of it for existing holders, and the shares closed the day nearly a fifth lower. The prospectus counted some 106 million active users, about 15 million of them paying, and said growth rested partly on converting free users; a third of revenue in 2011's first nine months came not from subscriptions but mainly from a search toolbar, Google paying AVG a share of its search-advertising revenue. The next day Kaspersky Lab said it would use accumulated profits to buy back the stake General Atlantic had taken in January 2011, and Eugene Kaspersky, reported by Reuters from an analysts' conference in Cancún, dropped the idea of a listing, saying of the company's culture, "I don't want to change." Avast, which had filed for its own listing on 21 December 2011, withdrew that July, citing market conditions, and in July 2016 agreed to buy AVG.
⏳ Time capsule — February 2012
- On 12 February Adele won all six Grammy Awards for which she was nominated, among them album, record and song of the year, and sang "Rolling in the Deep" at the ceremony in Los Angeles — her first performance since throat surgery the previous autumn.
- On 26 February The Artist won Best Picture at the 84th Academy Awards, the second silent feature to do so after Wings at the first ceremony in 1929, and Jean Dujardin became the first French actor to win Best Actor.
- On 28 February Virat Kohli made 133 not out from 86 balls in Hobart as India chased Sri Lanka's 320 in 36.4 overs, inside the forty that earned a bonus point.
- On 29 February the Raspberry Pi Model B went on sale at $35, and demand crashed the websites of both licensed distributors, Premier Farnell and RS Components.
The intrusion that outlived the company
Nortel became a standing example of how long an intruder can stay: present from about 2000, noticed in 2004, still reporting to an address near Beijing in 2009, in a company that had stopped looking after six months. Its harder legacy was the question the Journal put to the buyers. Avaya, Ciena, Ericsson and Genband bought businesses out of a network that, by Shields's account, had never been cleaned. In 2016 Marriott bought Starwood's network already occupied (November 2018), and its October 2024 settlement with 49 states and the District of Columbia required improved diligence in relation to future acquisitions. The patents outlived Nortel too: Rockstar sued Google, Samsung and others in 2013, and at the end of 2014 sold some 4,000 of them to RPX for $900 million.
Disclosure moved further than detection did. The SEC, whose 2011 guidance VeriSign's paragraph had followed, imposed its first penalty for a breach kept from investors in April 2018; since December 2023 an American public company has had four business days to disclose an intrusion once it judges it material, and the 2011 guidance itself was withdrawn in May 2025. Google paid its $22.5 million without admitting liability, and in March 2020 Safari began blocking third-party cookies by default across the board, closing the gap outright. Public attribution of Nortel's intruders has rested on addresses, one investigator's reading of them and later journalism. In India, where that month's questions had no privacy statute to be tested against, one arrived only in 2023, with the DPDP Act.