The agents came on 7 June 2011 to his grandmother's sixth-floor apartment in the Jacob Riis Houses on Manhattan's Lower East Side, where Hector Xavier Monsegur was raising two young girls whose mother was in prison. He was unemployed, self-taught and, as Sabu, the most visible member of LulzSec, the group behind that year's intrusions at Sony Pictures and PBS. By Fox News's account he answered the door protesting "I don't have a computer." The next day he agreed to cooperate. On 15 August he pleaded guilty to twelve counts carrying a combined maximum of 124 years and six months, and he went on posting as Sabu — first from FBI offices, later from home, on a laptop the bureau monitored continuously.
The arrangement became public on 6 March 2012, when Fox News reported it and prosecutors in the Southern District of New York unsealed the plea alongside charges against five men. Two were British: Ryan Ackroyd of Doncaster and Jake Davis of Lerwick, in Shetland. Two were Irish: Darren Martyn of Galway, and Donncha O'Cearrbhail of Birr, accused of breaking into an Irish police officer's personal email, finding the dial-in for a 17 January call between the FBI, Scotland Yard and other forces, and secretly recording it — the call Anonymous had published on 3 February. The Garda held him for twenty-four hours and released him without charge. The fifth, Jeremy Hammond, twenty-seven, had been arrested in Chicago late the night before.
Hammond was accused of the December 2011 intrusion at the private intelligence firm Stratfor: about 860,000 subscriber accounts, some 60,000 card numbers and more than $700,000 in unauthorised charges, by the government's count, besides the emails WikiLeaks had begun publishing on 27 February. The charging papers held the month's awkward question. Their chat logs had Hammond discussing Stratfor on 6 December with a cooperating witness, CW-1, presumed to be Monsegur, and, as SecurityNewsDaily read the indictment, the FBI and Monsegur had set up a server for the stolen data before 26 December. The FBI declined to comment. Hammond pleaded guilty in May 2013; that November Judge Loretta Preska gave him the maximum, ten years, citing his "unrepentant recidivism". He insisted he would never have hacked Stratfor without the informant.
Monsegur came before the same judge on 27 May 2014, having served seven months. Prosecutors said his cooperation had helped identify eight co-conspirators and prevent or mitigate more than 300 attacks; Preska called it "truly extraordinary" and sentenced him to time served and a year's supervised release. "I'm not the same person you saw three years ago," he told her. A month earlier the New York Times had reported, from court documents and interviews, that while cooperating he had directed other hackers at a list of more than 2,000 internet domains, among them government sites in Brazil, Iran, Pakistan, Syria and Turkey, and that what they took was uploaded to a server the FBI monitored. Whether the bureau had ordered any of it, the paper said, was unclear.
The alert before the name
On 30 March 2012 Brian Krebs reported that Visa and MasterCard had privately warned banks of a breach at an unnamed American processor, exposing full magnetic-stripe data from cards used between 21 January and 25 February; his financial-industry sources put it at more than ten million numbers. By midday the Wall Street Journal had named Global Payments of Atlanta, and that afternoon the company said it had found and self-reported the intrusion, having determined in early March that card data may have been accessed. On 1 April it said fewer than 1.5 million card numbers "may have been exported" — Track 2 data, but no names, addresses or social security numbers — and Visa dropped it from its register of compliant service providers. The networks' later alerts pushed the window back to June 2011, then to January 2011. By May 2013 the company had booked $121.2 million in expenses net of insurance, while calling the business lost to its delisting immaterial. In July 2013 an indictment unsealed in Newark named Global Payments among the victims of a ring charged with taking more than 160 million card numbers.
Thirty-nine John Does
On Friday 23 March 2012, escorted by US Marshals, Microsoft, the Financial Services Information Sharing and Analysis Center and NACHA, the electronic payments association, seized command servers for Zeus and SpyEye botnets at hosting sites in Scranton, Pennsylvania, and Lombard, Illinois. Their civil suit, filed in the Eastern District of New York on 19 March and announced on the 25th, named thirty-nine John Does, among them the authors of Zeus and SpyEye, known as Slavik and Gribodemon; it was the first botnet case in which Microsoft invoked the racketeering law, and it took some 800 domains. Microsoft counted more than 13 million suspected infections and said it did not expect to have wiped out every Zeus botnet. Abuse.ch's records suggested some seized domains were hijacked sites of legitimate businesses, a San Diego dance school among them; Fox-IT said one botnet was back within twenty-four hours and that the filings exposed nicknames investigators were following. The handles outlasted the servers. Slavik was charged as Evgeniy Bogachev in June 2014 and has never been arrested; Gribodemon, Aleksandr Panin, was sentenced in Atlanta in April 2016 to nine and a half years.
A lure about missile defence
On 29 March 2012 Trend Micro published Luckycat Redux, its account of a campaign it had followed since at least June 2011: ninety attacks and 233 compromised computers, by its count, against aerospace, energy, engineering, shipping and military research targets in India and Japan, and against Tibetan activists. Each audience had its own bait — a document on India's ballistic missile defence programme, a PDF sent amid the confusion after the Fukushima accident, the self-immolations in Tibet — and most samples exploited a Word flaw Microsoft had patched in November 2010. The researchers traced one registration, through a QQ number, to a hacker who had once recruited for a research project at Sichuan University's Information Security Institute. Their conclusion stopped where the evidence did: the operators used Chinese-language settings and logged in from Chinese addresses. Trend Micro named no government.
Two other documents that month looked at India itself. On 12 March Reporters Without Borders added it to its countries "under surveillance", citing monitoring stepped up since the 2008 Mumbai attacks, the IT Rules of 2011 and pressure on BlackBerry's maker for access to encrypted business traffic. In a written answer to the Lok Sabha that week, the minister of state for communications and IT, Sachin Pilot, said 112 government websites had been hacked from December 2011 to February 2012 — state sites from Andhra Pradesh to Manipur, the finance and health ministries, the Planning Commission — and that BSNL's had been hacked on 4 December by a group described as Pakistani. A national interception system followed in April 2013; a duty to report incidents came by direction in 2022, and a data protection statute in 2023.
A Turing Award for cause and chance
On 15 March 2012 the ACM named Judea Pearl of UCLA winner of the 2011 A.M. Turing Award, worth $250,000, for his calculus of probabilistic and causal reasoning. Pearl had given machines a way to weigh uncertain evidence, coining the term Bayesian network in 1985, and in Causality (2000) a formal way to tell what an intervention would do from what data merely showed. Google's Alfred Spector said that before Pearl most AI systems reasoned in true and false and "had a hard time with 'maybe'". IBM was finding Watson work: on 5 March Citigroup agreed to explore its use in banking, and on 22 March Memorial Sloan-Kettering agreed to build on it a decision-support tool for oncologists, beginning with lung, breast and prostate cancers. The causal half of Pearl's work became, in The Book of Why (2018), his case against the deep learning that came to dominate the field and took its own Turing Award in March 2019: systems that fitted curves to data, he argued, could not answer questions of cause.
Four teams poison the Kelihos botnet
On 28 March 2012 Kaspersky Lab, CrowdStrike, Dell SecureWorks and the Honeynet Project said they had disabled the second Kelihos botnet, a peer-to-peer spam network with no single command server to seize. From 21 March they fed the bots poisoned peer lists until most talked only to a sinkhole, while a false list of job servers kept new commands out; within hours its owners had released a new version. The partners' counts of machines cut off ran from 109,000 to over 129,000, roughly a quarter of them in Poland, and the machines stayed infected. On 29 March Seculert reported that a Facebook worm which had compromised over 70,000 accounts was spreading the new version and could win back the sinkholed machines; Kaspersky replied that the sample belonged to a separate botnet, CrowdStrike that there was "no known means" of regaining control. In 2018 Peter Levashov, arrested in Barcelona in April 2017, pleaded guilty in Connecticut, admitting to running Kelihos and, before it, the Storm and Waledac botnets; in 2021 he was sentenced to time served.
⏳ Time capsule — March 2012
- On 4 March Vladimir Putin won Russia's presidential election in the first round, for a term lengthened by constitutional amendment from four years to six; OSCE observers assessed the count negatively in almost a third of the polling stations observed.
- On 13 March Encyclopaedia Britannica's president, Jorge Cauz, said the 2010 edition — thirty-two volumes weighing 129 pounds — would be its last in print, 244 years after the first; print had fallen to less than one per cent of revenue.
- On 16 March, at Mirpur in the Asia Cup, Sachin Tendulkar made 114 against Bangladesh and became the first batsman to score a hundred international hundreds; Bangladesh won by five wickets.
- On 26 March James Cameron took the Deepsea Challenger alone to the floor of the Challenger Deep, recording a maximum depth of 10,908 metres — the first solo dive there, and the first crewed descent since the Trieste's in 1960.
What the bureau allowed
Neither American case went to trial, so the question March 2012 raised was tested in neither: how far a hacker working for the government may go while it watches. What exists are fragments — Hammond's statement, the Times's reporting, a government filing that counted attacks prevented rather than allowed. Ackroyd and Davis were sentenced at Southwark Crown Court in May 2013, to thirty and twenty-four months; Martyn and O'Cearrbhail, who admitted defacing Fine Gael's website, were spared jail in Ireland that October. Hammond left prison for a recovery house on 17 November 2020, after a spell of civil contempt for refusing to testify to a grand jury investigating WikiLeaks. Monsegur moved into security work, and in December 2014, as Washington moved to blame North Korea for the Sony Pictures intrusion, was among those who publicly doubted it.
The rest of the month set patterns that held. Stripe data kept leaving card readers — at Target in December 2013, at Home Depot in September 2014 — and only the American chip liability shift of October 2015 began, slowly, to retire the swipe. Microsoft's Digital Crimes Unit kept coming back, against ZeroAccess among others, and the Justice Department used court orders against GameOver Zeus in June 2014; the man it named as Slavik is still unarrested in 2026. Luckycat named no state, and attribution by unit number waited for February 2013. The government that counted 112 hacked websites in a parliamentary answer now has a six-hour reporting rule and a data protection statute to count by.