The email had a one-word subject line: News. The body was a single sentence asking the reader to look at an important article, and the link appeared to run to a Washington Post worldviews blog post dated that same day, 23 April 2013. It was signed with the name, job title, San Diego location and mobile number of an Associated Press colleague. Jim Romenesko's media blog printed the text from an internal AP message, and there was nothing in it to catch the eye. The link led to a login page that was not the one it pretended to be. An AP reporter, Mike Baker, wrote that staff had received an impressively disguised phishing email less than an hour before what followed; an AP spokesperson declined to confirm that timing.
What followed was one sentence. Just after one o'clock in the afternoon in New York the @AP account posted: "Breaking: Two Explosions in the White House and Barack Obama is injured." It came from an account the trading floor treated as a wire, and it was retweeted about four thousand times in under five minutes. The Dow Jones Industrial Average fell 143 points, from 14,697 to 14,554 — roughly one per cent — and Reuters put the momentary loss in the S&P 500's value at about $136.5 billion. Reporting put the round trip, fall and full recovery, at between six and ten minutes. Almost none of the selling was done by people. Joe Saluzzi of Themis Trading told reporters: "With people, you wouldn't have this type of reaction."
The corrections were immediate and, for several minutes, irrelevant. The White House press secretary, Jay Carney, was standing at the briefing room podium and said of the president, "I was just with him." The AP's spokesman, Paul Colford, said the cooperative was working with Twitter to investigate the issue; AP disabled its other Twitter accounts, and the main one, suspended that afternoon, was running again the next day. The Syrian Electronic Army, a group aligned with Bashar al-Assad, claimed the hijack on its own account — a claim rather than a finding, and one that could not be corroborated at the time. The FBI opened an investigation; a spokeswoman, Jenny Shearer, confirmed it and said nothing further. A Securities and Exchange Commission spokeswoman declined to comment at all.
There was no second factor to fail. Twitter offered login verification to nobody in April 2013; it began rolling it out on 22 May, by text message, with Jim O'Leary of its product security team describing the engineering behind it. A newsroom account was a password, typed by whoever had the shift. The collision of the month was that three weeks earlier, on 2 April, the Securities and Exchange Commission had published a report of investigation into Netflix and its chief executive, Reed Hastings, telling companies that social media channels could carry material information under Regulation Fair Disclosure provided investors were told where to look. The regulator had just recognised the channel as a place where price-moving news appears. The channel had a password on it and nothing else.
Fifty million rows, hashed once
On 26 April 2013 LivingSocial, the Washington daily-deals company, emailed customers to say an attack had reached data on its servers. More than 50 million of about 70 million accounts were affected, the company told customers. What went was names, email addresses, dates of birth for some users, and hashed and salted passwords; reporting at the time named the function as SHA1, fast enough by 2013 that salting bought less than the word suggested. The chief executive, Tim O'Shaughnessy, wrote that the company never stored passwords in plain text. Credit card and merchant financial records sat on a separate database and were untouched, the company said. The attorneys general of Connecticut and Maryland wrote jointly on 1 May asking about its data practices. Three days earlier, on 23 April, Verizon had published its Data Breach Investigations Report for 2013 — more than 47,000 incidents and 621 confirmed breaches from nineteen contributing organisations — and found 66 per cent of breaches took months or years to discover, against 56 per cent the year before. LivingSocial's speed was the exception. Its hashing choice was, as October would show at far greater scale, a disclosure choice.
Disaster as a lure
Two bombs went off near the finish line of the Boston Marathon at 2.49pm on 15 April 2013. Three people were killed and 264 injured. Within a day the pattern that has followed every mass-casualty event since was at full speed. John Bambenek of the Internet Storm Center counted 234 newly registered domains carrying the attack's name in the first twenty-four hours, and said he had expected it sooner. Sophos, Kaspersky and AVG warned of emails subject-lined for the explosion carrying the Tepfer trojan, which stole credentials and called home to addresses in Ukraine, Argentina and Taiwan. ESET reported the Kelihos botnet pushing pages that showed a bombing video over a hidden iframe pointing at a Redkit exploit page; Avira's Sorin Mustaca reported the same lures redirecting through three URLs to drop a Java archive on machines with a vulnerable runtime, and Websense identified the flaw the kit was firing as CVE-2013-0422, which Oracle had patched back in January. Eight days earlier a noisier, emptier campaign had come and gone: on 7 April, the eve of Holocaust Remembrance Day, hacktivists aligned with Anonymous ran the first OpIsrael against Israeli government and private sites, among them Yad Vashem and a charity for children with cancer, claiming billions in losses. Israel's National Cyber Bureau assessed it as largely unsuccessful.
The system with no statute
India began installing a national interception system in April 2013, and almost nobody noticed until the summer. Human Rights Watch, writing on 7 June 2013, said the government had begun rolling out the Central Monitoring System state by state that April. The design took the operator out of the loop: telecom companies install Interception Store and Forward servers wired into the lawful-interception equipment they already had, those feed Regional Monitoring Centres, and the centres feed the central system, run through the Telecom Enforcement Resource and Monitoring cells and built by the state-owned Centre for Development of Telematics. Writing for the Centre for Internet and Society from official documents, Maria Xynou reported that as of June 2013 seventy such servers had been bought for six licence service areas, that two were fully installed and integrated, at MTNL and Tata Communications, and that in Delhi the servers were in for every operator and testing was complete.
The legal floor under it was section 5(2) of the Indian Telegraph Act of 1885 and rule 419A of the 2007 amendment rules: an executive authorisation, with no warrant, no judge and no report to Parliament. The Cabinet Committee on Security had approved the system on 16 June 2011 and the pilot finished on 30 September 2011; among the agencies given access were the Intelligence Bureau, the Research and Analysis Wing, the Central Bureau of Investigation, the National Investigation Agency and the Directorate of Revenue Intelligence. Cynthia Wong of Human Rights Watch called the centralised monitoring chilling, given the government's record with the sedition and internet laws. The government's answer was that the system was a privacy improvement: Milind Deora, the minister of state for communications and information technology, argued that routing interception through the central system took telecom company employees out of the loop and made the process more secure, and said a privacy law was being drafted. India then had no privacy statute of any kind: the six-hour duty to report an intrusion arrived by direction in 2022, the data protection law in 2023, and the constitutional question underneath both waited until August 2017.
A brain map and two language teams
On 2 April 2013 President Obama announced the Brain Research through Advancing Innovative Neurotechnologies initiative from the East Room of the White House, with approximately $100 million for work at the National Institutes of Health, the Defense Advanced Research Projects Agency and the National Science Foundation in his proposed budget for the 2014 fiscal year — the American counterpart to Europe's brain-science flagship, and a wager that mapping the organ would eventually inform the machines modelled on it. The month's quieter transactions aged better. On 17 April TechCrunch reported that Amazon had bought Evi, the Cambridge question-answering company once called True Knowledge, for a sum nobody would confirm; Amazon, its investors and its founders all declined to comment, and the deal had in fact closed the previous October. Late in the month Google acquired Wavii, a Seattle startup whose natural-language software compressed news into short updates; it closed the product and moved the team into its Knowledge Graph group. Evi's engine became the core of Alexa, which Amazon shipped with the Echo in November 2014.
Microsoft counts the unprotected machines
On 17 April 2013 Microsoft published volume 14 of its Security Intelligence Report, covering the second half of 2012, and its central finding was about the industry itself: two and a half computers in ten worldwide were running without up-to-date antivirus software, many on preloaded trials that had expired or on protection paused and never switched back on. Tim Rains of Microsoft's Trustworthy Computing group wrote that such machines were "5.5 times more likely to be infected". Six days earlier Kaspersky Lab's research team had published its Winnti report, on a group active since 2009 inside at least thirty-five online gaming companies across four continents, whose real prize was the victims' code-signing certificates — one of them produced the first validly signed 64-bit Windows trojan the researchers had seen. The same week Microsoft withdrew KB2823324, an April update that left Windows 7 machines, mostly in Brazil, unable to boot, and Kaspersky told customers to uninstall it. The stolen signing keys were the quietest item of the month and the one that set the template for the decade's supply-chain compromises.
⏳ Time capsule — April 2013
- On 2 April the Criminal Law (Amendment) Act, 2013 received the President of India's assent, having passed the Lok Sabha on 19 March and the Rajya Sabha on 21 March; it took effect retrospectively from 3 February 2013 and created offences of acid attack, stalking, voyeurism and sexual harassment.
- On 8 April Margaret Thatcher died at the Ritz Hotel in London, aged 87, after a stroke; her ceremonial funeral was held at St Paul's Cathedral on 17 April.
- On 10 April bitcoin touched a momentary high of about $266 on Mt. Gox and fell towards $100 within hours; the next day the exchange suspended trading for twelve hours, saying it needed to catch up with volume.
- On 24 April the nine-storey Rana Plaza at Savar, near Dhaka, collapsed; it held five garment factories, a bank and apartments, and cracks had been found the day before. The search ended on 13 May with 1,134 confirmed dead and about 2,500 people rescued injured.
The password on the wire
Charges came three years late, and to no trial. On 22 March 2016 the Justice Department unsealed two criminal complaints in the Eastern District of Virginia against three Syrian nationals described as current or former Syrian Electronic Army members: Ahmad Umar Agha, then 22, known online as The Pro; Firas Dardar, then 27, known as The Shadow; and Peter Romar, then 36. The counts against Agha and Dardar included conspiring to engage in a hoax regarding a terrorist attack, and the complaint described the April 2013 tweet from the Associated Press account. Romar pleaded guilty. Agha and Dardar were placed on the FBI's Cyber's Most Wanted list with rewards of up to $100,000 each and are believed to be in Syria. Nobody has been tried for the sentence itself.
The rest changed quietly and completely. Twitter shipped login verification a month later, and by 2026 a shared newsroom password without a second factor is an audit finding — because a verified news account turned out to be market infrastructure, the lesson the platform relearned from the inside in July 2020. Machines reading headlines did not go away; they became ordinary, and so did the filters built around them. The storage argument ended too: a fast hash was already the weak choice in 2013, and what October 2013 exposed at Adobe was not hashing at all but reversible encryption — by 2026 either one is an audit finding. LivingSocial was taken over by Groupon on 31 October 2016 for no consideration at all. India's Central Monitoring System was never repealed, only outlived: the 1885 Act that authorised it gave way to the Telecommunications Act, which received assent on 24 December 2023.