The New York Times ran it first, on 18 February 2013, and the report itself went up the following day. Mandiant, an American incident-response firm then nine years old, published an account of a group it had tracked since 2006 and called APT1: at least 141 organisations compromised across twenty industries, most of them in the United States, with theft running to hundreds of terabytes. The firm put the average stay inside a victim's network at 356 days and the longest at 1,764 days — four years and ten months. With the report came a digital appendix of more than three thousand indicators, thirteen encryption certificates used by the group, descriptions of more than forty malware families, and a compilation of videos showing the operators at work.

The part nobody had done before was the address. Mandiant identified APT1 as Unit 61398 of the People's Liberation Army — the cover designator for the second bureau of the Third Department of the General Staff Department — and placed it in a twelve-storey building of 130,663 square feet, put up in early 2007, on Datong Road in Gaoqiaozhen, in the Pudong New Area of Shanghai. The report named three personas it had watched working: UglyGorilla, DOTA and SuperHard. The report's own trail attached UglyGorilla to a Wang Dong, later charged in the United States, and SuperHard to a Mei Qiang; the third handle was never publicly tied to a name.

Beijing answered within two days. On 20 February a spokesman for the Ministry of National Defense, Geng Yansheng, told a news conference that Chinese law forbids hacker attacks or any breach of internet security, that the government had always cracked down on such crime, and that the Chinese military had never supported any hacking; Mandiant's claim, he said, had no basis in fact. The foreign ministry's Hong Lei called the allegations unprofessional. The government had denied any involvement in hacking before the report and went on denying it after. Outside the building the argument was simpler and more physical: a CNN crew that drove out to Datong Road to film the gate was chased off by security officers.

The report landed a week into an American policy moment. On 12 February 2013 President Obama had signed Executive Order 13636, Improving Critical Infrastructure Cybersecurity, which defined critical infrastructure as systems and assets whose incapacity or destruction would have "a debilitating impact on security, national economic security, national public health or safety", gave the Attorney General, the Secretary of Homeland Security and the Director of National Intelligence 120 days to issue instructions ensuring the timely production of unclassified reports of cyber threats identifying a specific targeted entity, and directed the National Institute of Standards and Technology to lead a voluntary framework — a preliminary version within 240 days, a final one within a year of the order. The order was about defending things. The report published a week later was about naming the attacker, and it was the naming that the decade copied.

Also that month · 8–20 February

Signed by the guard

On 8 February 2013 Bit9, a Massachusetts company whose product worked by whitelisting — allowing only software an organisation had approved to run — said attackers had taken one of its code-signing certificates and used it to sign malware. The chief executive, Patrick Morley, wrote that "due to an operational oversight within Bit9, we failed to install our own product on a handful of computers within our network". At least three customers, which Bit9 described only as non-critical infrastructure entities, were sent files carrying the company's own signature. Twelve days later Brian Krebs reported the fuller shape: the intrusion had begun in July 2012 with a SQL injection against an internet-facing web server, used to plant the HiKit rootkit; Bit9 was alerted on 29 January 2013 by a third party rather than by a customer; about thirty-three files had been signed with the stolen certificate, of which researchers had so far found two on VirusTotal, both compiled in July 2012. Its chief technology officer, Harry Sverdlove, put it plainly — "this wasn't a campaign against us, it was a campaign using us."

Also that month · 1–22 February

The forum they all read

On 1 February 2013 Twitter's director of information security, Bob Lord, wrote that the company had shut down a live attack moments after finding it, and that attackers may have reached usernames, email addresses, session tokens and encrypted, salted passwords for about 250,000 accounts, whose passwords were reset. The attackers "were extremely sophisticated", he wrote, "and we believe other companies and organizations have also been recently similarly attacked", and he advised disabling Java in the browser. Facebook said on 15 February that employee laptops had been infected, Apple on 19 February that employees' Macs had been, and on 22 February Microsoft's Matt Thomlinson wrote of "a small number of computers, including some in our Mac business unit". The common ground named for Apple and Facebook — and, on researchers' accounts rather than the company's, for Twitter — was iPhoneDevSDK.com, a mobile developers' forum whose owner, Ian Sefferman, said an administrator account had been taken and JavaScript slipped into the site's theme; it served a Java sandbox bypass, CVE-2013-0431, from about 22 January until the attackers themselves removed it on 30 January. Cruder lessons followed: Burger King's account was renamed to McDonald's on 18 February and posted for an hour, Jeep's became Cadillac the next day for ten minutes, and both rivals denied involvement.

India desk · February 2013

The clause about email

India's February began with a law written in a hurry. On 3 February 2013 the President promulgated the Criminal Law (Amendment) Ordinance, 2013, eleven days after the committee headed by Justice J.S. Verma delivered its report on 23 January. Among the offences it inserted into the Indian Penal Code was stalking, Section 354D, which covered following a woman and contacting her repeatedly despite a clear indication of disinterest — and, in the same clause, monitoring "the use by a woman of the internet, email or any other form of electronic communication". Section 354C made voyeurism an offence, including watching or capturing a woman in a private act in a place where she would reasonably expect privacy. On 5 February the trial of five men accused in the December 2012 Delhi gang rape began.

It was the first time Indian criminal law treated the electronic monitoring of a named individual as a wrong in itself, and it arrived by ordinance rather than by debate: the Criminal Law (Amendment) Act, 2013 received assent on 2 April, came into force on 3 April, and applied back to 3 February. What India did not have that month was anything running the other way — an organisation losing other people's data. There was no data protection statute, no duty to report a breach, and no national cyber security policy at all. The policy came on 2 July 2013, released by the Department of Electronics and Information Technology with a target of half a million trained cyber security workers in five years. A mandatory reporting duty waited until the CERT-In rules notified in January 2014, a six-hour clock on it until a CERT-In direction in 2022, and a general data protection statute until 2023.

AI Tech desk · February 2013

The machine that read the journals

IBM put Watson to commercial work on 8 February 2013, two years after the Jeopardy! match, announcing with Memorial Sloan-Kettering Cancer Center and the insurer WellPoint the first products built on the system: Interactive Care Insights for Oncology, which suggested lung cancer treatments to clinicians, and WellPoint's Interactive Care Reviewer, trained on utilisation-management decisions. The hospital said it had given Watson more than 600,000 pieces of medical evidence, two million pages from forty-two journals and some 1,500 real cases; its president, Craig B. Thompson, expected the approach to "profoundly enhance cancer care". The month's other machine story ran through the skull. The State of the Union on 12 February named brain mapping among worthwhile investments, and on 17 February the New York Times reported a planned decade-long Brain Activity Map, which surfaced on 2 April as the BRAIN Initiative. On 28 February Duke published the first brain-to-brain link between rats, an encoder in Natal driving a decoder in Durham over the internet. IBM sold the Watson health data and analytics business to a private equity firm in 2022.

Digital Guard desk · February 2013

What came before Stuxnet

The RSA Conference opened in San Francisco on 25 February 2013, and the strongest work on show looked backwards. On 26 February Symantec published its account of an earlier build of the Natanz weapon, Stuxnet 0.5: operating from 2007, with a command server registered in November 2005, it spread only through Siemens Step 7 project files, exploited no Microsoft vulnerabilities, and closed the valves in the enrichment cascades rather than driving the rotor speeds, replaying recorded readings as it worked. It was written to stop infecting machines on 4 July 2009. The next day Kaspersky Lab and Hungary's CrySyS Lab described MiniDuke, espionage against government bodies in Ukraine, Belgium, Portugal, Romania, the Czech Republic and Ireland, arriving through an Adobe Reader sandbox escape patched on 20 February; its 20-kilobyte backdoor, written in assembler, took its orders from Twitter accounts and fell back on Google searches, a style Eugene Kaspersky recognised "from the end of the 1990s". Symantec's 0.5 remains the earliest version of the operation anyone has published, and vendor retrospectives of that depth became routine rather than remarkable.

⏳ Time capsule — February 2013

  • On 11 February Benedict XVI told a gathering of cardinals in Latin that he would resign, effective at 20:00 on 28 February — the first pope to leave the office since Gregory XII in 1415.
  • On 15 February, at about 09:20 local time, a roughly 18-metre object exploded over Chelyabinsk in the Urals with an energy estimated at 400 to 500 kilotonnes of TNT; 1,491 people sought medical treatment, most of them cut by window glass blown inward by the shock wave.
  • On 20 February Billboard said Baauer's "Harlem Shake" had entered the Hot 100 at number one on the chart dated 2 March, the first to count YouTube plays; about 40,000 imitation videos had been uploaded by 15 February.
  • On 28 February the finance minister P. Chidambaram presented India's Union Budget for 2013–14, which set aside ₹1,000 crore for the Nirbhaya Fund.
Where it stands today — 2026

What the address bought

Fifteen months after the report, on 19 May 2014, the United States indicted five officers of Unit 61398 — Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu and Gu Chunhui — on charges of stealing commercial information and planting malware. None has appeared in an American court; the naming was the instrument, and May 2014 is this month's direct sequel. Mandiant was bought by FireEye in December 2013, kept the Mandiant name when the FireEye product business was sold off to Symphony Technology Group in a deal announced in June 2021, and was bought by Google in a transaction that closed on 12 September 2022. What it made in February 2013 outlasted every one of those owners — the named report, the published indicators, the actor with a designation and a district, the form used again for APT28 in October 2014 and by everyone since.

The rest of the month aged into ordinary practice. A stolen code-signing certificate is now a routine step in a serious intrusion rather than a scandal, and the whitelisting company at the centre of that one bought Carbon Black in February 2014 and in time took its name. Executive Order 13636 produced the NIST Cybersecurity Framework in 2014, revised a decade after that. Java in the browser — which carried one compromised developers' forum into four of the largest technology companies in the world — did not survive the decade. And in India the words put into the Penal Code on 3 February 2013, about monitoring a woman's use of the internet or email, came a full ten years before the country had a general data protection statute.