On 17 December 2014 the Bundesamt für Sicherheit in der Informationstechnik, Germany's Federal Office for Information Security, published its annual assessment of the state of IT security in the country. Most of it was the ordinary accounting of malware families, botnets and unpatched software. One passage was not. It described an attack on a steel mill in which intruders had used spear-phishing and social engineering to reach the office network, and from the office network had moved into the production network. Control components and entire production machines failed. A blast furnace could not be shut down in a regulated way and was left in what the report called an undefined state. The damage to the plant, the office wrote, was massive.
What the report withheld was almost everything else. It did not name the mill. It did not name the attacker, or say where the office believed the attacker sat. It gave no date for the intrusion, no duration, no malware family, no account of how long the intruders had been inside, and no figure for the damage it had just called massive. German incident reporting in 2014 was voluntary and anonymised: an operator that told the BSI what had happened did so on the understanding that it would not be identified. It did say one thing about the intruders: their skills were advanced in conventional IT security, and they also held detailed knowledge of the industrial control systems and production processes in use.
The machine at the centre of the account is not a computer with consequences attached. It is a shaft of iron ore, coke and limestone held in continuous reaction, difficult to start and difficult to stop, and run without interruption for long periods for exactly that reason. The hot blast enters it at between 900 and 1,300 degrees Celsius; the combustion zone in front of the tuyeres runs hotter still, two thousand and beyond. Molten iron and slag are drawn off by drilling out a refractory clay plug and letting them run down a trough. Bringing such a vessel down is a procedure rather than a switch, and what the BSI described was a plant that had lost the ability to carry the procedure out. What broke inside it afterwards, the report did not say.
The framing that stuck came from the press, not the office: after Stuxnet, this was the second publicly known case of a computer intrusion causing physical destruction. Analysts at the time were more careful, and pointed out that nothing in the passage settled whether the furnace had been the target or the casualty — whether someone had set out to wreck a plant or blundered into the controls of one while looking for something else. No one was charged. The mill has never been officially identified; later publications have attached a company name to it, but the BSI has never confirmed one. Germany's answer was legislative: the IT Security Act, in force from July 2015, turned reporting to the BSI from a courtesy into a duty for operators of critical infrastructure.
A comedy, a threat and a Christmas
The intrusion at Sony Pictures belongs to November's edition; December belongs to what the stolen documents did once loose. Batches appeared through the first half of the month, and on 11 December correspondence between the studio's co-chairman, Amy Pascal, and the producer Scott Rudin was published, including an exchange joking about which films the president might like; both apologised the same day, Pascal calling the content insensitive and inappropriate. On 16 December a message from the group calling itself Guardians of Peace named The Interview for the first time and told cinema-goers to remember the eleventh of September 2001. AMC, Regal, Cinemark, Cineplex and Carmike withdrew, and on 17 December Sony cancelled the 25 December release. On 19 December the FBI publicly attributed the attack to North Korea; Pyongyang had already denied any hand in it, calling the accusation a wild rumour while describing the hack as a righteous deed, and a number of independent researchers disputed the bureau's evidence for months afterwards. The president said at his year-end press conference that the studio had made a mistake, and that nobody should be intimidated into that pattern. On 23 December Sony reversed course: 331 independent cinemas on Christmas Day, and a digital release the day before through Google Play, Xbox Video and YouTube. Pascal announced her departure on 5 February 2015.
A registry, a cloud drive and a Christmas Day
On 10 December Kaspersky Lab published its analysis of Cloud Atlas, an espionage framework found that August and tied to RedOctober, which the same laboratory had exposed the year before; in at least one case a computer had been attacked twice in two years, once by each. Victims were counted mainly in Russia and Kazakhstan, with a handful in Belarus, India and the Czech Republic; command and control ran over WebDAV on free cloud accounts. Blue Coat had published parallel research on what it called the Inception framework; Kaspersky noted it without claiming the two were one thing. On 16 December ICANN disclosed that email credentials belonging to several staff had been taken in a late-November spear-phishing campaign, in messages forged from ICANN's own domain, and used to reach the Centralized Zone Data System, the Governmental Advisory Committee wiki, the blog and the WHOIS portal; names, addresses, telephone numbers and salted password hashes of zone-file users were exposed. The IANA systems, ICANN said, were untouched. On 25 December a group calling itself Lizard Squad flooded Xbox Live and the PlayStation Network offline; Microsoft's service returned within about a day, Sony's took longer.
Thirty-two addresses
On 17 December 2014 the Department of Telecommunications ordered India's licensed internet providers to block thirty-two web addresses with immediate effect. The list was not a list of jihadist forums. It took in GitHub and its Gist service, Vimeo, Dailymotion, Weebly, Pastebin, the Internet Archive and SourceForge — the ordinary plumbing of software development and video. The basis was an advisory from the Mumbai police's Anti-Terrorism Squad, and the reason, once one was given, was that the sites carried Islamic State material: many of them, the government said, required no authentication to post anything, and were being used to circulate it. The power was section 69A of the Information Technology Act, 2000, which permits blocking in the interest of the sovereignty and integrity of India, the security of the state and public order, and which operates in confidence.
Nobody outside the providers knew. The circular carried no public notice and no expiry, and it surfaced only on 31 December, when a copy leaked and developers who had found a code repository unreachable learned why. The ministry then said it had begun unblocking sites that had removed material or cooperated with the investigation, and the reversals ran into the first days of January (January 2015). Three months later, on 24 March 2015, the Supreme Court struck down section 66A of the same Act in Shreya Singhal — and expressly upheld section 69A, describing it as narrowly drawn with adequate safeguards. The blocking power survived the judgment that made India's free-speech law famous; so did its confidentiality. India's later duties on the other side of the relationship — CERT-In's six-hour direction of 2022 and the DPDP Act of 2023 — came from elsewhere entirely.
Hawking's warning, and a Montreal paper
On 2 December 2014 the BBC published an interview in which Stephen Hawking, asked about the new system Intel had built to help him speak — its predictive layer supplied by the British firm SwiftKey, which learned how he wrote and offered his next word — replied that 'the development of full artificial intelligence could spell the end of the human race'. Six days later the field itself convened at the Palais des congrès in Montreal for NIPS, running to 13 December, where among some four hundred accepted papers sat one by Ian Goodfellow and colleagues, posted to arXiv on 10 June, which set a generator against a discriminator and let each train the other: generative adversarial networks. On 15 December Microsoft opened a sign-up preview of Skype Translator, spoken English and Spanish, to Windows 8.1; on 17 December Baidu's researchers posted Deep Speech, an end-to-end recogniser they said handled noisy audio better than commercial systems did. The quiet paper travelled furthest: three years on, the technique had given ordinary language a new noun (December 2017).
A FLASH alert, and Operation Cleaver
On 1 December 2014 the FBI sent American businesses a five-page FLASH alert about malware that overwrote the master boot record and rebooted the machine after a two-hour countdown; samples carried configuration files built on Korean-language systems, and the victim went unnamed. It was the bureau's first such warning over destructive malware against an American company, and vendors already had detections for the family, Destover. The next day Cylance — a young endpoint firm selling machine-learning prevention rather than signatures — published Operation Cleaver, tracing a campaign against more than fifty organisations in sixteen countries, airlines, airports and energy among them, to operators it placed in Iran; a spokesman for Iran's United Nations mission called the report a 'baseless and unfounded allegation'. Mid-month brought a counterweight: Alert Logic likened a Linux permissions design to Heartbleed, and Red Hat replied that expected behaviour had been read as a flaw. The pitch outlasted the company: BlackBerry bought Cylance in 2018 and sold it a decade after Cleaver for a fraction of the price, by which time no serious product sold on signatures alone.
⏳ Time capsule — December 2014
- On 3 December Japan's space agency launched Hayabusa2 on a six-year round trip to an asteroid and back.
- On 5 December NASA's Orion capsule made its first flight test, lifting off at 7:05 Eastern time and splashing down safely in the Pacific.
- On 17 December Barack Obama and Raúl Castro announced simultaneously that the United States and Cuba would move to restore relations; the imprisoned contractor Alan Gross was released, Cuba freed 53 political prisoners, and Pope Francis had mediated.
- On 30 December, after a drawn Test at Melbourne, MS Dhoni retired from the format; Virat Kohli took the captaincy for the match at Sydney.
The citation nobody can check
A decade on, the German steel mill is the case everyone cites and nobody can verify. Its value was never in the detail, because there was none. It was in the fact of it: a national security agency stating, in a document of record, that an intrusion begun with an email had ended in a wrecked machine. Everything in the archive's industrial thread reads back to that paragraph. A year later the lights went out for Ukrainian utilities (December 2015); the following December the country's grid was reached again (December 2016); and in December 2017 researchers disclosed an intrusion, some months old by then, at a Saudi petrochemical plant that had reached a safety instrumented system (December 2017) — the first known case in which the mechanism that exists to stop people being killed was itself the target.
The month's other stories aged into precedents too. Sony's December established that a company could be made to change a commercial decision by threat, and then, six days later, that the decision could be changed back; both halves are still argued from. ICANN's loss of staff credentials to an email forged from its own domain is the same sentence written about a thousand organisations since. Cloud Atlas mattered less for what it took than for what it showed: an operation exposed and dismantled can return with new code against the same victims. And the thirty-two addresses blocked in Delhi were the start of a habit: India would go on to order blocks and network shutdowns at a scale nobody in 2014 anticipated, under the section the Supreme Court left standing.