At about seven o'clock on the morning of Monday 24 November 2014, staff arriving at Sony Pictures Entertainment's lot in Culver City logged in and found an image of a skeleton and the words Hacked By #GOP. Fortune's later reconstruction described gunfire coming from the speakers, threats scrolling past, and grotesque images of the studio's two most senior executives. The text said that the studio had been warned, that this was a beginning, that internal data including secrets and top secrets had been obtained, and that it would be released to the world unless demands were met. The demands themselves were never stated. The group signed itself Guardians of Peace. Telephones and electronic mail stopped along with the computers.
The destruction took roughly an hour. By the studio's own reckoning, reported by Fortune, the malware erased 3,262 of Sony Pictures' 6,797 personal computers and 837 of its 1,555 servers, overwrote the data seven separate ways, then corrupted the code that starts a machine so that the hardware would not come back. Researchers who obtained samples named the wiper Destover, catalogued elsewhere as Wipall, and described it waiting ten minutes, shutting down the Microsoft Exchange information store, and deleting files on fixed and network-attached drives. The studio fell back on fax machines, notices pinned to walls and paper cheques for about seven thousand employees. Executives had received an extortion message three days earlier, signed God'sApstls, demanding monetary compensation. Almost nobody had read it as a warning.
The publishing began at once. On 27 November five Sony films appeared on file-sharing networks — Fury, then still in cinemas, together with Annie, Still Alice, Mr. Turner and To Write Love on Her Arms. Trackers counted more than 888,000 unique addresses downloading Fury and 184,000 taking Annie; the other three stayed below a hundred thousand each. Through December the group released executive salary lists and employees' personal and family details. An outside firm's count, reported on 7 December, put the unique social security numbers in the files at about 47,000. Medical claims were among them, and so was the corporate mail — including an exchange between the studio's co-chair, Amy Pascal, and the producer Scott Rudin containing racially framed remarks about President Obama, for which both apologised.
The last stage was coercion. On 16 December the group threatened attacks on cinemas showing The Interview, invoking 11 September and naming the premiere set for the 18th. The large chains declined the film; on 17 December Sony withdrew it. On 19 December the FBI attributed the attack to North Korea's government, citing similarities in lines of code, encryption algorithms and data deletion methods to malware North Korean actors had previously built, hardcoded addresses that spoke to known North Korean infrastructure, and resemblance to the March 2013 attacks on South Korean banks and broadcasters. Pyongyang denied it and proposed a joint investigation; Washington refused. Several researchers said publicly they were not persuaded. The film went out online on 24 December and into about three hundred independent cinemas on Christmas Day.
Five stages and a phone network
On 23 November 2014 Symantec published an analysis of a backdoor it called Regin. The thing was built in five stages, each encrypted and concealed except the first, so that an investigator holding one piece learned almost nothing about the rest. It had been in use since at least 2008, went quiet around 2011 and returned from 2013. Symantec put roughly half the victims it had observed in the category of private individuals and small businesses and about 28 per cent in telecommunications, the remainder spread across energy, hospitality, airlines and research; the infections it counted were concentrated in Russia and Saudi Arabia, with Ireland, Mexico, India, Belgium, Austria, Iran, Afghanistan and Pakistan among the rest. Kaspersky Lab published the following day and described modules for reaching a GSM base station controller, which made Regin the first known platform able to watch a mobile network from inside it. Also on 24 November, The Intercept reported that Regin had been found on internal systems and mail servers at Belgacom, the partly state-owned Belgian operator GCHQ had targeted under the codename Operation Socialist. No government confirmed anything.
A ticket, a scanner and a redirect
On 18 November Microsoft broke its monthly cycle for MS14-068, a flaw in the Windows Kerberos key distribution centre, CVE-2014-6324. Any ordinary account holder in a domain could forge a ticket and take the privileges of a domain administrator; the company said it was already in use in targeted attacks and rated it critical on server editions. On 20 November Amnesty International, the Electronic Frontier Foundation, Privacy International and Digitale Gesellschaft released Detekt, a free Windows scanner written by the researcher Claudio Guarnieri that looked for surveillance tools sold to governments: FinFisher's FinSpy and Hacking Team's remote control system among them, alongside DarkComet, XtremeRAT and Gh0st RAT. Its authors said plainly that a clean result proved nothing, since the vendors revise their products; it reached version 2.0 in July 2015 and was later retired. On 27 November the Syrian Electronic Army altered registrar records at GoDaddy for domains belonging to Gigya, an identity provider embedded in the login widgets of hundreds of publishers, and briefly served a pop-up to readers of The Telegraph, The Independent, Forbes and CBC News. Gigya said its platform and its users' data were never reached.
Encryption arrives before the policy
On 18 November 2014 Open Whisper Systems announced that WhatsApp had begun shipping its TextSecure protocol. The scope was narrower than the coverage suggested — the Android client only, one-to-one text messages only, group chats and media still to come — but it was switched on by default, and the announcement called it the largest deployment of end-to-end encrypted communication in history. What made it an Indian story was arithmetic. India had the third-largest online population in the world and was on the way to becoming the service's largest market; the company would put its Indian monthly users at 200 million by February 2017.
The law pointed the other way. The Department of Telecommunications' licence for internet service providers, at clause 2.2(vii) of the standard licence agreement, permitted encryption only up to forty bits without written permission and required anyone using more to deposit the decryption keys in two parts; bulk encryption by providers was barred outright. Section 84A of the Information Technology Act allowed the government to prescribe standards, and no rules were ever made under it, so an application like WhatsApp sat in a gap rather than in compliance. The gap was tested in September 2015, when a draft National Encryption Policy that would have obliged users to keep plaintext copies of their messages for ninety days was published and withdrawn within days, the minister saying it was not the government's view. WhatsApp encrypted everything in April 2016; the Supreme Court declined that June to hear a plea to ban it; the traceability rule of 2021 reopened the argument and WhatsApp took it to the Delhi High Court. CERT-In's six-hour direction and the DPDP Act came later.
Seven microphones and a sentence
On 6 November 2014 Amazon announced Echo, a cylinder with a seven-microphone far-field array and a voice service called Alexa, sold at first by invitation to Prime subscribers; general sale came on 14 July 2015. On 17 November four Google researchers — Oriol Vinyals, Alexander Toshev, Samy Bengio and Dumitru Erhan — posted Show and Tell, a convolutional network feeding a recurrent one that wrote a sentence describing a photograph; on the Pascal set it lifted the BLEU-1 score from a state of the art of 25 to 59, with people at about 69. A Stanford group under Andrej Karpathy and Li Fei-Fei arrived independently at the same design. In the same week a comment of Elon Musk's on an Edge.org thread, deleted soon after and confirmed by a spokesman as authentic but not meant for publication, put the risk of "something seriously dangerous happening" at five years, ten at most. The cylinder became the always-listening microphone in tens of millions of homes; the captioning work became the plumbing beneath every assistant that reads a picture.
A cable, a hotel and a graph
On 5 November 2014 Palo Alto Networks' Unit 42 described WireLurker, which reached iPhones by an unusual road: 467 repackaged Mac applications on the Maiyadi store in China, downloaded 356,104 times in six months, that waited for a handset on the USB cable and installed software through Apple's enterprise provisioning system, jailbroken or not. Ryan Olson, the unit's intelligence director, called it "unlike anything we've ever seen"; Apple revoked the signing certificate. On 10 November Kaspersky Lab published Darkhotel, a group that followed executives on to hotel networks in Asia, served them false updates for ordinary software, abused the trust of at least ten certificate authorities, and withdrew its tools once a target was taken. Roughly 90 per cent of infections were in Japan, Taiwan, China, Russia and South Korea. On 13 November Microsoft bought Aorato, whose graph of normal Active Directory traffic became Advanced Threat Analytics and later Defender for Identity; the price was not disclosed. WireLurker's provisioning trick outlived the malware; Darkhotel outlived rather more, a version of it turning up in Bitdefender's research in July 2017.
⏳ Time capsule — November 2014
- On 9 November Berlin marked twenty-five years since the fall of the Wall with the Lichtgrenze, some 8,000 illuminated balloons set along 15.3 kilometres of the old border and released into the night sky that evening.
- On 12 November the European Space Agency's Philae lander, carried by Rosetta, made the first soft landing on a comet, bouncing about a kilometre across 67P/Churyumov–Gerasimenko before it came to rest in shadow.
- On 13 November Rohit Sharma scored 264 against Sri Lanka at Eden Gardens in Kolkata, the highest individual innings in one-day international cricket.
- On 27 November OPEC ministers meeting in Vienna left the group's output ceiling at 30 million barrels a day; Brent crude fell more than $6 to about $71.25, a four-year low, and kept falling.
The playbook and the default
Twelve years on, November 2014 reads as the month destruction became a normal option. Until then a breach meant data taken; here it meant machines that would not start. The Sony intrusion produced sanctions on 2 January 2015 (January 2015), a settlement of up to $8 million for former employees given final approval in April 2016, and Amy Pascal's departure announced that February. The United States charged Park Jin Hyok in September 2018 over both Sony and WannaCry. The technique outlived the case: the same shape had been seen at Saudi Aramco in 2012 and ran on through NotPetya in June 2017, and through every ransomware crew that now wipes the backups before asking for money.
The month's other stories aged into the ordinary. Regin was an early case of commercial vendors setting out, in public and in detail, a platform that reporting then tied to Western intelligence — a decision that looks routine now and did not in 2014. MS14-068 was an early instance of the pattern that still defines intrusions: one ordinary account, one forged ticket, the whole domain. Detekt itself is gone, but the work it stood for went to Citizen Lab and Amnesty's Security Lab, and the industry it scanned for grew into Pegasus. And the quiet announcement of 18 November — Android only, text only — became the default for several billion people, and the reason the argument over lawful access has run in India, and everywhere else, ever since.