On 2 October 2014 JPMorgan Chase filed a current report with the Securities and Exchange Commission under Item 7.01, the heading a company uses when it wants everyone to hear a thing at the same moment. The substance ran to a paragraph. User contact information — name, address, phone number and email address — along with internal JPMorgan Chase information, had been compromised for about 76 million households and seven million small businesses. The filing then set out what had not been reached: there was no evidence, it said, that account numbers, passwords, user IDs, dates of birth or Social Security numbers had been taken, and customers were not liable for unauthorised transactions they reported promptly. About two in three American households sat inside that first figure.

The intrusion had begun in June. The bank's own security team found it in late July, and the attackers were not completely shut out until the middle of August. The scale of it became public on 2 October — roughly four months from entry to announcement, and about nine weeks from discovery to announcement. In the interval JPMorgan shut the compromised accounts and reset the passwords of every employee in its technology organisation, while telling customers they needed to change nothing, because on the bank's own account there was nothing for a customer to change. The attackers, investigators found, had obtained a list of the bank's applications and programs and worked through it looking for a way in. Analysts quoted at the time called it a wake-up call for the American financial services system: if the largest bank in the country could be walked through this way, the question was who could not be.

What had been taken was a mailing list, and the value of a bank's mailing list is that a message arriving on it looks as though it came from the bank. That was the warning issued and repeated: not fraud on the accounts, of which JPMorgan said it had seen nothing unusual, but the letter, the call or the email that already knows a customer's name and where they keep their money. Reporting that autumn placed nine other financial institutions in the same campaign; what each of them lost, if anything, was disputed rather than settled, and several said nothing had been taken at all. By the end of the year the bank put its own security spending at about $250 million a year, with a thousand people doing it.

The ending came thirteen months later, in an indictment this archive takes up in November 2015, and it was not the ending anyone had expected in October: not an intelligence service and not a card-fraud crew, but a criminal enterprise in which the bank's customer list was one asset among many. Gery Shalon pleaded guilty to all twenty-three counts and forfeited more than $400 million. Ziv Orenstein was extradited in 2016 and Joshua Samuel Aaron arrested in December of that year; Andrei Tyurin, extradited from Georgia in 2018, was sentenced in 2021 to twelve years. JPMorgan said it would double its annual security budget to $500 million over five years. No customer was ever asked to change a password.

Also that month · 9–20 October

A protocol, the tills and a wallet

On 14 October three Google researchers — Bodo Möller, Thai Duong and Krzysztof Kotowicz — published an attack on SSL 3.0, the version that preceded TLS, which browsers still fell back to when a newer handshake failed. POODLE, for Padding Oracle On Downgraded Legacy Encryption, needed on average 256 requests to recover one byte of a secret, cheap when that secret is a session cookie. CVE-2014-3566 could not be patched, only abandoned: Chrome 39 dropped the fallback in November, Firefox 34 the protocol in December. The tills had the worse month. Dairy Queen confirmed on 9 October that Backoff had been found at 395 of its American stores and one Orange Julius, reached on a vendor's credentials; Kmart's technology team detected malware in its payment systems that same day, and Sears Holdings told the SEC on 10 October that card numbers had gone but no PINs, email addresses or Social Security numbers. On 20 October banks traced counterfeit-card fraud to Staples shops in Pennsylvania, New York and New Jersey. Apple Pay went live the same day with iOS 8.1, handing the shop a device account number, not a card number.

Also that month · 14 & 27 October

Two names for Moscow

The same day POODLE went public, Microsoft's monthly patches closed CVE-2014-4114, a flaw in the Windows OLE package manager that let a crafted PowerPoint file fetch and run a remote INF file. iSIGHT Partners, which had found it, named the group Sandworm, after the references to Frank Herbert's Dune in the operators' infrastructure. The spear-phishing had been spotted in late August and the zero-day confirmed on 3 September, around the NATO summit in Wales; the targets named were NATO, the European Union, the Ukrainian government, energy and telecommunications firms and one American organisation. iSIGHT said the zero-day virtually guaranteed all of them had fallen victim to some degree, which none of the targets confirmed; the payload dropped was BlackEnergy, the family that would turn the lights off in December 2015. On 27 October FireEye published on another Russian group, APT28, assessing it as most likely sponsored by the Russian government, on Russian-language build settings, compile times in Moscow and St Petersburg working hours, and years of methodical development. It hedged: no single entity, it said, understood the whole picture. This archive follows it to April 2015 and June 2016.

India desk · October 2014

The deadline at the end of the month

While an American bank explained what it had lost and American tills leaked card numbers, the Reserve Bank of India was enforcing a rule nowhere else had adopted. Its circular of 22 August 2014 — DPSS.PD.CO. No.371/02.14.003/2014-2015, on security issues and risk mitigation measures related to card not present transactions — recorded instances of such transactions being effected without the mandated additional authentication, by entities routing payments between two people in India through banks abroad, an arrangement that also sent foreign exchange out of the country. Card payments for goods and services within India, the bank directed under the Payment and Settlement Systems Act, 2007, must be acquired through banks in India and settled in rupees. Arrangements that did not comply had until 31 October 2014 to end.

The company most visibly caught was Uber, which had been charging Indian riders through an overseas gateway and now needed a second factor in front of every fare. On its India blog at the end of November it called two-factor authentication an antiquated solution, cumbersome for consumers, reported a slow conversion of riders from cards to a compliant wallet and asked for another forty-five days. The dates slipped; the rule did not. India had made a second factor ordinary on card payments years before anywhere else, and the friction a foreign company called antiquated is much of why Indian card fraud never took the American shape. Its own reckoning came two years later, in October 2016, when about 3.2 million debit cards were blocked or replaced after malware reached a payment processor. The duty to tell anyone came later still — CERT-In's six-hour direction in 2022, the DPDP Act in 2023.

AI Tech desk · October 2014

A Working Memory, and a Warning

On 24 October 2014, taking questions at the centennial symposium of MIT's department of aeronautics and astronautics, Elon Musk was asked about artificial intelligence and said that if he had to guess at the biggest existential threat, it was probably that; the field, he added, amounted to “summoning the demon”, and some regulatory oversight might be wise. The remark travelled further than anything else said on the subject that month: $10 million to a safety research programme in January 2015, and a co-founding role at OpenAI in December of that year. The research itself went on quietly. Four days earlier three DeepMind researchers — Alex Graves, Greg Wayne and Ivo Danihelka — had posted Neural Turing Machines to arXiv, a network coupled to an addressable external memory, differentiable end to end and so trainable by gradient descent, which learned copying, sorting and associative recall from examples alone. On 23 October Google announced that DeepMind had taken the seven founders of two Oxford spin-outs, Dark Blue Labs on language and Vision Factory on vision, terms undisclosed.

Digital Guard desk · October 2014

Symantec Splits Itself in Two

Three days after Hewlett-Packard said it would break itself apart, Symantec did the same. On 9 October 2014 its board approved a separation into two independent public companies: a security business with $4.2 billion of revenue in fiscal 2014, under Symantec's president and chief executive Michael Brown, and an information management business of backup, archiving and storage worth $2.5 billion, under a new general manager, John Gannon. The plan would give each side “the flexibility and focus to drive growth”, the company said. It did not end as drawn. The management half, named Veritas, went to a Carlyle-led group for $8 billion in January 2016 rather than to shareholders; the security half to Broadcom for $10.7 billion in 2019, the remainder becoming NortonLifeLock and then Gen Digital. Two days before the announcement Kaspersky Lab had described Tyupkin, a backdoor installed on Windows cash machines from a bootable CD, found on more than fifty ATMs in eastern Europe and accepting commands, by default, only on Sunday and Monday nights. An ATM was a Windows endpoint that dispensed cash.

⏳ Time capsule — October 2014

  • On 2 October the Swachh Bharat Abhiyan, a national cleanliness mission, was launched in India by the prime minister, Narendra Modi.
  • On 10 October the 2014 Nobel Peace Prize was announced, going jointly to Kailash Satyarthi of India and Malala Yousafzai of Pakistan.
  • On 12 October Cyclone Hudhud made landfall near Visakhapatnam in Andhra Pradesh; at least 46 people were killed in Andhra Pradesh and three more in Odisha, and hundreds of thousands had been moved into shelters before it came ashore.
  • On 28 October an Antares rocket carrying a Cygnus cargo capsule to the International Space Station lost first-stage propulsion fifteen seconds after lifting off from Wallops Island, Virginia, and was destroyed on the range; nobody was hurt.
Where it stands today — 2026

Nothing to reset

A decade on, the strangest thing about October 2014 is what did not follow it. There was no password to change, no card to reissue, no credit file to freeze — only about 76 million households whose names, addresses, telephone numbers and email addresses were now attached, somewhere, to the fact that they banked at Chase. Harm of that kind cannot be counted, and it never was. The criminal side closed: guilty pleas, a forfeiture of more than $400 million, a twelve-year sentence in 2021. What did not close is the question the filing opened — what a company owes the people whose contact details it loses, when nothing it lost can be cancelled. Every notification law written since has been an attempt at an answer.

The other threads ran further than the month suggested. SSL 3.0 is gone, and so is the downgrade dance that made POODLE work; the pattern of retiring a protocol rather than repairing it became routine. Sandworm did not stop at a PowerPoint file — the name belongs now to the Ukrainian grid, taken up here in December 2015 — and APT28 acquired other names and a far larger audience, followed to April 2015 and June 2016. The tills were fixed slowly and by economics rather than by rule: chip cards, which America was still arguing about that month, and the tokenised wallet that launched on 20 October, which by 2026 is simply how a card is presented. India's answer, a mandatory second factor, was already in force.